#MicroFocusCyberSummit
ESM 7 Distributed Correlation
Paul MacGyver Carman Global Technical Security Sales Engineer
ESM 7 Distributed Correlation Paul MacGyver Carman Global Technical - - PowerPoint PPT Presentation
ESM 7 Distributed Correlation Paul MacGyver Carman Global Technical Security Sales Engineer #MicroFocusCyberSummit Confidential information This is a rolling (up to three year) Roadmap and is subject to change without notice Confidential
#MicroFocusCyberSummit
Paul MacGyver Carman Global Technical Security Sales Engineer
This is a rolling (up to three year) Roadmap and is subject to change without notice
2
Confidential information. This Roadmap contains Confidential Information of Micro Focus and/or its affiliates (“Micro Focus”), and is subject to change without notice. If you have a valid Confidential Disclosure Agreement (“CDA”) with a Micro Focus entity, use of the Roadmap is subject to that CDA and allowed solely for the purpose of evaluating purchase decisions from Micro Focus. If not, it is subject to the following terms. For 3 years after disclosure, You may use the Roadmap solely for the purpose of evaluating purchase decisions from Micro Focus. You must use a reasonable standard of care to prevent disclosure. You will not disclose the contents
becomes publically known or is rightfully received by you from a third party without duty of confidentiality.
Why Distributed Correlation? Distributed Correlation Architecture
Deployment and Sizing Examples
Monitoring the ESM Cluster Next Steps
3
correlated events per second per cluster
needed to scale out
required between layers
heavier content
Split data stream to parallel processes across multiple nodes in a cluster Clustered correlation Centralized Alerts and Content building
HPE Confidential, under NDA use only
6
Persistor
UI Interaction
ACC Console Connectors / EB Legend
Data Exchange Event Intake and Persistence Repo Information Exchange
Isolate persistence
CORRE DB
7
Persistor
UI Interaction
ACC Console Connectors / EB Legend
Data Exchange Event Intake and Persistence Repo Information Exchange
Correlators Correlators Correlators: filter evaluation
CORRE DB
8
UI Interaction
Legend
Data Exchange Event Intake and Persistence Repo Information Exchange
Aggregators Aggregators Aggregators: grouping Persistor ACC Console Connectors / EB Correlators Correlators
CORRE DB
Aggregators Aggregators Persistor ACC Console Connectors / EB Correlators Correlators
CORRE DB
9
UI Interaction
Legend
Data Exchange Event Intake and Persistence Repo Information Exchange
Message Bus: events, data M e s s a g e B u s
Aggregators Aggregators Persistor ACC Console Connectors / EB Correlators Correlators
CORRE DB
M e s s a g e B u s
10
UI Interaction
Legend
Data Exchange Event Intake and Persistence Repo Information Exchange
Distributed Cache: lists, resources D i s t r i b u t e d C a c h e
Aggregators Aggregators Persistor ACC Console Connectors / EB Correlators Correlators
CORRE DB
M e s s a g e B u s D i s t r i b u t e d C a c h e
11
UI Interaction
Legend
Data Exchange Event Intake and Persistence Repo Information Exchange
Repository: global settings Repository
12
Aggregators Correlators Persistor Aggregators Correlators Connectors, EB, ESM, ...
Persisted & Enriched Correlation, Audit Rule Data Monitor Audit Correlation, Audit Audit
Where correlation happens
Pre-persistence Rules Light-weight Rules Standard Rules, Data Monitors
14
Persistor Mbus_control Repo Correlator Aggregator Mbus_control Mbus_data Repo Correlator Aggregator Mbus_control Mbus_data Repo
ESM Node 1 ESM Node 2 ESM Node 3
Includes DCache)
across nodes
15
ESM Node 1 ESM Node 2 ESM Node 4 ESM Node 3
Persistor Repo Correlator Aggregator DCache Mbus_data Mbus_control Correlator Correlator Repo Mbus_data Mbus_control Aggregator Aggregator DCache Mbus_data Mbus_control Repo Includes DCache)
16
ESM Node 1
Persistor Repo
ESM Node 2
Correlator Correlator Aggregator DCache Mbus_cont Mbus_data
ESM Node 3
Correlator Correlator Aggregator Repo Mbus_cont Mbus_data
ESM Node 4
Correlator Correlator Aggregator DCache Mbus_cont Mbus_data Repo
ESM Node 5
DCache Mbus_data Includes DCache) Correlator Correlator Aggregator
possible
for redundancy
make a good pair for a node, usually 2C:1A
DCache
very memory intensive – no more than 3 total on a node
is a good idea
instance
17
18
monitor cluster
in the console
to MB and DC
correlator and aggregators
updated
20
Download ESM 7
under maintenance
Distributed Modes
Download and Review the Documentation
Review your Requirements with SE and/or PS
is right for you
#MicroFocusCyberSummit
#MicroFocusCyberSummit