Configuring NetFlow Collector

To collect and analyze NetFlow statistics logs from Cisco routers and switches, you must add details about Netflow Collector devices in Logpoint. This includes entering the device names and IP addresses and selecting relevant device groups. You must also specify how the logs will be managed, processed, and stored. This ensures effective log management by facilitating accurate log collection, proper formatting, and timely analysis, which are crucial for identifying security incidents and maintaining compliance. All these are done in Configuring Netflow Collector.

Note

While we provide Windows-specific instructions in this guide, it’s important to be aware that the Windows interface may change over time. To ensure you have the most up-to-date information and to navigate any potential changes in the Windows interface, we recommend going to the official Windows documentation .

Adding Logpoint as a Device in Windows

  1. Go to Flowalyzer on Windows.

  2. Enter 9001 in UDP Port.

  3. Enter Logpoint IP in IP Address.

  4. Click Apply.

_images/netflow.png

Adding Logpoint as Device in Windows

Configuring NetFlow Collector from Devices

Configuring a Repo for NetFlow Collector

  1. Go to Settings >> Configuration from the navigation bar and click Repos.

  2. Click Add.

  3. Enter a Repo Name.

  4. Select a Repo Path to store incoming logs.

  5. Set a Retention Day to keep logs in a repository before they are automatically deleted. You can add and remove multiple Repo Paths and Retention Days.

_images/adding_repo.png

Adding a Repo

  1. Click Submit.

Adding a Processing Policy

A Processing Poliicy combines normalization, enrichment and routing policies into a single policy that is then assigned to a NetFlow device.

  1. Go to Settings >> Configuration from the navigation bar and click Processing Policies.

  2. Click ADD.

  3. Enter a Policy Name.

  4. Select the Normalization Policy. This is optional for NetFlow Collector.

  5. Select the Enrichment Policy and Routing Policy.

_images/processing_policy.png

Adding a Processing Policy

  1. Click Submit.

Adding a NetFlow Device

  1. Go to Settings >> Configuration >> Devices.

  2. Click Add.

  3. Enter a device Name.

  4. Enter the IP address(es) of the Windows server.

  5. Select the Device Groups.

  6. Select a Log Collection Policy.

  7. If you use a distributed Logpoint, select a collector from the Distributed Collector dropdown.

  8. Select a Time Zone. The timezone must be same as of NetFlow.

  9. Enter the Inactivity Threshold in minutes. It specifies the time after which to mark the device as inactive in Last Log Received under device lists if logs are not received. You can enter a value from 5 to 525600.

  10. Configure the Risk Values for Confidentiality, Integrity and Availability used to calculate the risk levels of the alerts generated from the device.

_images/create_device.png

Creating a Device

  1. Click Save.

Configuring NetFlow Collector on a Device

  1. Go to Settings >> Configuration from the navigation bar and click Devices.

  2. Click the Add icon from Actions of the previously added device.

  3. Click NetFlow Collector.

_images/available_collectorfetcher.png

Available Collectors Fetchers

  1. Select the previously created Processing Policy.

  2. Click Submit.

_images/netflowcollector.png

NetFlow Collector

Configuring NetFlow Collector from Log Source

  1. Go to Settings >> Log Sources from the navigation bar and click Add Log Source.

  2. From the list of templates, select NetFlow Collector.

Source

In source, you can add details about the log source from where Netflow collects logs.

  1. Click Source.

  2. Enter the Log Source’s Name.

  3. Enter the Device Addresses.

  4. Select the Device Groups.

  5. Select a Time Zone. The timezone must be same as of NetFlow.

  6. Enter the Inactivity Threshold in minutes. It specifies the time after which to mark a log source as inactive in Last Log Received under Settings >> Log Source if logs are not received. You can enter a value from 5 to 525600.

  7. Configure the Risk Values for Confidentiality, Integrity and Availability used to calculate the risk levels of the alerts generated from the device.

_images/Source.png

Configuring Source

Connector

A connector transmits logs from Cisco to Logpoint. You use a connector to configure how NetFlow Collector and Cisco communicate with each other. If you use a distributed Logpoint, select a collector from the Distributed Collector dropdown.

_images/connector.png

Configuring Connector

Routing

In routing, you can create repos and routing criteria for NetFlow Collector. Repos are locations where incoming logs are stored and routing criteria is created to determine the conditions under which these logs are sent to repos.

To create a repo:

  1. Click Routing and + Create Repo.

  2. Enter a Repo name.

  3. In Path, enter the location to store incoming logs.

  4. In Retention (Days), enter the number of days logs are kept in a repository before they are automatically deleted.

  5. In Availability, select the Remote logpoint and Retention (Days).

_images/create_repo.png

Creating a Repo

  1. Click Create Repo.

In Repo, select the created repo to store logs.

To create Routing Criteria:

  1. Click + Add row.

  2. Enter a Key and Value. The routing criteria is only applied to those logs which have this key-value pair.

  3. Select an Operation for logs that have this key-value pair.

    3.1. Select Store raw message to store both the incoming and the normalized logs in the selected repo.

    3.2. Select Discard raw message to discard the incoming logs and store the normalized ones.

    3.3. Select Discard entire event to discard both the incoming and the normalized logs.

  4. In Repository, select a repo to store logs.

_images/Routing.png

Creating a Routing Criteria

Click the (uninstall) icon under Action to delete the created routing criteria.

Normalization

In normalization, you can select normalizers for the incoming logs. Normalizers translate a raw log message into Logpoint taxonomy. This step is optional for NetFlow Collector.

  1. Click Normalization.

  2. You can either select a previously created normalization policy from the Select Normalization Policy dropdown or select a Normalizer from the list and click the swap(Swap) icon.

Enrichment

In enrichment, you can select an enrichment policy for the incoming logs. Enrichment policies are used to add additional information to a log, such as user information, device type or geolocation, before analyzing it. This step is optional for NetFlow Collector.

  1. Click Enrichment.

  2. Select an Enrichment Policy.

Click Create Log Source to save the configurations of Source, Connector, Routing, Normalization, and Enrichment.


Helpful?

We are glad this guide helped.


Please don't include any personal information in your comment

Contact Support