Upgrade Guide. Upgrading to EventTracker v7.1 Enterprise. Upgrade Guide Centre Park Drive Publication Date: Apr 11, 2011.

Similar documents
Upgrade Guide. Upgrading to EventTracker v6.4 b50. Upgrade Guide Centre Park Drive Publication Date: Feb 17, 2010.

Upgrade Guide. Upgrading to EventTracker v6.4 b50. Upgrade Guide Centre Park Drive Publication Date: Feb 17, 2010.

Upgrade Guide. Upgrading to EventTracker v6.4 b50. Upgrade Guide Centre Park Drive Publication Date: Feb 17, 2010.

Upgrade Guide. Upgrading to EventTracker v6.4 b50. Upgrade Guide Centre Park Drive Publication Date: Feb 17, 2010.

EventTracker Upgrade Guide. Upgrade to v9.0

EventTracker: Upgrade Guide

Agent Installation Using Smart Card Credentials Detailed Document

Product Update: ET82U16-029/ ET81U EventTracker Enterprise

Integrating LOGbinder SP EventTracker v7.x

Integrating Terminal Services Gateway EventTracker Enterprise

Integrating Barracuda SSL VPN

Enhancement in Network monitoring to monitor listening ports EventTracker Enterprise

Enhancement in Agent syslog collector to resolve sender IP Address EventTracker Enterprise

Port Configuration. Configure Port of EventTracker Website

Integrating Microsoft Forefront Unified Access Gateway (UAG)

8815 Centre Park Drive Columbia MD Publication Date: Dec 04, 2014

Agent health check enhancements Detailed Document

Receive and Forward syslog events through EventTracker Agent. EventTracker v9.0

Integrate TippingPoint EventTracker Enterprise

Integrate Malwarebytes EventTracker Enterprise

Feature List. EventTracker v7.6. EventTracker 8815 Centre Park Drive Columbia MD Publication Date: Sep 15, 2014

Installation Guide. EventTracker Enterprise. Install Guide Centre Park Drive Publication Date: Aug 03, U.S. Toll Free:

Integrate Windows PowerShell

Integrate Sophos Enterprise Console. EventTracker v8.x and above

Integrating Cisco Distributed Director EventTracker v7.x

Integrate Dell FORCE10 Switch

New Features Guide EventTracker v6.2

Agent Direct Log Archiver Configuration Guide

Integrate Veeam Backup and Replication. EventTracker v9.x and above

EventVault Introduction and Usage Feature Guide Version 6.x

Integrate Sophos UTM EventTracker v7.x

EventTracker: Backup and Restore Guide Version 9.x

Integrate Viper business antivirus EventTracker Enterprise

Geolocation and hostname resolution while Elasticsearch indexing. Update Document

Integrating Microsoft Forefront Threat Management Gateway (TMG)

Integrate Trend Micro InterScan Web Security

EventTracker v8.2. Install Guide for EventTracker Log Manager. EventTracker 8815 Centre Park Drive Columbia MD

Integrate Juniper Secure Access VPN

Integrate Barracuda Spam Firewall

Integrate Cisco VPN Concentrator

Integrate Sophos Appliance. EventTracker v8.x and above

Integrate Meraki WAP. EventTracker Enterprise. EventTracker 8815 Centre Park Drive Columbia MD

Remote Indexing Feature Guide

SECURE FILE TRANSFER PROTOCOL. EventTracker v8.x and above

How To Embed EventTracker Widget to an External Site

Integrating Cyberoam UTM

Integrate MySQL Server EventTracker Enterprise

Integrate Microsoft Antimalware. EventTracker v8.x and above

Integrate NGINX. EventTracker v8.x and above

Security Scorecard in Flex Dashboard

Integrate Microsoft Hyper-V Server

Integrate IIS SMTP server. EventTracker v8.x and above

Integrate Akamai Web Application Firewall EventTracker v8.x and above

Integrate Citrix Access Gateway

Integrate Symantec Messaging Gateway. EventTracker v9.x and above

Integrate Microsoft ATP. EventTracker v8.x and above

Integrate Palo Alto Traps. EventTracker v8.x and above

Integrate Microsoft Office 365. EventTracker v8.x and above

Integrate Cb Defense. EventTracker v8.x and above

Integrate pfsense EventTracker Enterprise

Integrate Fortinet Firewall. EventTracker v8.x and above

Installation Guide Install Guide Centre Park Drive Publication Date: Feb 11, 2010

Configuring TLS 1.2 in EventTracker v9.0

EventTracker Manual Agent Deployment User Manual

Integration of Phonefactor or Multi-Factor Authentication

Integrate Bluecoat Content Analysis. EventTracker v9.x and above

Integrate Saint Security Suite. EventTracker v8.x and above

Integrate Grizzly steppe attacks detection script

Service Pack ET90U Feature Document

Integrate Salesforce. EventTracker v8.x and above

Event Correlator. EventTracker v8.x

Integrate Microsoft IIS

Enable Auditing in Open LDAP on Linux Server

EventTracker v7.x. Integrating Cisco Catalyst. EventTracker 8815 Centre Park Drive Columbia MD

