收集 Quest File Access Audit 記錄

支援的國家/地區:

本文說明如何使用 Bindplane 代理程式,將 Quest File Access Audit 記錄擷取至 Google Security Operations。

Quest Change Auditor (舊稱 Quest File Access Audit) 是檔案伺服器和 Active Directory 稽核平台,可監控及回報 Windows 環境中的檔案存取活動、權限變更和管理動作。Change Auditor 提供內建的 SIEM 整合功能,包括透過事件訂閱轉送系統記錄。

事前準備

請確認您已完成下列事前準備事項:

  • Google SecOps 執行個體
  • Windows Server 2016 以上版本,或搭載 systemd 的 Linux 主機
  • Bindplane 代理程式與 Quest Change Auditor 協調器伺服器之間的網路連線
  • 如果透過 Proxy 執行,請確保防火牆通訊埠已根據 Bindplane 代理程式需求開啟
  • Quest Change Auditor 用戶端或協調器伺服器的特殊權限

取得 Google SecOps 擷取驗證檔案

  1. 登入 Google SecOps 控制台。
  2. 依序前往「SIEM 設定」>「收集代理程式」
  3. 下載擷取驗證檔案
  4. 將檔案安全地儲存在要安裝 Bindplane 的系統上。

取得 Google SecOps 客戶 ID

  1. 登入 Google SecOps 控制台。
  2. 依序前往「SIEM 設定」>「設定檔」
  3. 複製並儲存「機構詳細資料」部分中的客戶 ID

安裝 Bindplane 代理程式

請按照下列操作說明,在 Windows 或 Linux 作業系統上安裝 Bindplane 代理程式。

Windows 安裝

  1. 以管理員身分開啟「命令提示字元」或「PowerShell」
  2. 執行下列指令:

    msiexec /i "https://github.com/observIQ/bindplane-agent/releases/latest/download/observiq-otel-collector.msi" /quiet
    
  3. 等待安裝完成。

  4. 執行下列指令,確認安裝成功:

    sc query observiq-otel-collector
    

    服務應顯示為「RUNNING」

Linux 安裝

  1. 開啟具有根層級或 sudo 權限的終端機。
  2. 執行下列指令:

    sudo sh -c "$(curl -fsSlL https://github.com/observiq/bindplane-agent/releases/latest/download/install_unix.sh)" install_unix.sh
    
  3. 等待安裝完成。

  4. 執行下列指令,確認安裝成功:

    sudo systemctl status observiq-otel-collector
    

    服務應顯示為有效 (執行中)

其他安裝資源

如需其他安裝選項和疑難排解資訊,請參閱 Bindplane 代理程式安裝指南

設定 Bindplane 代理程式,擷取系統記錄檔並傳送至 Google SecOps

找出設定檔

  • Linux:

    sudo nano /opt/observiq-otel-collector/config.yaml
    
  • Windows:

    notepad "C:\Program Files\observIQ OpenTelemetry Collector\config.yaml"
    

編輯設定檔

  • config.yaml 的所有內容替換為下列設定:

    receivers:
        udplog:
            listen_address: "0.0.0.0:514"
    
    exporters:
        chronicle/quest_file_audit:
            compression: gzip
            creds_file_path: '/etc/bindplane-agent/ingestion-auth.json'
            customer_id: '<customer_id>'
            endpoint: malachiteingestion-pa.googleapis.com
            log_type: QUEST_FILE_AUDIT
            raw_log_field: body
    
    service:
        pipelines:
            logs/quest_file_audit_to_chronicle:
                receivers:
                    - udplog
                exporters:
                    - chronicle/quest_file_audit
    

設定參數

替換下列預留位置:

  • 接收器設定:

    • listen_address:要接聽的 IP 位址和通訊埠:
      • 0.0.0.0,監聽所有介面 (建議)
      • 通訊埠 514 是標準的系統記錄通訊埠 (在 Linux 上需要根層級權限;非根層級權限請使用 1514)
  • 匯出工具設定:

    • creds_file_path:擷取驗證檔案的完整路徑:
      • Linux/etc/bindplane-agent/ingestion-auth.json
      • WindowsC:\Program Files\observIQ OpenTelemetry Collector\ingestion-auth.json
    • customer_id:從 Google SecOps 控制台複製的客戶 ID
    • endpoint:區域端點網址:
      • 美國malachiteingestion-pa.googleapis.com
      • 歐洲europe-malachiteingestion-pa.googleapis.com
      • 亞洲asia-southeast1-malachiteingestion-pa.googleapis.com
      • 如需完整清單,請參閱「區域端點

