Configure a Secure Network Analytics Data Store
Configure a Secure Network Analytics data store deployment to integrate SAL (OnPrem) with threat defense devices that are Security Cloud Control-managed.
Before you begin
Ensure the following:
-
You have a provisioned Security Cloud Control tenant and have the following Security Cloud Control user roles:
-
Admin
-
Super admin
-
-
Your threat defense devices are working as expected and generating events.
-
If you are currently using syslog to send events to the Secure Network Analytics appliance from device versions that support sending events directly, disable syslog for those devices (or assign those devices an access control policy that does not include syslog configurations) to avoid duplicate events on the remote volume.
-
Gather the following information:
-
The hostname or the IP address of your Secure Network Analytics Manager.
-
The IP address of your flow collector.
-
Note | You may be logged out of the Secure Network Analytics Manager during the registration process; complete any work in progress before you start with the deployment wizard. |
Procedure
Step 1 | Log in to Security Cloud Control. | ||
Step 2 | From the Security Cloud Control menu, navigate to open the Services page. | ||
Step 3 | Choose Cloud-Delivered FMC and click Configuration. | ||
Step 4 | Navigate to . | ||
Step 5 | In the Secure Network Analytics Data Store widget, click Start. | ||
Step 6 | Enter the hostname or the IP address and port number of the flow collector. To add more flow collectors, click +Add another Flow Collector. | ||
Step 7 | If you have configured more than one flow collector, associate the managed devices with different flow collectors:
| ||
Step 8 | Click Next. | ||
Step 9 | Deploy the changes to the registered managed devices. The event data is not logged to the SAL (OnPrem) until the logging policy changes are deployed to the registered threat defense devices.
You can view and work with these remotely stored events in the event viewer and context explorer in the management center, and include them when generating reports. You can also cross-launch from an event in the management center to view related data on your Secure Network Analytics Manager. For more information, see the online help for the management center. |