The Log Forwarder Agent is designed to streamline the data collection processes from third party data collection services. It serves as a great alternative for fast and accessible deployment where the recommended Virtual Appliance (VA) is not feasible due to resource constraints. It streamlines log forwarding from third-party services and works with your existing security infrastructure to improve Continuous Compromise Assessment. It offers the option to create Netflow Collectors, a seamless way to integrate with metadata collected by Security Information and Event Management (SIEM) technologies.
The Netflow collector collects metadata of flows (Netflow/IPFIX) passing over a network device such as a switch. Among other malicious behaviors, network flows provide insights into an organization’s devices that are controlled by adversaries and attempting to move laterally.
In this article, you will learn how add the Netflow Collector to your Log Forwarder Agent. For more information on how to create and install the Log Forwarder Agent, refer to the Deploy Collectors with Log Forwarder for Windows article.
Each Netflow/IPFIX collector can only receive data from a single switch. To collect data from multiple switches, you must create a separate collector for each one.
You will need to configure at least one collector for the Log Forwarder Agent to work.
You can configure different collectors for different devices.
1. On the Lumu Portal, head to the Collectors category on the left panel, then click on Log Forwarder. You will see a list of all your Log Forwarder Agents. Click on the one you want to add collectors to.
2. Once on the Log Forwarder Details page, click on Add Collector.
3. Name your collector and choose the Netflow/IPFIX collector.
4. Enter the UDP Listener Port and select the correct Timezone.
5. Your newly created collector will be shown under the Collectors section of the Log Forwarder Details page.