The Lumu Virtual Appliance (VA) offers the option to create VA collectors, a seamless way to integrate the network metadata of your entire enterprise into the Lumu cloud with the lowest impact on the network operation.
Collecting metadata other than DNS requests is important since some attacks avoid domain resolution, leaving traces of their contacts in the access logs of firewalls, proxies, etc. This option is also available for accommodating networks where DNS configuration is not possible. In this scenario, companies can monitor IP traffic with the Lumu Virtual Appliance acting as a network metadata collector on your enterprise perimeter.
This approach ensures compromise visibility without having to make major changes, as almost every cybersecurity vendor solution can forward metadata externally without impacting their operation.
All detailed steps to create, download, and install a virtual appliance on your preferred hypervisor or Cloud solution are available in our documentation:
Go to the Lumu Virtual Appliance and refresh the VA collectors settings by running the command lumu-appliance collectors refresh. If the appliance is running, it should be stopped for setting up collectors.
Once you have installed and configured a Lumu Virtual Appliance with the respective collector, the next step is to set up the vendor solution to forward metadata to Lumu. Please consult the vendor documentation on instructions to set up or forward logs to the Lumu Virtual Appliance.
You can find documentation from Lumu with more specific guidance and links to the following vendors: