EventTracker v8.2. Install Guide for EventTracker Log Manager. EventTracker 8815 Centre Park Drive Columbia MD

Similar documents
Installation Guide Install Guide Centre Park Drive Publication Date: Feb 11, 2010

Installation Guide. EventTracker Enterprise. Install Guide Centre Park Drive Publication Date: Aug 03, U.S. Toll Free:

EventTracker Enterprise v8.1

EventTracker v8.3. Install Guide

EventTracker v9.0. Install Guide

Integrating Microsoft Forefront Unified Access Gateway (UAG)

Integrating Barracuda SSL VPN

Product Update: ET82U16-029/ ET81U EventTracker Enterprise

Integrate Sophos UTM EventTracker v7.x

Integrating Cisco Distributed Director EventTracker v7.x

Agent health check enhancements Detailed Document

Remote Indexing Feature Guide

Agent Installation Using Smart Card Credentials Detailed Document

Port Configuration. Configure Port of EventTracker Website

Receive and Forward syslog events through EventTracker Agent. EventTracker v9.0

Integrating Terminal Services Gateway EventTracker Enterprise

Enhancement in Agent syslog collector to resolve sender IP Address EventTracker Enterprise

Enhancement in Network monitoring to monitor listening ports EventTracker Enterprise

SECURE FILE TRANSFER PROTOCOL. EventTracker v8.x and above

EventTracker v7.x. Integrating Cisco Catalyst. EventTracker 8815 Centre Park Drive Columbia MD

Integrate MySQL Server EventTracker Enterprise

Integrate Malwarebytes EventTracker Enterprise

8815 Centre Park Drive Columbia MD Publication Date: Dec 04, 2014

Integrate TippingPoint EventTracker Enterprise

Integrate Veeam Backup and Replication. EventTracker v9.x and above

Secure IIS Web Server with SSL

Integrate Windows PowerShell

Integrate Meraki WAP. EventTracker Enterprise. EventTracker 8815 Centre Park Drive Columbia MD

Integrating LOGbinder SP EventTracker v7.x

Integrate Dell FORCE10 Switch

Upgrade Guide. Upgrading to EventTracker v6.4 b50. Upgrade Guide Centre Park Drive Publication Date: Feb 17, 2010.

Integrate Juniper Secure Access VPN

Integrate pfsense EventTracker Enterprise

Integrate Symantec Messaging Gateway. EventTracker v9.x and above

Integrate Viper business antivirus EventTracker Enterprise

Integrate Microsoft Hyper-V Server

Integrate Microsoft ATP. EventTracker v8.x and above

EventTracker Manual Agent Deployment User Manual

Integrating Microsoft Forefront Threat Management Gateway (TMG)

Integrate Cisco VPN Concentrator

Upgrade Guide. Upgrading to EventTracker v6.4 b50. Upgrade Guide Centre Park Drive Publication Date: Feb 17, 2010.

Upgrade Guide. Upgrading to EventTracker v6.4 b50. Upgrade Guide Centre Park Drive Publication Date: Feb 17, 2010.

Integrate Sophos Enterprise Console. EventTracker v8.x and above

Integrate Salesforce. EventTracker v8.x and above

EventTracker Upgrade Guide. Upgrade to v9.0

Integrate Bluecoat Content Analysis. EventTracker v9.x and above

Integrate NGINX. EventTracker v8.x and above

Integrate Sophos Appliance. EventTracker v8.x and above

Integrate Trend Micro InterScan Web Security

Integrate Palo Alto Traps. EventTracker v8.x and above

Integrating Cyberoam UTM

Integrate Microsoft IIS

Integrating Imperva SecureSphere

Integrate Barracuda Spam Firewall

Integration of Phonefactor or Multi-Factor Authentication

New Features Guide EventTracker v6.2

Enable Auditing in Open LDAP on Linux Server

Integrate Microsoft Office 365. EventTracker v8.x and above

Configuring TLS 1.2 in EventTracker v9.0

IIS Web Server Configuration Guide EventTracker v8.x

EventTracker Manual Agent Deployment User Manual Version 7.x

Integrate Aventail SSL VPN

IIS Web Server Configuration Guide EventTracker v9.x

Integrate F5 BIG-IP LTM

EventVault Introduction and Usage Feature Guide Version 6.x

Configure Alerts. EventTracker v6.x. EventTracker 8815 Centre Park Drive Columbia MD Publication Date: Jun 12, 2009

Agent Direct Log Archiver Configuration Guide

Integrate Cisco Sourcefire

How To Embed EventTracker Widget to an External Site

Upgrade Guide. Upgrading to EventTracker v6.4 b50. Upgrade Guide Centre Park Drive Publication Date: Feb 17, 2010.

