When
deploying your SIEM Solution Infrastructure with HP ArcSight products, you may
consider installing more than one Logger systems for several reasons.
Without
going too much into detail for these reasons, let’s name the 2 major ones,
first reaching the computation levels on your system (RAM, CPU or 15000 EPS
level indicated in HP ArcSight documents) and second providing redundancy,
installing an ArcSight Logger appliance for each datacenter for not consuming
too much bandwidth to send logs.
Whatever
the reason for using several ArcSight Loggers, the problem of lookup in several
databases appears.
The
solution for this problem is establishing peering between your Logger
appliances. Once peering is established, the pattern you are searching for is
executed on all peer Loggers and the result is shown on the Logger you
initiated the search.
Below you
can find the details on peer configuration between two Loggers.
For peering 2 or more loggers should first authenticate each other. For authentication, 2 methods exist:
Authentication with a logger user credentials
Authentication with Peer Authorization ID and Code
In this article, we will follow the second method to prevent any problems that may be caused by the user credentials in the first method.
Let's assume, we will initiate the peering on Logger1. To be able to realize it, we should first log in to the Logger2 and generate the Authorization ID and Code for Logger 2.
Once the first step is done, generated values must be entered on Logger1. After successfully saving the configuration Logger Peering is done and logs can be queried through either of the loggers.
UPDATE 29/07/2015: There is something odd about peering config for Loggers. "Add Peer Logger"
option must be configured on both loggers and it is not enough so see one line of peer Logger under Peer Loggers menu. Authorization ID and Code generated on Logger2 for Logger1 must be entered on Logger1 and vice versa. At the end of successfull configuration, you should see 2 identical lines for each Logger you established peering relation under Peer Loggers menu.
Logger 6.0
P2 is now available for download from HP Software support download page. Note
that it is referred to as Logger 6.02 on the download site.
Logger 6.0
P2 includes:
Important
security updates (Honestly I could not find what those updates are in the
release notes, even though I went through
the document for multiple times)
A fix to
peer search (LOG-13574).
Modifications
to SOAP APIs:
SOAP API
login events in Audit logs
SOAP login
API now uses the authentication method configured in Logger, which can be an
external authentication method, such as Radius. Clients using the SOAP login
API must now pass the login credentials for the authentication method
configured in Logger (e.g. Radius credentials) instead of the credentials of a
local Logger user.
2014 and
2015 have been years full of discoveries on cryptographic and algorithmic
vulnerabilities starting with Heartbleed following with POODLE and several others.
These vulnerabilities pushed many administrators patch their webservers,
disable vulnerable protocols (SSLv2, SSLv3 and even TLS1.0) and cipher suites
containing weak algorithms (RC4, SHA1, MD5 and others).
ArcSight
systems, working over web interfaces, are also subject to these vulnerabilities
and possible attacks. Apache web server hosting Logger and Management Center
interfaces should be configured to eliminate the cryptographic algorithm and
protocol threats.
First of
all, to know the status of webserver, we will use the sslscan application with
given parameters.
From this
output we can see that SSLv2 and SSLv3 protocols are already disabled but
protocols such as RC4, DES and Diffie-Hellman are still accepted.
In order to
force the webserver to use secure algorithms and protocols we will modify
apache configuration file httpd.conf under <LOGGER_INSTALLATION_DIRECTORY> /local/apache/conf directory, which in my own installation is /opt/arcsight/current/local/apache/conf/.
It is wise to take a backup of the httpd.conf file before making any changes.
# cp
httpd.conf httpd.conf.backup
Then we
should edit this file with a text editor such as nano or vi.
We should
modify the line starting with SSLProtocol
and SSLCipherSuite as follows
and save the file.
After this
operation, so that the changes become active we should restart logger services
under <LOGGER_INSTALLATION_DIRECTORY>/arcsight/logger/bin
directory with ./loggerd
restart command.
When we recheck with sslscan, we see that vulnerable
options are no longer supported.
HP Arcsight Logger product constitutes the log management part of HP's Security Event Management and Log Management product portfolio, ESM being the security event management part.
Before getting this much into SEM and Log Management, they both meant the same thing for me, as most of the products available on the market were trying to do. Architecture-wise, Arcsight managed to distinguish its offerings for different needs and markets. This issue is the topic of another blog entry however if you are looking for a product which will allow you to store all your logs in a stable way and query specific patterns very quickly then Arcsight Logger is the solution you are looking for.
As of mid-2015, the latest version of HP Arcsight Logger is the 6.0 SP1 version with no known security bugs. Arcsight 6.0 SP1 :
Distributes latest version of OpenSSL, 0.9.8zc, which addresses multiple vulnerabilities including CVE-2014-0224.
Resolves the Bourne-Again Shell (Bash) Code Injection Vulnerability, including CVE-2014-6271, CVE-2014-7169, CVE-2014-7186, CVE-2014-7187, CVE-2014-6277, and CVE-2014-6278.
Disables support for SSL v3.0 encryption, to address the Padding Oracle On Downgraded Legacy Encryption (POODLE) vulnerability (CVE-2014-3566).
Version 6.0 SP1 also brings support for doubled local storage size. Each instance of logger now can support up to 8TB of logs before sending logs to archive.
In this article, I tried to resume how you can get your Logger up and running in a short amount of time. This is also the first time for me to include a video which obviously makes the article more interesting.
The installation of Arcsight Logger is a 2 step process, Preparation and Installation itself.
For the preparation you should of course have your server equipped with necessary resources (just like all other Log Management products, Logger also is greedy in resources), Logger software, license,user accounts (root privileges are required for the installation) and ports. PREPARATION Server Requirements OS
Red Hat Enterprise Linux (RHEL) versions 6.2 and 6.5 (64-bit),
CentOS versions 5.5 and 6.5 (64-bit)
Hardware For the Trial Logger and VM Instances:
CPU: 1 or 2 x Intel Xeon Quad Core or equivalent
Memory: 4 - 12 GB (12 GB recommended)
Disk Space: 10 GB (minimum) in the Logger installation directory (/opt/...)
Temp directory: 1 GB
For the Enterprise Version of Software Logger:
CPU: 2 x Intel Xeon Quad Core or equivalent
Memory: 12 - 24 GB (24 GB recommended)
Disk Space: 65 GB (minimum) in the Software Logger installation directory. (/opt/...)
Root partition: 400 GB
Temp directory: 1 GB
For performance reasons, it is preferable to use dedicated hardware for Logger rather than using virtual machines. For faster searchs archive connections should be over direct fiber channel rather over NFS.
Logger interface can be reached through all known browsers with recent versions.
Logger can be installed using root and non-root accounts but following points should be taken into consideration:
For root installs, allow access to port 443 as well as the ports for any protocol that thelogger receivers need, such as port 514 for the UDP receiver and port 515 for the TCP receiver.
For non-root installs, allow access to port 9000 as well as the ports for any protocol that the Logger receivers need, such as port 8514 for the UDP receiver and port 8515 for the TCP receiver.
INSTALLATION
You can follow instructions given below. The video also follows the same steps.
1. Install Linux Server (Minimal Server with GUI for trial installations). Do not "Easy Install" when using Vmware and manually set partitions
2. Adjust partitions as below as a minimum:
/10240 MB
/home10240 MB
swap4096 MB(Typically half of your RAM but do not exagerrate)
/opt70000 MB(Give Minimum 65 GB, more is better)
/tmp2048 MB