Distributed Logpoint

The Distributed Logpoint setup connects multiple Logpoint machines to segregate search and indexing. You can collect, index, and store logs in multiple Logpoint machines and search through them from a single main Logpoint, the Search Head. You can also monitor, configure, and analyze the logs on the connected devices.

The following scenario demonstrates workflow in the distributed setup using two Logpoint machines, LP1 and LP2.

In LP1, you can add LP2 as a distributed Logpoint if you have the permission to access the logs on LP2. The users in LP1 can then search and create dashboards, alerts, and reports using the logs from the repos in either machine. In this case, users in LP2 cannot view the logs in LP1 unless LP1 is also added as a distributed Logpoint of LP2.

You can switch between multiple Logpoint machines using the DLP Selector in the top-right corner of the title bar.

_images/LP_Config_DLP_Selector.png

Distributed Logpoint Selector

The DLP Selector is only visible in any of the page from Settings.

_images/LP4.png

Four DLPs with a single search head

The figure shows a distributed setup with four Logpoint machines. Here, LP2, LP3, and LP4 are added as Distributed Logpoint for LP1. the logs from LP2, LP3, and LP4 are then accessible at LP1. You can configure two or more Logpoint machines as Distributed Logpoint of each other. The logs are then accessible both ways.

Note

The names of each Logpoint must be unique in a distributed setup. You can rename a Logpoint. To learn how, go to System Settings >> General.

DLP Accessibility

Use the main Logpoint machine to access and administer the following within a distributed Logpoint:

  1. Permission Groups

  2. Normalization Policies & Normalization Packages

  3. Routing Policies

  4. Log Collection Policies

  5. Parsers

  6. Distributed Collector and Distributed Logpoint

  7. Devices and Device Groups

  8. Label Packages

  9. Search Templates

  10. Macros

  11. System Monitor

  12. System Settings

  13. Logpoint License, Open Door, Integrations

  14. View Search Views and Packages

  15. View Alert Rules

  16. View Lists and Tables

  17. View and create Dashboards

  18. View and create users and user groups

  19. View and update data privacy settings

  20. Export data through Logpoint Sync

  21. UEBA


Helpful?

We are glad this guide helped.


Please don't include any personal information in your comment

Contact Support