Upgrade Guide. Upgrading to EventTracker v7.1 Enterprise. Upgrade Guide Centre Park Drive Publication Date: Apr 11, 2011.

Integrate Grizzly steppe attacks detection script

Integrate IIS SMTP server. EventTracker v8.x and above

Feature List. EventTracker v7.6. EventTracker 8815 Centre Park Drive Columbia MD Publication Date: Sep 15, 2014

How to Configure ASA 5500-X Series Firewall to send logs to EventTracker. EventTracker

Integrate Saint Security Suite. EventTracker v8.x and above

Integrate HP ProCurve Switch

Integrate Citrix Access Gateway

Integrate Akamai Web Application Firewall EventTracker v8.x and above

Integrate VMware ESX/ESXi and vcenter Server

Integrate Fortinet Firewall. EventTracker v8.x and above

Monitoring SharePoint 2007/ 2010/ 2013 Server using EventTracker

Integrate EMC Isilon. EventTracker v8.x and above

Integrate Microsoft Antimalware. EventTracker v8.x and above

Check Point Guide. Configure ETAgent to read CheckPoint Logs. EventTracker 8815 Centre Park Drive Columbia MD

Event Correlator. EventTracker v8.x

Integrate Check Point Firewall. EventTracker v8.x and above

Integrate Cisco IronPort Security Appliance (ESA)

Integrate Citrix NetScaler

Integrate APC Smart UPS

Integrate McAfee Firewall Enterprise VPN

Integrate Cb Defense. EventTracker v8.x and above

Integrate Cisco IOS Publication Date: April 15, 2016

x10data Application Platform v7.1 Installation Guide

Service Pack ET90U Feature Document

Integrate Kaspersky Security Center

Integrate Apache Web Server

How to - Install EventTracker Windows and Change Audit Sensor Sensor Deployment User Manual-v9.0

Geolocation and hostname resolution while Elasticsearch indexing. Update Document

Process Termination. Feature Guide

Transcription:

EventTracker v8.2 Install Guide for EventTracker Log Manager Publication Date: Jun. 10, 2016 EventTracker 8815 Centre Park Drive Columbia MD 21045 www.eventtracker.com

Abstract This guide will help the users to install and configure EventTracker Log Manager, and verify the expected functionality of all its components. EventTracker is a reliable, policy driven solution to monitor and manage critical events generated by Windows 7/8/8.1/2008/2008 R2/2012/2012 R2/10, Solaris BSM, Unix (SYSLOG), SYSLOG-NG and SNMP devices. EventTracker is an enterprise grade solution that provides realtime alerts, secure warehousing, and flexible reporting. Target Audience EventTracker users or system administrators, who wish to install the EventTracker Log Manager. The information contained in this document represents the current view of Prism Microsystems, Inc. on the issues discussed as of the date of publication. Because Prism Microsystems, Inc. must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Prism Microsystems, Inc. and Prism Microsystems, Inc. cannot guarantee the accuracy of any information presented after the date of publication. This document is for informational purposes only. Prism Microsystems, Inc. MAKES NO WARRANTIES, EXPRESS OR IMPLIED, AS TO THE INFORMATION IN THIS DOCUMENT. Complying with all applicable copyright laws is the responsibility of the user. Without limiting the rights under copyright, this Guide may be freely distributed without permission from Prism, as long as its content is unaltered, nothing is added to the content and credit to Prism is provided. Prism Microsystems, Inc. may have patents, patent applications, trademarks, copyrights, or other intellectual property rights covering subject matter in this document. Except as expressly provided in any written license agreement from Prism Microsystems, Inc. the furnishing of this document does not give you any license to these patents, trademarks, copyrights, or other intellectual property. The example companies, organizations, products, people and events depicted herein are fictitious. No association with any real company, organization, product, person or event is intended or should be inferred. 2016 Prism Microsystems, Inc. All rights reserved. The names of actual companies and products mentioned herein may be the trademarks of their respective owners. 1

Table of Contents Introduction... 3 System Requirements... 3 Hardware Requirements [Min. Configuration]... 3 Software Requirements... 4 Install EventTracker Manager... 5 Pre-install Checklist for EventTracker Manager... 5 Procedure to install EventTracker Manager... 6 Uninstall EventTracker... 28 2

