FortiSIEM Configuring Virtualization

Configuring Virtualization

AccelOps supports these virtualization servers for discovery and monitoring.

HyperV Configuration

VMware ESX Configuration

HyperV Configuration
What is Discovered and Monitored
Protocol Information discovered Metrics collected Used for
Powershell over WMI   CPU, Memory, Network and Storage metrics both at Guest and Host level . Performance Monitoring

PH_DEV_MON_HYPERV_CPU_GUEST_VIRTUAL_PROC: HyperV Guest Virtual Processor Usage

 

PH_DEV_MON_HYPERV_MEM_VID_PARTITION_PER_VM: HyperV per-VM VID Partition Memory Usage

[PH_DEV_MON_HYPERV_MEM_VID_PARTITION_PER_VM]:[phyMachIpAddr]=172.16 .20.180,[phyMachName]=WIN-HH2MFBPMHMR,[hostIpAddr]=172.16.20.185,[h ostName]=accelops-reporter-hyperv-4.3.1.1158,[vmName]=accelops-repo rter-hyperv-4.3.1.1158,[physicalPages]=1050632,[remotePages]=0

PH_DEV_MON_HYPERV_MEM_OVERALL: HyperV Root Memory Usage

[PH_DEV_MON_HYPERV_MEM_OVERALL]:[hostIpAddr]=172.16.20.180,[hostNam e]=WIN-HH2MFBPMHMR,[freeMemKB]=27519348,[pageFaultsPersec]=0

PH_DEV_MON_HYPERV_NET_VIRTUAL_SWITCH: HyperV Virtual Switch Network Usage

[PH_DEV_MON_HYPERV_NET_VIRTUAL_SWITCH]:[hostIpAddr]=172.16.20.180,[ hostName]=WIN-HH2MFBPMHMR,[vSwitch]=broadcom bcm5709c netxtreme ii gige [ndis vbd client] _34 – virtual

switch,[recvBitsPerSec]=719403.45,[recvPktsPerSec]=323.03,[sentBits PerSec]=3382443.50,[sentPktsPerSec]=283.90,[totalPktsPerSec]=323.03 [PH_DEV_MON_HYPERV_NET_VIRTUAL_SWITCH]:[hostIpAddr]=172.16.20.180,[ hostName]=WIN-HH2MFBPMHMR,[vSwitch]=broadcom bcm5709c netxtreme ii gige [ndis vbd client] _34 – virtual

switch,[recvBitsPerSec]=719403.45,[recvPktsPerSec]=323.03,[sentBits PerSec]=3382443.50,[sentPktsPerSec]=283.90,[totalPktsPerSec]=323.03

PH_DEV_MON_HYPERV_NET_VIRTUAL_ADAPTER: HyperV Virtual Switch Per Adapter Network Usage

[PH_DEV_MON_HYPERV_NET_VIRTUAL_ADAPTER]:[phyMachIpAddr]=172.16.20.1 80,[phyMachName]=WIN-HH2MFBPMHMR,[hostIpAddr]=172.16.20.182,[hostNa me]=accelops-va-hyperv-4.3.1.1158,[vmName]=accelops-va-hyperv-4.3.1 .1158,[intfName]=adapter_e1eb0a1f-1b36-48fe-be79-fde20d335364–3157 5d2f-5085-45d3-905f-2f3e17342a81,[recvBitsPerSec]=64970.24,[recvPkt sPerSec]=20.86,[sentBitsPerSec]=124741.68,[sentPktsPerSec]=42.61,[t otalPktsPerSec]=20.86

PH_DEV_MON_HYPERV_STORAGE_VIRTUAL_STORAGE: HyperV Virtual Storage Usage

HyperV Disk I/O Warning

HyperV Disk I/O Critical

HyperV Guest Critical

HyperV Guest Hypervisor Run Time Percent Warning

HyperV Logical Processor Total Run Time Percent Critical

HyperV Logical Processor Total Run Time Percent Warning

HyperV Page fault Critical

HyperV Page fault Warning

HyperV Remainining Guest Memory Warning

Reports

Look in Analytics > Reports > Device > Server > HyperV

HyperV Configuration and Health

Top HyperV Guests By Virtual Processor Run Time Pct

Top HyperV Guests by Large Page Size Usage

Top HyperV Guests by Remote Physical Page Usage

Top HyperV Root Partitions By Virtual Processor Run Time Pct

Top HyperV Root Partitions by Large Page Size Usage

Top HyperV Servers By Logical Processor Run Time Pct

Top HyperV Servers by Disk Activity

Top HyperV Servers by Disk Latency

Top HyperV Servers by Large Page Size Usage

Top HyperV Servers by Memory Remaining for Guests

Top HyperV Servers by Remote Physical Page Usage

Configuration

AccelOps needs WMI credentials to get the HyperV performance metrics. Configure this following the guidelines described in Microsoft Windows Server Configuration.

Settings for Access Credentials

Configure WMI on AccelOps

 

VMware ESX Configuration

What is Discovered and Monitored

Configuration

Settings for Access Credentials

What is Discovered and Monitored
Protocol Information discovered Metrics collected Used for
VMWare

SDK

ESX Server and the Guest hosts running on that server. ESX host clusters. Hardware (CPU, Memory, Disk, network Interface) for all guests, OS vendor and version for all guests. Virtual switch for connecting guest hosts to network interfaces. Both ESX level and guest host level performance metrics. Guest host level metrics include CPU/memory/disk utilization, CPU Run/Ready/Limited percent, memory swap in/out rate, free memory state, disk read/write rate/latency, network interface utilization, errors, bytes in/out.

ESX level metrics include physical CPU utilization, ESX kernel disk read/writre latency  etc

Performance

Monitoring

VMWare

SDK

  ESX logs include scenarios like ESX level login sucess/failure, configuration change, Guest host movement, account creation and modification Availability,

Change and

Security

Monitoring

Configuration

AccelOps discovers and monitors VMware ESX servers and guests over the the VMware SDK. Make sure that VMware Tools is installed on all the guests in your ESX deployment, and AccelOps will be able to obtain their IP addresses.

Settings for Access Credentials

Configuring VPN Gateways

AccelOps supports these VPN gateways for discovery and monitoring.

Cisco VPN 3000 Gateway Configuration

Juniper Networks SSL VPN Gateway Configuration

Microsoft PPTP VPN Gateway Configuration PulseSecure Configuration

Cisco VPN 3000 Gateway Configuration

What is Discovered and Monitored

Event Types

Rules

Reports

Configuration

SNMP

Syslog

Sample Parsed Cisco VPN 3000 Syslog Messages  Settings for Access Credentials

What is Discovered and Monitored
Protocol Information Discovered Metrics Collected Used For
 SNMP      
 Syslog      

Event Types

In CMDB > Event Types, search for “cisco_vpn” in the Name and Device Type column to see the event types associated with this device.

Rules

There are no predefined rules for this device.

Reports

There are no predefined reports for this device.

Configuration

SNMP

  1. Log in to your device with administrative credentials.
  2. Go to Configuration > System > Management Protocols > SNMP Communities.
  3. Click Add.
  4. For Community String, enter public.

Syslog

  1. Go to Configuration > System > Events > Syslog Servers.
  2. Click Add.
  3. Enter the IP address of your AccelOps virtual appliance for Syslog Server.
  4. Add a syslog server with AccelOps IP address

Sample Parsed Cisco VPN 3000 Syslog Messages

Settings for Access Credentials

 

This entry was posted in Administration Guides, FortiSIEM on by .

About Mike

Michael Pruett, CISSP has a wide range of cyber-security and network engineering expertise. The plethora of vendors that resell hardware but have zero engineering knowledge resulting in the wrong hardware or configuration being deployed is a major pet peeve of Michael's. This site was started in an effort to spread information while providing the option of quality consulting services at a much lower price than Fortinet Professional Services. Owns PacketLlama.Com (Fortinet Hardware Sales) and Office Of The CISO, LLC (Cybersecurity consulting firm).

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.