Configure Alerts. EventTracker v6.x. EventTracker 8815 Centre Park Drive Columbia MD Publication Date: Jun 12, 2009

EventTracker Upgrade Guide. Upgrade to v8.2

Integrate HP ProCurve Switch

Integrate EMC Isilon. EventTracker v8.x and above

Integrate Cisco Sourcefire

Process Termination. Feature Guide

EventTracker Manual Agent Deployment User Manual Version 7.x

Integrate F5 BIG-IP LTM

How to Configure ASA 5500-X Series Firewall to send logs to EventTracker. EventTracker

Monitoring SharePoint 2007/ 2010/ 2013 Server using EventTracker

Integrate McAfee Firewall Enterprise VPN

Integrate Cisco IOS Publication Date: April 15, 2016

Integrating Imperva SecureSphere

Integrate Check Point Firewall. EventTracker v8.x and above

Integrate Citrix NetScaler

Integrate Kaspersky Security Center

Secure IIS Web Server with SSL

Feature List. EventTracker v9.0

Integrate Aventail SSL VPN

IIS Web Server Configuration Guide EventTracker v8.x

Integrate Cisco IronPort Security Appliance (ESA)

Check Point Guide. Configure ETAgent to read CheckPoint Logs. EventTracker 8815 Centre Park Drive Columbia MD

Integrate Apache Web Server

IIS Web Server Configuration Guide EventTracker v9.x

Integrate Cisco Switch

Integrate VMware ESX/ESXi and vcenter Server

Transcription:

Upgrading to EventTracker v7.1 Enterprise Upgrade Guide 8815 Centre Park Drive Publication Date: Apr 11, 2011 Columbia MD 21045 U.S. Toll Free: 877.333.1433

Abstract The purpose of this document is to help users upgrade from EventTracker v.6.4 b50 to EventTracker v7.1 Enterprise, and to verify the expected functionality and performance of all its components. If you encounter any problems during upgrade process, please contact Support to get quick and thorough instructions. The information contained in this document represents the current view of Prism Microsystems, Inc. on the issues discussed as of the date of publication. Because Prism Microsystems, Inc. must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Prism Microsystems, Inc. and Prism Microsystems, Inc. cannot guarantee the accuracy of any information presented after the date of publication. This document is for informational purposes only. Prism Microsystems, Inc. MAKES NO WARRANTIES, EXPRESS OR IMPLIED, AS TO THE INFORMATION IN THIS DOCUMENT. Complying with all applicable copyright laws is the responsibility of the user. Without limiting the rights under copyright, this Guide may be freely distributed without permission from Prism, as long as its content is unaltered, nothing is added to the content and credit to Prism is provided. Prism Microsystems, Inc. may have patents, patent applications, trademarks, copyrights, or other intellectual property rights covering subject matter in this document. Except as expressly provided in any written license agreement from Prism Microsystems, Inc. the furnishing of this document does not give you any license to these patents, trademarks, copyrights, or other intellectual property. The example companies, organizations, products, people and events depicted herein are fictitious. No association with any real company, organization, product, person or event is intended or should be inferred. 2011 Prism Microsystems, Inc. All rights reserved. The names of actual companies and products mentioned herein may be the trademarks of their respective owners. Prism Microsystems, Inc. 2

Table of Contents WHO SHOULD USE THIS GUIDE?... 4 BEFORE YOU UPGRADE... 4 WHAT IS NEW IN EVENTTRACKER V7.1 ENTERPRISE... 5 ENHANCEMENTS... 6 PREREQUISITES... 7 PLANNING... 8 COMPLETE UPGRADE PROCEDURE... 9 MANAGEMENT CONSOLE... 9 UPGRADING FROM V6.4 B50 TO V7.1 ENTERPRISE... 9 POST UPGRADE PROCESS... 9 VALIDATION... 13 Prism Microsystems, Inc. 3

Who should use this Guide? It is incumbent upon all users of EventTracker v.6.4 b50 who wish to upgrade to v7.1 Enterprise. Prism strongly recommends that you read the entire document thoroughly before you begin the upgrade process. Before you upgrade 1. Thoroughly read the EventTracker Architecture guide. This guide explains the architecture and sample deployment methods with illustrations. http://www.prismmicrosys.com/resources/documents/eventtrackerarchitecture.pdf 2. Contact support@prismmicrosys.com for information regarding license keys. Important: Users of versions 5.x and below contact support@prismmicrosys.com for complete and thorough instructions. Prism Microsystems, Inc. 4

