Esta página ainda não está disponível no idioma selecionado. Estamos trabalhando para adicionar mais opções de idiomas. Agradecemos sua compreensão.
- What's New
- Function Overview
- Service Overview
-
Billing
- Billing Overview
- Billing Modes
- Billing Items
- Billing Examples
- Changing the Billing Mode
- Renewing Your Subscription
- Bills
- About Arrears
- Billing Termination
- Cost Management
-
Billing FAQs
- How Is SecMaster Billed?
- Can I Use SecMaster for Free?
- How Do I Change or Disable Auto Renewal for SecMaster?
- Will SecMaster Be Billed After It Expires?
- How Do I Renew SecMaster?
- Where Can I Unsubscribe from SecMaster?
- Where Can I View the Remaining Quotas of Security Data Collection and Security Data Packages?
- Can I Change the Billing Mode for SecMaster?
- Getting Started
-
User Guide
- Buying SecMaster
- Authorizing SecMaster
- Checking Security Overview
- Workspaces
- Viewing Purchased Resources
-
Security Governance
- Security Governance Overview
- Security Compliance Pack Description
- Authorizing SecMaster to Access Cloud Service Resources
- Subscribing to or Unsubscribing from a Compliance Pack
- Starting a Self-Assessment
- Viewing Security Compliance Overview
- Viewing Evaluation Results
- Viewing Policy Scanning Results
- Downloading a Compliance Report
- Security Situation
- Resource Manager
- Risk Prevention
- Threats
- Security Orchestration
-
Playbook Overview
- Ransomware Incident Response Solution
- Attack Link Analysis Alert Notification
- HSS Isolation and Killing of Malware
- Automatic Renaming of Alert Names
- Auto High-Risk Vulnerability Notification
- Automatic Notification of High-Risk Alerts
- Auto Blocking for High-risk Alerts
- Real-time Notification of Critical Organization and Management Operations
-
Settings
- Data Integration
-
Log Data Collection
- Data Collection Overview
- Data Collection Process
- Adding a Node
- Configuring a Component
- Adding a Connection
- Creating and Editing a Parser
- Adding and Editing a Collection Channel
- Verifying Log Collection
- Managing Connections
- Managing Parsers
- Managing Collection Channels
- Viewing Collection Nodes
- Managing Nodes and Components
- Partitioning a Disk
- Logstash Configuration Description
- Connector Rules
- Parser Rules
- Upgrading the Component Controller
- Customizing Directories
- Permissions Management
- Key Operations Recorded by CTS
-
Best Practices
-
Log Access and Transfer Operation Guide
- Solution Overview
- Resource Planning
- Process Flow
-
Procedure
- (Optional) Step 1: Buy an ECS
- (Optional) Step 2: Buy a Data Disk
- (Optional) Step 3: Attach a Data Disk
- Step 4: Create a Non-administrator IAM User
- Step 5: Configure Network Connection
- Step 6: Install the Component Controller (isap-agent)
- Step 7: Install the Log Collection Component (Logstash)
- (Optional) Step 8: Creating a Log Storage Pipeline
- Step 9: Configure a Connector
- (Optional) Step 10: Configure a Log Parser
- Step 11: Configure a Log Collection Channel
- Step 12: Verify Log Access and Transfer
- Credential Leakage Response Solution
-
Log Access and Transfer Operation Guide
-
API Reference
- Before You Start
- API Overview
- Calling APIs
-
API
- Alert Management
- Incident Management
- Indicator Management
- Playbook Management
- Alert Rule Management
- Playbook Version Management
- Playbook Rule Management
- Playbook Instance Management
- Playbook Approval Management
- Playbook Action Management
- Incident Relationship Management
- Data Class Management
- Workflow Management
- Data Space Management
- Pipelines
- Workspace Management
- Metering and Billing
- Metric Query
- Baseline Inspection
- Appendix
- FAQs
-
More Documents
-
User Guide (ME-Abu Dhabi Region)
- Service Overview
- Buying SecMaster
- Authorizing SecMaster
- Viewing Security Overview
- Workspaces
- Viewing Purchased Resources
-
Security Governance
- Security Governance Overview
- Security Compliance Pack Description
- Authorizing SecMaster to Access Cloud Service Resources
- Subscribing to or Unsubscribing from a Compliance Pack
- Starting a Self-Assessment
- Viewing Security Compliance Overview
- Viewing Evaluation Results
- Viewing Policy Scanning Results
- Downloading a Compliance Report
- Security Situation
