收集 Quest File Access Audit 記錄
本文說明如何使用 Bindplane 代理程式,將 Quest File Access Audit 記錄擷取至 Google Security Operations。
Quest Change Auditor (舊稱 Quest File Access Audit) 是檔案伺服器和 Active Directory 稽核平台,可監控及回報 Windows 環境中的檔案存取活動、權限變更和管理動作。Change Auditor 提供內建的 SIEM 整合功能,包括透過事件訂閱轉送系統記錄。
事前準備
請確認您已完成下列事前準備事項:
- Google SecOps 執行個體
- Windows Server 2016 以上版本,或搭載
systemd的 Linux 主機 - Bindplane 代理程式與 Quest Change Auditor 協調器伺服器之間的網路連線
- 如果透過 Proxy 執行,請確保防火牆通訊埠已根據 Bindplane 代理程式需求開啟
- Quest Change Auditor 用戶端或協調器伺服器的特殊權限
取得 Google SecOps 擷取驗證檔案
- 登入 Google SecOps 控制台。
- 依序前往「SIEM 設定」>「收集代理程式」。
- 下載擷取驗證檔案。
將檔案安全地儲存在要安裝 Bindplane 的系統上。
取得 Google SecOps 客戶 ID
- 登入 Google SecOps 控制台。
- 依序前往「SIEM 設定」>「設定檔」。
複製並儲存「機構詳細資料」部分中的客戶 ID。
安裝 Bindplane 代理程式
請按照下列操作說明,在 Windows 或 Linux 作業系統上安裝 Bindplane 代理程式。
Windows 安裝
- 以管理員身分開啟「命令提示字元」或「PowerShell」。
執行下列指令:
msiexec /i "https://github.com/observIQ/bindplane-agent/releases/latest/download/observiq-otel-collector.msi" /quiet等待安裝完成。
執行下列指令,確認安裝成功:
sc query observiq-otel-collector服務應顯示為「RUNNING」。
Linux 安裝
- 開啟具有根層級或 sudo 權限的終端機。
執行下列指令:
sudo sh -c "$(curl -fsSlL https://github.com/observiq/bindplane-agent/releases/latest/download/install_unix.sh)" install_unix.sh等待安裝完成。
執行下列指令,確認安裝成功:
sudo systemctl status observiq-otel-collector服務應顯示為有效 (執行中)。
其他安裝資源
如需其他安裝選項和疑難排解資訊,請參閱 Bindplane 代理程式安裝指南。
設定 Bindplane 代理程式,擷取系統記錄檔並傳送至 Google SecOps
找出設定檔
Linux:
sudo nano /opt/observiq-otel-collector/config.yamlWindows:
notepad "C:\Program Files\observIQ OpenTelemetry Collector\config.yaml"
編輯設定檔
將
config.yaml的所有內容替換為下列設定:receivers: udplog: listen_address: "0.0.0.0:514" exporters: chronicle/quest_file_audit: compression: gzip creds_file_path: '/etc/bindplane-agent/ingestion-auth.json' customer_id: '<customer_id>' endpoint: malachiteingestion-pa.googleapis.com log_type: QUEST_FILE_AUDIT raw_log_field: body service: pipelines: logs/quest_file_audit_to_chronicle: receivers: - udplog exporters: - chronicle/quest_file_audit
設定參數
替換下列預留位置:
接收器設定:
listen_address:要接聽的 IP 位址和通訊埠:0.0.0.0,監聽所有介面 (建議)- 通訊埠
514是標準的系統記錄通訊埠 (在 Linux 上需要根層級權限;非根層級權限請使用1514)
匯出工具設定:
creds_file_path:擷取驗證檔案的完整路徑:- Linux:
/etc/bindplane-agent/ingestion-auth.json - Windows:
C:\Program Files\observIQ OpenTelemetry Collector\ingestion-auth.json
- Linux:
customer_id:從 Google SecOps 控制台複製的客戶 IDendpoint:區域端點網址:- 美國:
malachiteingestion-pa.googleapis.com - 歐洲:
europe-malachiteingestion-pa.googleapis.com - 亞洲:
asia-southeast1-malachiteingestion-pa.googleapis.com - 如需完整清單,請參閱「區域端點」
- 美國:
儲存設定檔
- 編輯完成後,請儲存檔案:
- Linux:依序按下
Ctrl+O、Enter和Ctrl+X - Windows:依序點選「檔案」>「儲存」
- Linux:依序按下
重新啟動 Bindplane 代理程式,以套用變更
如要在 Linux 中重新啟動 Bindplane 代理程式,請執行下列指令:
sudo systemctl restart observiq-otel-collector確認服務正在執行:
sudo systemctl status observiq-otel-collector檢查記錄中是否有錯誤:
sudo journalctl -u observiq-otel-collector -f
如要在 Windows 中重新啟動 Bindplane 代理程式,請選擇下列其中一個選項:
以管理員身分開啟命令提示字元或 PowerShell:
net stop observiq-otel-collector && net start observiq-otel-collector服務控制台:
- 按下
Win+R,輸入services.msc,然後按下 Enter 鍵。 - 找出 observIQ OpenTelemetry Collector。
- 按一下滑鼠右鍵,然後選取「重新啟動」。
確認服務正在執行:
sc query observiq-otel-collector檢查記錄中是否有錯誤:
type "C:\Program Files\observIQ OpenTelemetry Collector\log\collector.log"
- 按下
設定 Quest Change Auditor 系統記錄檔轉送
選項 1:使用 Change Auditor 用戶端設定系統記錄轉送
- 開啟「Change Auditor」用戶端應用程式。
- 依序前往「管理」>「事件訂閱」。
- 按一下「新增」,然後選取「Syslog」做為訂閱類型。
- 在 Syslog 事件訂閱精靈中,設定下列項目:
- 主機:輸入 Bindplane 代理程式主機的 IP 位址。
- 「Port」(通訊埠):輸入
514。 - 訊息格式:選取 CEF (通用事件格式) 或 LEEF (記錄事件擴充格式)。
- 子系統:選取要轉送的事件子系統 (例如「檔案系統」)。
- 按一下「完成」即可建立訂閱項目。
選項 2:使用 PowerShell 設定 Syslog 轉送
- 在 Change Auditor 協調器伺服器上開啟 PowerShell,然後匯入 Change Auditor 模組。
建立系統記錄事件訂閱:
$subsystems = Get-CAEventExportSubsystems | Where-Object { $_.Name -like "*File*" } New-CASyslogEventSubscription -Host "<BINDPLANE_AGENT_IP>" -Port 514 -SyslogFormat "CEF" -Subsystems $subsystems確認訂閱項目已建立:
Get-CASyslogEventSubscriptions
UDM 對應表
| 記錄欄位 | UDM 對應 | 邏輯 |
|---|---|---|
| Keywords、EventType、Task、ThreadID、Channel、Opcode | additional.fields | 事件的其他資訊 |
| EventTime | metadata.event_timestamp | 事件發生的時間戳記 |
| event_type | metadata.event_type | 活動類型 |
| EventReceivedTime | metadata.ingested_timestamp | 事件擷取時間的時間戳記 |
| EventID | metadata.product_event_type | 產品定義的事件類型 |
| RecordNumber | metadata.product_log_id | 產品指派的記錄 ID |
| metadata.product_name | 產生事件的產品名稱 | |
| metadata.vendor_name | 產生事件的供應商名稱 | |
| SourceModuleType | observer.application | 觀察者使用的應用程式 |
| SourceModuleName | observer.resource.attribute.labels | 與觀察器資源相關聯的標籤 |
| 網域 | principal.administrative_domain | 主體的管理網域 |
| SourceName | principal.application | 校長使用的應用程式 |
| 主機名稱 | principal.asset.hostname | 與主體相關聯的資產主機名稱 |
| ip_address | principal.asset.ip | 與主體相關聯的資產 IP 位址 |
| 主機名稱 | principal.hostname | 主體的主機名稱 |
| ip_address | principal.ip | 主體的 IP 位址 |
| ProcessID | principal.process.pid | 程序 ID |
| logonID | principal.user.attribute.labels | 與使用者相關聯的標籤 |
| AccountType | principal.user.attribute.roles | 與使用者相關聯的角色 |
| AccountName | principal.user.userid | 使用者 ID |
| UserID | principal.user.windows_sid | 使用者的 Windows SID |
| 說明 | security_result.description | 安全性結果說明 |
| SeverityValue | security_result.severity | 安全性結果的嚴重程度 |
| 嚴重性 | security_result.severity_details | 嚴重程度詳細資料 |
| 類別 | security_result.summary | 安全性結果摘要 |
| file_path | target.file.full_path | 目標檔案的完整路徑 |
| file_path | target.process.file.full_path | 與目標程序相關聯的檔案完整路徑 |
變更記錄
還有其他問題嗎?向社群成員和 Google SecOps 專業人員尋求答案。