Introduction EventTracker Log Manager provides a unique combination of capabilities, including: Real-Time Alerting Log Search Secure Log Storage Reports Knowledge This is the good time to familiarize you with the various product features as described on the Web site (https://www.eventtracker.com/etlm/) in the brochure of this package. This installation guide is designed as an easy reference, since we recognize the imperative importance of error free and painless installation experience. System Requirements For optimal performance, following are the hardware and software requirements to host EventTracker Log Manager. Hardware Requirements [Min. Configuration] Minimum hardware required to install and smoothly run EventTracker Log Manager. 32-bit Installation: CPU RAM HDD 2.80 GHz and above, 4 Core or equivalent 8 GB 80 GB Free Hard disk space for the application Table 1 64-bit Installation: CPU RAM HDD 2.80 GHz and above, 4 Core or equivalent 8 GB 80 GB Free Hard disk space for the application Table 2 NOTE: The recommended CPU is 8 Core. 3

Software Requirements EventTracker Manager Windows Platforms 32 bit 64 bit Server 2012 R2 Not Applicable Supported Server 2012 Not Applicable Supported Server 2008 R2 Not Applicable Supported Server 2008 Supported Supported Windows 7 Supported Supported Windows 8 Supported Supported Windows 8.1 Supported Supported Windows 10 Supported Supported Components: Table 3 Microsoft.NET Framework 3.5 SP1 and.net Framework 4 or 4.5.2. Microsoft SQL SERVER 2005/2008/2008 R2/2012/2012 R2/2014 Express depending on the Operating System type. IIS Express gets installed depending upon the Operating System type. Windows Management Framework 2.0 Windows updates with all the latest service packs has to be installed. Web Browsers: Internet Explorer 11 and above Firefox Browser latest. EventTracker Agent Windows Platforms 32 bit 64 bit Server 2012 R2 Not Applicable Supported Server 2012 Not Applicable Supported Server 2008 R2 Not Applicable Supported Server 2008 Supported Supported Server 2003 R2 Supported Supported Server 2003 Supported Supported 4

Windows XP Supported Supported Vista Supported Supported Windows 7 Supported Supported Windows 8, 8.1 Supported Supported Windows 10 Supported Supported EventTracker Agent for Solaris: Solaris 9, Solaris 10 Table 4 Components: Microsoft.NET Framework 2.0 and above. NOTE: Versions other than those specified above are not supported. Install EventTracker Manager Prism recommends you to refer EventTracker Architecture guide before you begin installation. This guide explains the architecture and sample deployment methods with illustrations. Installation can be initiated by the following methods. 1. Launch the executable program. The installation is geared to be intuitive and friendly. The installation procedure is identical for all operating system(s) as mentioned in Table 3. Pre-install Checklist for EventTracker Manager The pre-install checklist describes the specific settings, permissions, and privileges that are required for installing EventTracker Manager. Read the checklist before installation to avoid installation failure. 5

User is a member of Local Administrators group MSI package installation is allowed ENSURE User has Logon As Service rights User has Logon As Batch job rights Network Discovery is enabled System cryptography: Use FIPS 140 compliant cryptographic algorithms, with encryption, hashing and signing algorithms disabled. User has permission on Application install directory (Folders and sub folders). VERIFY User must have create service permission on the target system(scm- service control manager) User has Read/Write permission on windows registry. Table 5 Procedure to install EventTracker Manager The detail procedure to install EventTracker is given below. NOTE: For Windows 7 and Windows 2008, if the Windows Management Framework 2.0 is not installed, the PowerShell 3.0 installation will fail, which is a pre-requisite for the EventTracker installation. To download Windows Management Framework 2.0, click on the following link: https://support.microsoft.com/en-us/kb/968929 1. Double-click the executable file. EventTracker installs the Microsoft.NET Framework 4.5.2 for Windows 2008,2008 R2, Windows 7. NOTE:.NET 4.5 is enabled by default for Windows 8/8.1/2012. **IMPORTANT: Fresh users who are installing the EventTracKer Log Manager (ETLM) will only get the screens shown below, during the installation process. 6

Figure 1 NOTE: In case system doesn t contain the latest windows updates with service packs then the following message will be displayed: Figure 2 EventTracker Pre-Install Check window displays. 7

Figure 3 2. Click the Next > button. Hardware Summary pane displays. NOTE: It may take a few seconds to fetch the hardware details and a processing symbol will appear during the data collection process. The processing symbol will be displayed only to the customers who are using EventTracker V 8.0 and later. 8

Figure 4 3. Click the Next > button. Prerequisite page displays. NOTE: If the prerequisites are not installed, then a message Install displays against the respective prerequisite. 9

Figure 5 a. Click the Next > button. For some Windows platforms,.net Framework gets installed via Deployment Image Servicing Management Tool (DISM). The instructions to install.net Framework is given in detail in How To - Install Microsoft.NET Framework. If the system contains all latest service packs, then PowerShell will start installing. 10

