Project Creation
- Go to “Settings”->“System Settings”. Click on “Add New Project”.
- Select “Custom” from the list and click on “Create Project” on the next page.
- This is where you will start configuring the project.
- Instance Type – Private Cloud
- Data Type – Log
- Agent Type – Live Streaming
(See Figure 1)
- Click on “Next” and you will be taken to the next page.
- Then on the next page, you can type in the “Project Name” and “System Name” and click on Register. You can also define detection keywords and Incident labels.
-
- Detection keywords/regular expressions are used to detect which log entries will produce allowlist alerts.
- Incident labels/regex are used to identify which log entries indicate incidents.
(See Figure 2)
- Once a project is successfully created, you will see a message like below.
(See Figure 3) - Once a project is successfully created, you need to set-up an agent.
-
Agent Setup
You would need a server where you can run this agent.
- For container:
- Access the image
- Follow the steps from the overview section to use the agent
- For GitHub:
- Download the agent from the link on the server.
- Follow the steps from the link to install the agent on the server.
Once you have an agent running, you will be able to see the data streaming into the InsightFinder project. To check,
- Go to Analysis->Log/Trace Analysis.
- Select your project and date. Click on the Refresh button on the right top. You will get the calendar view of log data.
(See Figure 4)