儲存設定檔

  • 編輯完成後,請儲存檔案:
    • Linux:依序按下 Ctrl+OEnterCtrl+X
    • Windows:依序點選「檔案」>「儲存」

重新啟動 Bindplane 代理程式,以套用變更

  • 如要在 Linux 中重新啟動 Bindplane 代理程式,請執行下列指令:

    sudo systemctl restart observiq-otel-collector
    
    1. 確認服務正在執行:

      sudo systemctl status observiq-otel-collector
      
    2. 檢查記錄中是否有錯誤:

      sudo journalctl -u observiq-otel-collector -f
      
  • 如要在 Windows 中重新啟動 Bindplane 代理程式,請選擇下列其中一個選項:

    • 以管理員身分開啟命令提示字元或 PowerShell:

      net stop observiq-otel-collector && net start observiq-otel-collector
      
    • 服務控制台:

      1. 按下 Win+R,輸入 services.msc,然後按下 Enter 鍵。
      2. 找出 observIQ OpenTelemetry Collector
      3. 按一下滑鼠右鍵,然後選取「重新啟動」
      4. 確認服務正在執行:

        sc query observiq-otel-collector
        
      5. 檢查記錄中是否有錯誤:

        type "C:\Program Files\observIQ OpenTelemetry Collector\log\collector.log"
        

設定 Quest Change Auditor 系統記錄檔轉送

選項 1:使用 Change Auditor 用戶端設定系統記錄轉送

  1. 開啟「Change Auditor」用戶端應用程式。
  2. 依序前往「管理」>「事件訂閱」
  3. 按一下「新增」,然後選取「Syslog」做為訂閱類型。
  4. 在 Syslog 事件訂閱精靈中,設定下列項目:
    • 主機:輸入 Bindplane 代理程式主機的 IP 位址。
    • 「Port」(通訊埠):輸入 514
    • 訊息格式:選取 CEF (通用事件格式) 或 LEEF (記錄事件擴充格式)。
    • 子系統:選取要轉送的事件子系統 (例如「檔案系統」)。
  5. 按一下「完成」即可建立訂閱項目。

選項 2:使用 PowerShell 設定 Syslog 轉送

  1. 在 Change Auditor 協調器伺服器上開啟 PowerShell,然後匯入 Change Auditor 模組。
  2. 建立系統記錄事件訂閱:

    $subsystems = Get-CAEventExportSubsystems | Where-Object { $_.Name -like "*File*" }
    New-CASyslogEventSubscription -Host "<BINDPLANE_AGENT_IP>" -Port 514 -SyslogFormat "CEF" -Subsystems $subsystems
    
  3. 確認訂閱項目已建立:

    Get-CASyslogEventSubscriptions
    

UDM 對應表

記錄欄位 UDM 對應 邏輯
Keywords、EventType、Task、ThreadID、Channel、Opcode additional.fields 事件的其他資訊
EventTime metadata.event_timestamp 事件發生的時間戳記
event_type metadata.event_type 活動類型
EventReceivedTime metadata.ingested_timestamp 事件擷取時間的時間戳記
EventID metadata.product_event_type 產品定義的事件類型
RecordNumber metadata.product_log_id 產品指派的記錄 ID
metadata.product_name 產生事件的產品名稱
metadata.vendor_name 產生事件的供應商名稱
SourceModuleType observer.application 觀察者使用的應用程式
SourceModuleName observer.resource.attribute.labels 與觀察器資源相關聯的標籤
網域 principal.administrative_domain 主體的管理網域
SourceName principal.application 校長使用的應用程式
主機名稱 principal.asset.hostname 與主體相關聯的資產主機名稱
ip_address principal.asset.ip 與主體相關聯的資產 IP 位址
主機名稱 principal.hostname 主體的主機名稱
ip_address principal.ip 主體的 IP 位址
ProcessID principal.process.pid 程序 ID
logonID principal.user.attribute.labels 與使用者相關聯的標籤
AccountType principal.user.attribute.roles 與使用者相關聯的角色
AccountName principal.user.userid 使用者 ID
UserID principal.user.windows_sid 使用者的 Windows SID
說明 security_result.description 安全性結果說明
SeverityValue security_result.severity 安全性結果的嚴重程度
嚴重性 security_result.severity_details 嚴重程度詳細資料
類別 security_result.summary 安全性結果摘要
file_path target.file.full_path 目標檔案的完整路徑
file_path target.process.file.full_path 與目標程序相關聯的檔案完整路徑

變更記錄

查看這個剖析器的變更記錄

還有其他問題嗎?向社群成員和 Google SecOps 專業人員尋求答案。