Figure 6 Installing Windows Installer and Powershell a. Click the Install button. b. Once the download is completed, it will search for updates in the computer. The Windows Update Standalone Installer page displays. Figure 7 c. It will ask for applying the Windows Software updates. 11

Figure 8 a. Click Yes. Figure 9 b. Accept the agreement by clicking the I Accept button. c. The update package, Windows Management Framework 2.0 gets installed via Pre-installer as shown in the figure below: 12

Figure 10 NOTE: In case system doesn t contain the latest windows updates with service packs then the following message will be displayed: Figure 22 Once prerequisites are installed, Database page displays. 4. If MSSQL Server Express Edition 2005/2008/2008 R2/2012/2014 is already installed, then select one instance and click the Next > button. If MS SQL Express is not installed, then click Next >. 13

Figure 12 The pre-installer prompts to download SQL Server Express Edition. Figure 13 14

a. Click the Download button. Please select a location to download the SQL installer window displays. Figure 14 b. Select the path to download SQL Express on a particular location and then click Save. SQL Express starts downloading. Figure 15 15

5. The Select SQL install and data directories screen will appear where you can choose the directory to which the SQL Server is to be installed. Figure 16 6. Select the browse button to choose the location and then click OK. SQL Express will be installed in the background. 7. For SQL Express 2012/2014 one needs to provide the user name and password of that person/account that will run the SQL service. This is to prevent the service from stopping since in some systems it is observed that the SQL service doesn t execute under the default account in which it gets created. Figure 17 Figure 18 After MS SQL Express is installed, Web Server page displays. 8. For EventTracker Log Manager, select IIS Express option, and then select the Next > button. 16

Figure 19 If IIS Express is already installed, on clicking Next >, If IIS Express is not installed, please refer Figure 20 and proceed to install it. 17

Figure 20 a. If IIS Express (Not Installed) option is selected, then click the Next > button. Installation of IIS Express proceeds. 18

Figure 21 b. Click the Install button. After IIS Express is installed successfully. a. Click the Next > button. This User will manage EventTracker page displays. 19

Figure 22 b. Enter relevant credentials, and then click the Next > button. Summary page displays. 9. In Summary page, verify all the data entered, and then click the Install button. 20

Figure 23 It will redirect you to the Registration page of EventTracker. Figure 24 21

10. Fill the register trail form, scroll down and click the Submit button. It will display the following screen. Figure 25 11. Close the page to proceed with the installation. EventTracker - Install Shield Wizard displays. Figure 26 22

EventTracker - InstallShield Wizard displays the Welcome screen. 10. Click Next >. Figure 27 InstallShield Wizard displays the License Agreement screen. 23

Figure 28 11. Read the license agreement, and then click I accept the terms in the license agreement option to accept the terms and condition. 12. Click the Next > button. Ready to Install the Program page displays. Figure 29 24

13. Click the Install button. InstallShield Wizard installs. Figure 30 InstallShield Wizard displays the last screen. Figure 31 a. Click Import existing event log entries option to import event logs of EventTracker. (Enabling the import option is not mandatory) Windows Security Alert message will be displayed if Firewall is on. 25

Figure 32 Firewall blocks the incoming network connection, if getallevt.exe does not exist in the Program and Services Exceptions and displays a notification. Click Unblock for the getallevt.exe to import event logs. b. Check Add a shortcut to the desktop option, to add the shortcuts to the EventTracker application on the desktop. Add EventTracker diagnostics as a startup program option is selected by default to notify problems about EventTracker, if any. 14. Click Finish to conclude the installation process. InstallShield Wizard displays the EventTracker Configuration screen. Provide the valid user credentials. 26

Figure 33 15. Click OK. After successfully validating the user credentials, InstallShield[R] Wizard displays the EventTracker Configuration message box. Figure 34 16. Click OK. 17. Once the installation process is complete, the user can click the desktop shortcut and login to the EventTracker application. NOTE: If the installation comes with the following error stating that Fails to Install IIS Express Service, please follow the below steps: 27

Figure 35 Restart the system and please run the EventTracker Configuration again. 1. To run EventTracker Configuration, click Start, click Programs, and then click Prism Microsystems. 2. Select EventTracker, and then select EventTracker Configuration. 3. Enter valid User Credentials, and then select the OK button. Uninstall EventTracker 1. Select the Start button, select All Programs, and then select Prism Microsystems. 2. Select EventTracker, and then select Uninstall EventTracker. Windows Installer window appears displays. 3. Select the Yes button. Figure 36 28

EventTracker window displays. Figure 37 4. Select the Ok button. Uninstall EventTracker Enterprise window displays. NOTE: Figure 38 In case you wish to retain Configuration, Reports and Data, then select the respective check box otherwise uncheck the options. 5. Select the Ok button. 29