- Resource Manager
- Risk Prevention
- Threat Operations
- Security Orchestration
-
Settings
- Data Integration
-
Log Data Collection
- Data Collection Overview
- Adding a Node
- Configuring a Component
- Adding a Connection
- Creating and Editing a Parser
- Adding and Editing a Collection Channel
- Managing Connections
- Managing Parsers
- Managing Collection Channels
- Viewing Collection Nodes
- Managing Nodes and Components
- Partitioning a Disk
- Logstash Configuration Description
- Connector Rules
- Parser Rules
- Upgrading the Component Controller
- Customizing Directories
- Permissions Management
- FAQs
- Change History
-
User Guide (Kuala Lumpur Region)
- Service Overview
- Authorizing SecMaster
- Security Overview
- Workspaces
- Viewing Purchased Resources
- Security Situation
- Resource Manager
-
Risk Prevention
-
Baseline Inspection
- Baseline Inspection Overview
- Creating a Custom Check Plan
- Starting an Immediate Baseline Check
- Viewing Check Results
- Handling Check Results
- Viewing Compliance Packs
- Creating a Custom Compliance Pack
- Importing and Exporting a Compliance Pack
- Viewing Check Items
- Creating a Custom Check Item
- Importing and Exporting Check Items
- Vulnerability Management
- Policy Management
-
Baseline Inspection
-
Threat Operations
- Incident Management
- Alert Management
- Indicator Management
- Intelligent Modeling
- Security Analysis
- Data Delivery
-
Security Orchestration
- Security Orchestration Overview
- Built-in Playbooks
- Security Orchestration Process
- (Optional) Configuring and Enabling a Workflow
- Configuring and Enabling a Playbook
- Operation Object Management
- Playbook Orchestration Management
- Layout Management
- Plug-in Management
- Settings
-
FAQs
-
Product Consulting
- Why Is There No Attack Data or Only A Small Amount of Attack Data?
- Where Does SecMaster Obtain Its Data From?
- What Are the Dependencies and Differences Between SecMaster and Other Security Services?
- What Are the Differences Between SecMaster and HSS?
- How Do I Update My Security Score?
- How Do I Handle a Brute-force Attack?
- Issues About Data Synchronization and Data Consistency
- About Data Collection Faults
-
Product Consulting
- Change History
-
User Guide (ME-Abu Dhabi Region)
- General Reference
Copied.
Adding and Editing a Collection Channel
Scenario
This topic describes how to add and edit a log collection channel to connect functional components and let SecMaster and the log collector work properly.
Adding a Channel Group
Before adding a collection channel, you need to add a connection group.
- Log in to the management console.
- Click
in the upper part of the page and choose Security > SecMaster.
- In the navigation pane on the left, choose Workspaces > Management. In the workspace list, click the name of the target workspace.
Figure 1 Workspace management page
- In the navigation pane on the left, choose Settings > Collections. Then, select the Collection Channels tab.
Figure 2 Collection channel management tab page
- Add a channel group.
- On the Collection Channels tab, click
on the right of Groups.
- Enter a group name and click
.
To edit or delete a group, hover the cursor over the group name and click the edit or deletion icon.
- On the Collection Channels tab, click
Adding a Collection Channel
- Log in to the management console.
- Click
in the upper part of the page and choose Security > SecMaster.
- In the navigation pane on the left, choose Workspaces > Management. In the workspace list, click the name of the target workspace.
Figure 3 Workspace management page
- In the navigation pane on the left, choose Settings > Collections. Then, select the Collection Channels tab.
Figure 4 Collection channel management tab page
- On the right of the group list, click Add.
- On the displayed page, in the Basic Configuration phase, configure basic information.
Table 1 Basic configuration parameters Parameter
Description
Basic Information
Title
User-defined collection channel name.
Channel grouping
Select the group to which the collection channel belongs.
(Optional) Description
(Optional) Enter the description of the collection channel.
Configure Source
Source Name
Select the source name of the collection channel.
