收集 HPE Nimble Storage OS 記錄

支援的國家/地區:

本文說明如何使用 Bindplane,將 HPE Nimble Storage OS 記錄檔擷取至 Google Security Operations。

HPE Nimble Storage OS 是儲存陣列作業系統,可產生系統、硬體和複製記錄。這個平台會監控儲存空間作業,並提供詳細的事件記錄,方便您管理容量、陣列健康狀態和資料保護活動。HPE Nimble Storage 陣列支援將系統事件的原始 syslog 轉送至外部收集器。

事前準備

請確認您已完成下列事前準備事項:

  • Google SecOps 執行個體
  • Windows Server 2016 以上版本,或搭載 systemd 的 Linux 主機
  • Bindplane 代理程式與 HPE Nimble Storage 陣列之間的網路連線
  • 如果透過 Proxy 執行,請確保防火牆通訊埠已根據 Bindplane 代理程式需求開啟
  • 具備管理員權限的 HPE Nimble Storage 陣列特殊存取權

取得 Google SecOps 擷取驗證檔案

  1. 登入 Google SecOps 控制台。
  2. 依序前往「SIEM 設定」>「收集代理程式」
  3. 下載擷取驗證檔案,並將檔案安全地儲存在要安裝 Bindplane 的系統中。

取得 Google SecOps 客戶 ID

  1. 登入 Google SecOps 控制台。
  2. 依序前往「SIEM 設定」>「設定檔」
  3. 複製並儲存「機構詳細資料」部分中的客戶 ID

安裝 Bindplane 代理程式

請按照下列操作說明,在 Windows 或 Linux 作業系統上安裝 Bindplane 代理程式。

Windows 安裝

  1. 以管理員身分開啟「命令提示字元」或「PowerShell」
  2. 執行下列指令:

    msiexec /i "https://github.com/observIQ/bindplane-agent/releases/latest/download/observiq-otel-collector.msi" /quiet
    
  3. 等待安裝完成。

  4. 執行下列指令,確認安裝成功:

    sc query observiq-otel-collector
    

服務應顯示為「RUNNING」

Linux 安裝

  1. 開啟具有根層級或 sudo 權限的終端機。
  2. 執行下列指令:

    sudo sh -c "$(curl -fsSlL https://github.com/observiq/bindplane-agent/releases/latest/download/install_unix.sh)" install_unix.sh
    
  3. 等待安裝完成。

  4. 執行下列指令,確認安裝成功:

    sudo systemctl status observiq-otel-collector
    

服務應顯示為有效 (執行中)

其他安裝資源

如需其他安裝選項和疑難排解資訊,請參閱 Bindplane 代理程式安裝指南

設定 Bindplane 代理程式,擷取系統記錄檔並傳送至 Google SecOps

找出設定檔

  • Linux:

    sudo systemctl status observiq-otel-collector
    
  • Windows:

    notepad "C:\Program Files\observIQ OpenTelemetry Collector\config.yaml"
    

編輯設定檔

  • config.yaml 的所有內容替換為下列設定:

    receivers:
        udplog:
            listen_address: "0.0.0.0:514"
    
    exporters:
        chronicle/nimble_os:
            compression: gzip
            creds_file_path: '/etc/bindplane-agent/ingestion-auth.json'
            customer_id: '<customer_id>'
            endpoint: malachiteingestion-pa.googleapis.com
            log_type: NIMBLE_OS
            raw_log_field: body
            ingestion_labels:
                env: production
    
    service:
        pipelines:
            logs/nimble_to_chronicle:
                receivers:
                    - udplog
                exporters:
                    - chronicle/nimble_os
    

設定參數

替換下列預留位置:

  • 接收器設定:

    • udplog:根據通訊協定的接收器類型:
      • udplog (適用於 UDP 系統記錄檔)
      • tcplog 適用於 TCP Syslog
    • 0.0.0.0:要接聽的 IP 位址:
      • 0.0.0.0,監聽所有介面 (建議)
      • 在一個介面上接聽的特定 IP 位址
    • 514:要接聽的通訊埠號碼 (例如 51415146514)
  • 匯出工具設定:

    • nimble_os:匯出工具的說明名稱
    • creds_file_path:擷取驗證檔案的完整路徑:
      • Linux/etc/bindplane-agent/ingestion-auth.json
      • WindowsC:\Program Files\observIQ OpenTelemetry Collector\ingestion-auth.json
    • <customer_id>:上一步中的客戶 ID
    • endpoint:區域端點網址:
      • 美國malachiteingestion-pa.googleapis.com
      • 歐洲europe-malachiteingestion-pa.googleapis.com
      • 亞洲asia-southeast1-malachiteingestion-pa.googleapis.com
      • 如需完整清單,請參閱「區域端點
    • NIMBLE_OS:記錄類型,與 Chronicle 中顯示的完全相同
    • ingestion_labels:YAML 格式的選用標籤 (例如 env: production)
  • 管道設定:

    • nimble_to_chronicle:管道的說明名稱

儲存設定檔

  • 編輯完成後,請儲存檔案:
    • Linux:依序按下 Ctrl+OEnterCtrl+X
    • Windows:依序點選「檔案」>「儲存」

重新啟動 Bindplane 代理程式,以套用變更

如要在 Linux 中重新啟動 Bindplane 代理程式,請執行下列步驟:

  1. 執行下列指令:

    sudo systemctl restart observiq-otel-collector
    
  2. 確認服務正在執行:

    sudo systemctl status observiq-otel-collector
    
  3. 檢查記錄中是否有錯誤:

    sudo journalctl -u observiq-otel-collector -f
    

如要在 Windows 中重新啟動 Bindplane 代理程式,請按照下列步驟操作:

  1. 您可以選擇下列其中一個選項:

    • 以管理員身分開啟命令提示字元或 PowerShell:
    net stop observiq-otel-collector && net start observiq-otel-collector
    
    • 服務控制台:
      1. 按下 Win+R,輸入 services.msc,然後按下 Enter 鍵。
      2. 找出 observIQ OpenTelemetry Collector
      3. 按一下滑鼠右鍵,然後選取「重新啟動」
  2. 確認服務正在執行:

    sc query observiq-otel-collector
    
  3. 檢查記錄中是否有錯誤:

    type "C:\Program Files\observIQ OpenTelemetry Collector\log\collector.log"
    

設定 HPE Nimble Storage OS 系統記錄轉送

HPE Nimble Storage 陣列支援將系統、硬體和複寫事件記錄轉送至外部 syslog 伺服器。您可以使用 CLI 或管理 GUI 設定系統記錄轉送功能。

使用 CLI 設定系統記錄

  1. 使用管理員憑證,透過 SSH 連線至 HPE Nimble Storage 陣列:

    ssh admin@<nimble_array_ip>
    
  2. 啟用系統記錄,並將 Bindplane 代理程式指定為系統記錄伺服器:

    group --edit --syslog_server <bindplane_agent_ip>
    
  3. (選用) 指定自訂系統記錄檔通訊埠 (預設為 514):

    group --edit --syslog_port <port_number>
    
  4. 驗證系統記錄設定:

    group --info | grep -i syslog
    

    輸出內容應顯示 Syslogd enabled: Yes,以及設定的伺服器位址和通訊埠。

使用管理 GUI 設定系統記錄

  1. 登入 HPE Nimble Storage 管理介面。
  2. 依序前往「Administration」(管理) >「Syslog」(系統記錄)
  3. 按一下「啟用系統記錄伺服器」
  4. 在「伺服器」欄位中,輸入 Bindplane 代理程式主機的 IP 位址。
  5. 在「Port」(通訊埠) 欄位中,輸入與 Bindplane 代理程式接收器設定相符的通訊埠 (預設為 514)。
  6. 按一下 [儲存]

UDM 對應表

記錄欄位 UDM 對應 邏輯
extensions.auth.mechanism 驗證機制
extensions.auth.type 驗證類型
data_message metadata.description 活動說明
類型 metadata.event_type 事件類型
類型 metadata.product_event_type 產品事件類型
id metadata.product_log_id 產品記錄 ID
版本 metadata.product_version 產品版本
群組 principal.group.group_display_name 群組顯示名稱
logsource principal.hostname 主要主機名稱
client_ip principal.ip 主體 IP 位址
陣列 principal.resource.name 資源名稱
principal.resource.resource_subtype 資源子類型
principal.resource.resource_type 資源類型
狀態 security_result.action 安全性動作
錯誤 security_result.description 安全性結果說明
security_result.summary 安全性結果摘要
filename,target target.file.full_path 檔案完整路徑
object_id target.resource.id 資源 ID
object、target、filename、partner、volname target.resource.name 資源名稱
target.resource.resource_subtype 資源子類型
target.resource.resource_type 資源類型
target.user.user_display_name 使用者顯示名稱
使用者名稱 target.user.userid 使用者 ID
metadata.product_name 產品名稱
metadata.vendor_name 供應商名稱

變更記錄

查看這個剖析器的變更記錄

還有其他問題嗎?向社群成員和 Google SecOps 專業人員尋求答案。