Distributed Logpoint

A Distributed Architecture distributes functionalities across multiple locations for scalability, fault tolerance, and high availability. You can implement this type of architecture in Logpoint to distribute log collection, normalization, and analytics functionalities across various Logpoints, Syslog Forwarders, and Logpoint Collectors to create a Distributed Logpoint.

A Standalone Logpoint has all the functionalities, including log collection, normalization, and analytics, in a single Logpoint instance.

_images/LP_Consolidated_Logpoint.png

Standalone Logpoint

As more devices are added to a network, more Events Per Second (EPS) produce a high volume of logs. As the logs grow, we can vertically scale by adding more processing power, memory, and storage to handle the increasing number of logs. However, there are limitations to vertical scaling. Additionally, it also creates a single point of failure. For that reason, a distributed architecture handles the high volumes of logs and increases fault tolerance.

Important

All Logpoints in a distributed architecture must have the same version of Logpoint installed.

Distributed Syslog Forwarder

A Distributed Syslog Forwarder distributes the functionality of Logpoint between a Syslog Forwarder and Logpoints. Devices in your network send logs to a Syslog Forwarder. The Syslog Forwarder collects and normalizes the logs and forwards them to a Logpoint via a TCP connection on port 514.

_images/LP_Distributed_Syslog_Forwarder.png

Distributed Syslog Forwarder Logpoint

To learn how to add a Syslog Forwarder to a Logpoint, go to Adding a Syslog Forwarder.

Distributed Logpoint Collector

Distributed Logpoint Collector distributes the functionality of a Logpoint between a Logpoint Collector and Logpoints. Devices in your network are connected to a Logpoint Collector, which then forwards logs to Logpoint via a VPN-connected network.

_images/LP_Distributed_Logpoint_Collector.png

Distributed Logpoint Collector

To learn how to add a Logpoint Collector to a Logpoint, go to Configuring Distributed Collectors.

Distributed Logpoint

Distributed Logpoint or DLP distributes the functionality of a Standalone Logpoint into various Logpoints, Logpoint Collectors, and Syslog Forwarders. The key defining component of a Distributed Logpoint is the presence of a High Availability Logpoint. A High Availability Logpoint has all the configuration and logs duplicated to create a failsafe in case of failure.

_images/LP_Distributed_Logpoint.png

Distributed Logpoint

You can collect, index, and store logs in multiple Logpoints and search through them from a single main Logpoint, the Search Head. Search Head performs analytics functionality rather than log normalization or storage. This Logpoint is primarily used to create dashboards and monitor, configure, and analyze the logs on the connected Logpoints.

Distributed Logpoint Implementation

Distributed Logpoint, Distributed Syslog Forwarders, and Logpoint Collectors can be added or removed to implement the distribution of functionalities. The following diagram shows a full-fledged implementation with various components working together.

_images/LP_DLP_Full.png

Distributed Logpoint

Contact your regional sales representative or customer support for specific organizational implementations. They will give you options for the best implementation based on your network layout, devices, and availability requirements.

Distributed Logpoint Navigation

To navigate between multiple Logpoints, you can use the DLP Selector in the top-right corner of the title bar.

_images/LP_Config_DLP_Selector.png

Distributed Logpoint Selector

The DLP Selector is only visible on any page from Settings. The names of each Logpoint must be unique in a distributed setup. To rename a Logpoint, go to System Settings >> General.

Distributed Logpoint Accessibility

Using the Search Head, you can access and administer the following within a distributed Logpoint:

  1. Permission Groups

  2. Normalization Policies & Normalization Packages

  3. Routing Policies

  4. Log Collection Policies

  5. Parsers

  6. Distributed Collector and Distributed Logpoint

  7. Devices and Device Groups

  8. Label Packages

  9. Search Templates

  10. Macros

  11. System Monitor

  12. System Settings

  13. Logpoint License, Open Door, Integrations

  14. View Search Views and Packages

  15. View Alert Rules

  16. View Lists and Tables

  17. View and create Dashboards

  18. View and create users and user groups

  19. View and update data privacy settings

  20. Export data through Logpoint Sync

  21. UEBA


Helpful?

We are glad this guide helped.


Please don't include any personal information in your comment

Contact Support