After you select a source, the system automatically generates the information about the selected source.
Destination
Destination Name
Select the destination name of the collection channel.
After you select a destination, the system automatically generates the information about the selected destination.
- After the basic configuration is complete, click Next in the lower right corner of the page.
- On the Configure Parser page, select a parser. You can check its details.
If no parser is available or you want to create a parser, click Create and create one. For details, see Creating and Editing a Parser.
- After the parser is configured, click Next in the lower right corner of the page.
- On the Select Node page, click Create. In the Add Node dialog box displayed, select a node and click OK.
- Running parameters: You can configure running parameters for added nodes by taking the following steps:
- In the node list, locate the row that contains the target node, and click Running parameters in the Operation column.
- Click Add Configuration and select a key and value.
If you need to optimize the running parameters of a collection channel, SecMaster provides optimization parameters pipeline.batch.size, pipeline.workers, and pipeline.batch.delay for your choice. If no optimizations are required, delete related configurations.
Table 2 Parameter configuration description Parameter
Type
Description
pipeline.batch.size
int
This parameter specifies the number of events that can be collected by each worker thread each time. A larger value indicates a higher efficiency. However, the memory overhead also increases. You can increase the heap space in jvm.options.
pipeline.workers
int
This parameter specifies the number of worker threads in the pipeline. The default value is the number of CPU cores.
pipeline.batch.delay
int
This parameter specifies the delay to submit the current pipeline. You can use this parameter to increase message submission times and system consumption efficiency.
- To remove an added node, locate the row that contains the target node, click Remove in the Operation column.
- Running parameters: You can configure running parameters for added nodes by taking the following steps:
- After the running node is selected, click Next in the lower right corner of the page.
- On the Preview Channel Details page, confirm the configuration and click Save and Execute.
If the collection channel healthy status is Normal, all collection channels are successfully delivered. The following table describes the statuses of collection channels.
Table 3 Health status of a collection channel Monitoring Status
Description
Healthy
The collection channel is successfully delivered.
Abnormal
Some collection channels are successfully delivered, and some are abnormal.
Faulty
The collection channel has not been delivered. This status changes according to the heartbeat status, and there is a delay. Generally, the monitoring status is reported every 30 seconds.
Editing a collection channel
- Log in to the management console.
- Click
in the upper part of the page and choose Security > SecMaster.
- In the navigation pane on the left, choose Workspaces > Management. In the workspace list, click the name of the target workspace.
Figure 5 Workspace management page
- In the navigation pane on the left, choose Settings > Collections. Then, select the Collection Channels tab.
Figure 6 Collection channel management tab page
- In the collection channel list, locate the row that contains the target channel, click More > Edit in the Operation column. The Edit Collection Channel page is displayed.
- On the displayed page, in the Basic Configuration phase, configure basic information.
Table 4 Basic configuration parameters Parameter
Description
Basic Information
Channel Name
User-defined collection channel name.
Channel grouping
Select the group to which the collection channel belongs.
(Optional) Description
(Optional) Enter the description of the collection channel.
Source Configuration
Source Name
Select the source name of the collection channel.
After you select a source, the system automatically generates the information about the selected source.
Destination Name
Select the destination name of the collection channel.
After you select a destination, the system automatically generates the information about the selected destination.
- After the basic configuration is complete, click Next in the lower right corner of the page.
- On the parser configuration page, select a parser to view its details.
If no parser is available or you want to create a parser, choose Create to create a parser. For details, see Creating and Editing a Parser.
- After the parser is configured, click Next in the lower right corner of the page.
- On the Select Node page, click Add. In the Add Node dialog box displayed, select a node and click OK.
- Running parameters: After a node is added, if you want to configure parameters for the added node, perform the following steps:
- In the node list, locate the row that contains the target node, and click Running parameters in the Operation column.
- Click Add Configuration and select a key and value.
- To remove an added node, locate the row that contains the target node, click Remove in the Operation column.
- Running parameters: After a node is added, if you want to configure parameters for the added node, perform the following steps:
- After the running node is selected, click Next in the lower right corner of the page.
- On the Preview Channel Details page, confirm the configuration and click Save and Execute.
Related Operations
For details about how to view, delete, enable, disable, and restart a collection channel, see Managing Collection Channels.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot