Help Center/ SecMaster/ Best Practices/ Log Access and Transfer Operation Guide/ Procedure/ Step 11: Configure a Log Collection Channel
Updated on 2024-11-18 GMT+08:00

Step 11: Configure a Log Collection Channel

This topic describes how to configure a log collection channel and connect functional components to let SecMaster and the log collector work properly.

Procedure

  1. Log in to the management console.
  2. Click in the upper left corner of the page and choose Security & Compliance > SecMaster.
  3. In the navigation pane on the left, choose Workspaces > Management. In the workspace list, click the name of the target workspace.

    Figure 1 Workspace management page

  4. In the navigation pane on the left, choose Settings > Collections. Then, select the Collection Channels tab.

    Figure 2 Collection channel management tab page

  5. Add a log collection channel group.

    1. On the Collection Channels tab, click on the right of Groups.
    2. Enter a group name and click .

  6. Create a log collection channel.

    1. On the right of the group list, click Add.
    2. In the Configure Basic Configuration step, configure basic information.
      Table 1 Basic configuration parameters

      Parameter

      Description

      Basic Information

      Title

      The collection channel name you customize.

      Channel grouping

      Select the group created in 5.

      (Optional) Description

      Enter the description of the collection channel.

      Configure Source

      Source Name

      Select the name of the log source added in Step 9: Configure a Connector.

      After you select a source, the system automatically generates the information about the selected source.

      Destination Configuration

      Destination Name

      Select the name of the log destination added in Step 9: Configure a Connector.

      After you select a destination, the system automatically generates the information about the selected destination.

    3. Click Next in the lower right corner of the page.
    4. On the displayed Configure Parser page, select the parser configured in (Optional) Step 10: Configure a Log Parser and click Next in the lower right corner of the page.

      If no parsers are configured, you can select Quick access Parser to add raw logs to the collection channel list.

    5. On the Select Node page, click Create. In the Add Node dialog box displayed, select the ECS node created in (Optional) Step 1: Buy an ECS and click OK.
      Figure 3 Selecting a node

  7. Click Next in the lower right corner of the page.
  8. On the Preview Channel Details page, confirm the configuration and click Save and Execute.

    On the Collection Channels tab, if the health status of a collection channel is Normal, the collection channel is successfully delivered.

    Figure 4 Collection channels configured