ig Configuration Guide for realize the Qosmos log analysis with Click&DECiDE NSI Or how quickly configure Qosmos log analysis With this document help, we will present the quick configuration of Qosmos in discover mode and the integration of Click&DECiDE log analysis for Qosmos. Should you have any question about this document, or would you like some help, please contact: Benoît Rostagni Tel: +33 1 47 86 91 66 GSM: +33 6 82 88 94 17 email: benoit.rostagni@clickndecide.com Contact us: E-mail: sales@clickndecide.com Tel: +33 467 844 800 Main Office: 130, rue Baptistou, ZAE Nord, 34 980 St Gély du Fesc, France To contact your nearest Click&DECiDE partner, click here.
Table of Contents 1. Click&DECiDE configuration to analyze Qosmos logs... 3 1.1. Hardware Configuration... 3 1.2. Software Installation... 3 1.3. Downloading Click&DECiDE Software... 3 2. Qosmos configuration to send logs to Click&DECiDE... 3 2.1. Qomos Discover Tuple... 3 2.2. Qosmos Supervision... 4 2.3. CSV log collection... 5 3. Click&DECiDE configuration to analyze the logs... 6 3.1. Qosmos Discover Filter import... 6 3.2. Qosmos Discover filter configuration... 6 4. Operating Qosmos data... 8 4.1. Creating an on demand report, on current processed data... 8 4.2. Creating a data Cube for easy data manipulation... 9
1. Click&DECiDE configuration to analyze Qosmos logs 1.1. Hardware Configuration Thank you for reporting to the Guide: NSI Architectures design guide From 1 to 300 millions lines per day available here: http:///resources/guides 1.2. Software Installation Thank you for reporting to the Guide: NSI Quick Installation Guide For Proof of Concept, For Demonstrations, For Free Evaluation Licenses NSI Soft Appliance Quick Installation Guide And to the training books: NSI Training Book Part 1 : Log Source Configuration NSI Training Book Part 2 : Management Console Configuration All those documents are available here: http:///resources/guides 1.3. Downloading Click&DECiDE Software Register on the web page http://license.clickndecide.com/downloads/cndnsi_request.aspx and you will received by email, you licence code valid for a month, with direct links to download either: Click&DECiDE NSI software version Click&DECiDE NSI Soft Appliance version for VMware Workstation Click&DECiDE NSI Soft Appliance version for VMware ESXi 4.x Click&DECiDE NSI Soft Appliance version for Windows Virtual PC Please follow the installation instructions 2. Qosmos configuration to send logs to Click&DECiDE Installation of the Qosmos "Discover" tuple prepared for Click&DECiDE. Please contact us if you did not receive it. 2.1. Qomos Discover Tuple The Tuple looks like: tuple cnd1_discover 'base:flow_id not null, time(base:flow_id not null), time(base:session_end not null), base:session_packet_counter not null, ip:client_addr not null, ip:server_addr not null, tcp:server_port, udp:server_port, sum(base:tot_len not null), ip:protocol not null, base:path not null, eth:src not null' export default
The configuration must be scheduled to write (flush tuple) the logs every 1 to 5 minutes. The configuration file "tdclid.conf.disco" must include the following line: tune max_timeout 180 Load the tuple using the command: tdcli conf load disco The CSV generated must be sent in a shared directory on the Click&DECiDE computer. This can be done on a shared disk or by an FTP command. Eventually, logs can be received in Syslog. In this case, the Qosmos Click&DECiDE filter should be modified to take into account the logs sent in syslog format. 2.2. Qosmos Supervision You can use console software like putty to oversee the collection of logs, for example with the command: watch 'tdcli caplin stats; echo ====; tdcli tuple statlist; echo ====; free' Or with the command: tdcli rep caplin stats verbose
2.3. CSV log collection Logs received in Click&DECiDE directory looks like the following: The file contains records of this type:
3. Click&DECiDE configuration to analyze the logs After becoming familiar with Click&DECiDE solution using the setup guide and the Demo device installation, you can install the Qosmos Discover filter prepared by Click&DECiDE. Please contact us if you did not receive it. 3.1. Qosmos Discover Filter import The filter is named Qosmos Discover.xml. Open the Management Console, and go to Filters section and press the right click button on the mouse. Select Import Filter and / or Parsers. Answer yes to both questions to import the filter and parsers. 3.2. Qosmos Discover filter configuration Make sure that the collection agent is pointing by default on the area you have chosen to carry out the collection of logs. If necessary, make the change supervised directory.
Then apply the agent configuration for the Flat File Parser. Then do the same on the filter configuration, at ULA level. The * means that a configuration has changed and need to be saved (Apply Change), the sign disappear when the modified configuration is loaded on the system.
4. Operating Qosmos data By default, Qosmos data are sent in a table Firewall. Every night at 1 AM, those data are aggregated and reports are created daily and available on the web portal. If you want to use the data immediately, without waiting for next day, you must perform a scheduled task, including aggregation and report generation (please refer to training books). 4.1. Creating an on demand report, on current processed data In the Click&DECiDE Web portal (http://localhost/dvweb/) use the following links: NSI Report and Analysis > Dynamic Reports > Firewall Statistics (Daily) > Report Book for the Firewall(s) (Daily Reports 01 to 15). Select "Today" for the date and write "Qosmos Discover" in the Firewall. And press the Save task button. Check the boxes next to the dates to automate the date calculations and fill in the destination as follows: Save the task. This task must be scheduled in order to be process automatically.
In Scheduled Task & Task > Scheduled Task, select New Scheduled Task and configure it as follow to be executed on-demand: Press finish and the report is available within minutes later in: NSI Reports and Analysis > Published Reports > Qosmos Discover > Qosmos_Daily.pdf 4.2. Creating a data Cube for easy data manipulation In NSI Reports and Analysis > Forensic Analysis > Firewall Cubes > Firewall Cube on Detailed Information (limited to 100 000 records), select the parameters to filter your data in your cube view: And then manipulate the dimension (display, filter, sort,...) as desired.
Sample of a grid view: Sample of a graph view: