Cloudera Docs
»
1.2.2
»
Administration
Administration
Also available as:
Contents
1. HCP Information Roadmap
2. Introduction to Hortonworks CyberSecurity Suite
HCP Architecture
Real-time Processing Security Engine
Telemetry Data Collectors
Data Services and Integration Layer
Understanding HCP Terminology
3. Configuring and Customizing
Adding a New Telemetry Data Source
Prerequisites
Streaming Data into HCP
Creating a NiFi Flow to Stream Events to HCP
Parsing a New Data Source to HCP
Using the Management Module User Interface
Using the CLI
Verifying That the Events Are Indexed
Enriching Telemetry Events
Bulk Loading Enrichment Information
Configuring an Extractor Configuration File
Configuring Element-to-Enrichment Mapping
Running the Enrichment Loader
Mapping Fields to HBase Enrichments
Management Module UI Method
CLI Method
Streaming Enrichment Information
Configuring Indexing
Default Configuration
Specifying Index Parameters
Specifying Index Parameters using the Management Module
Specifying Index Parameters Using the CLI
Turning Off HDFS Writer
Using Threat Intelligence Feeds
Prerequisites
Bulk Loading Threat Intelligence Information
Configuring an Extractor Configuration File
Configure Mapping for the Intelligence Feed
Running the Threat Intel Loader
Mapping Fields to HBase Threat Intel
Management Module Method
CLI Method
Creating a Streaming Threat Intel Feed Source
Prioritizing Threat Intelligence
Prerequisites
Performing Threat Triage Using the Management Module
Performing Threat Triage Using the CLI
Creating the Threat Triage Rule Configuration
Uploading the Threat Triage Configuration to ZooKeeper
Viewing Triaged or Scored Alerts
Setting Up Enrichment Configurations
Global Configuration
Sensor Configuration
Configuring the Profiler
Configuring the Profiler
Creating an Index Template
Configuring the Metron Dashboard to View the New Data Source Telemetry Events
Setting up PCAP to View Your Raw Data
Setting up pycapa
Starting PCAP
Setting up Fastcapa
Prerequisites
Automated Installation
Manual Installation
Enable Transparent Huge Pages
Install DPDK
Install Librdkafka
Install Fastcapa
Using Fastcapa
Parameters
Environmental Abstraction Layer Parameters
Fastcapa-Core Parameters
Fastcapa-Kafka Configuration File
Output
Using Fastcapa in a Kerberized Environment
Troubleshooting Parsers
Storm is Not Receiving Data From a New Data Source
Determining Which Events Are Not Being Processed
4. Monitor and Management
Understanding Throughput
Updating ZooKeeper
Managing Sensors
Modifying a Sensor
Deleting a Sensor
Monitoring Sensors
Displaying the Metron Error Dashboard
Default Metron Error Dashboard
Loading Metron Templates
Starting and Stopping Parsers
Starting and Stopping Enrichments
Starting and Stopping Indexing
Modifying the Elasticsearch Template
5. Concepts
Parsers
Java Parsers
General Purpose Parsers
Parser Configuration
fieldTransformation Configuration
Telemetry Data Source Parsers Bundled with Hortonworks Cybersecurity Suite
Snort
Bro
YAF (NetFlow)
Indexing
pcap
Enrichment Framework
Sensor Enrichment Configuration
Individual Sensor Enrichments
Stellar Enrichment Configuration
Threat Intelligence Enrichments
Using Stellar to Set up Threat Triage Configurations
Global Configuration
Using Stellar for Queries
Using Stellar to Transform Sensor Data Elements
Management Utility
Fastcapa
A. Stellar Language Functions
Stellar Benchmarks
« Prev
Next »
Troubleshooting Parsers
This section provides some troubleshooting solutions for parser issues.
© 2012–2020, Cloudera, Inc.
Document licensed under the
Creative Commons Attribution ShareAlike 4.0 License
.
Cloudera.com
|
Documentation
|
Support
|
Community