What is New in EventTracker v7.1 Enterprise 1. The Web interface has been given a comprehensive facelift to improve workflow and productivity 2. Integrated framework of EventTracker plug-ins (TrapTracker, StatusTracker) 3. FIPS 140-2 accredited cryptographic modules 4. Revamped Behavior Dashboard a. Dashlets snippets of information with drill-down facility b. configure custom Behavior Rules c. add custom Behavior Rules as Dashlets 5. NetFlow Receiver to read NetFlow v5/v9 logs. NetFlow Analyzer interface helps you with easy-tounderstand network stats with graphical charts. a. in-depth visibility into network traffic and its patterns b. closely monitor and identify bandwidth abusers c. identify malicious applications running on the network 6. SCAP based Configuration Assessment a. assess configurations against compliance mandates such as FDCC b. rapidly detect and declare deviations c. create Plans of Actions and Milestones for the associated remediation d. generate XCCDF bundle for configuration reporting 7. Integrated Change auditing 8. Vulnerability Parsers a. to read and extract vulnerability information from XML reports generated by Vulnerability Scanners on EventTracker managed systems b. analyze extracted vulnerability information to evaluate potential impact 9. Integrated StatusTracker 10. EventVault Explorer 11. Agent DLA an offline method to archive events directly into EventTracker data repository 12. Reports Transfer Facility in DLA 13. Internal scoring algorithm to automatically compute and rank Alert severity levels 14. New services a. EventTracker Remoting service manage deployments of EventTracker Windows and Change Audit Agents b. EventTracker Indexer service indexes CAB files to quickly search and find relevant information 15. Digital Certificate based licensing 16. Centralized storage on Manager system to store remote Agent configuration files 17. Manage Asset Value value indicates how critical the system is Prism Microsystems, Inc. 5

18. Tag Cloud weighting 19. Web Slices 20. Changed Alert "USB insert alert" to "Media insert alert" 21. New categories for StatusTracker audit events Enhancements 1. EventTracker Agent service receives and performs configuration assessment requests and sends back the assessment results 2. EventTracker Scheduler service fetches configuration assessment requests from queue and dispatches the request to EventTracker Agents running on target system Prism Microsystems, Inc. 6

Prerequisites Before you begin the upgrade process, please follow this checklist and make sure that you have all the components in place to perform a successful upgrade. The most effective upgrade method is to first export all the custom settings using Export Import Utility, install the new version and import the custom settings. There is no need to export all policy settings since all the Categories included in any prior versions have been retained. The recommended method is to first upgrade the Manager and validate all its functionality, next upgrade the Agents and lastly verify the performance. Prism Microsystems, Inc. 7

Planning This section gives you a rough estimation of time required for upgrading as well as monitoring the successful upgrade. It might take 60 90 minutes for you to read this document and to complete the upgrade process gracefully. You will also require spending a few minutes the following day after the upgrade, to verify all your Scheduled Reports are being generated. If any reports fail to generate, then please read the Validation section at the end of this document. Prism Microsystems, Inc. 8

Complete Upgrade Procedure Verify that all the prerequisites described above have been satisfied. Management Console Before the upgrade process begins, 1. Backup all custom Categories, Alerts (Please check the Export E-mail Settings check box), Filters, Scheduled Reports, and RSS Feeds using Export Import Utility. 2. Close/terminate all the EventTracker components like Management Console and Reports Console, including RDP (Remote Desktop Protocol) sessions. 3. Note down the custom changes you have made in the Trusted List (Agent Configuration -> Network Connection Monitor -> Suspicious Traffic Only (SNAM) -> Trusted List). Upgrading from v6.4 b50 to v7.1 Enterprise 1. Uninstall the existing version by retaining old configuration and data. 2. Restart the EventTracker Manager server. 3. Install EventTracker v7.1 Enterprise. 4. Using Export Import Utility, import all the custom Categories, Alerts, Filters, and RSS Feeds. 5. Verify that the Categories, Alerts, Filters, and RSS Feeds are intact. 6. Upgrade all agents using the System Manager. 7. Update the Trusted List with the changes you have noted down earlier. Post Upgrade Process By default, EventTracker sets the Threat level of Alerts imported from v6.4 as Undefined as shown in the following figure. You need to explicitly set the Threat level as per your requirement. Prism Microsystems, Inc. 9

1. To set the Threat level, click the title of the Alert. Figure 1 EventTracker displays the Alert configuration page. Prism Microsystems, Inc. 10

Figure 2 2. Select an appropriate option, for example, Critical from the Threat level drop-down list. 3. Click Finish. EventTracker saves the configuration settings. Prism Microsystems, Inc. 11

Figure 3 Prism Microsystems, Inc. 12

Validation After successfully completing the upgrade process, please verify that the Backup Directory path, Directory Path for Scheduled Reports copies and Report Data Cache path are properly configured. Prism Microsystems, Inc. 13