SMB protocol is one of the source addition options of the Logsign Unified SecOps Platform. If your product, device, or software you are using logs on the file, Logsign Unified SecOps Platform will read that file and provide you with relevant results.
Note: this guide's worked example uses Exchange Server 2010, which reached end of support in October 2020. The parsing logic and general steps below still apply to later Exchange Server versions (2013/2016/2019) that support Message Tracking logs; just select the matching Version in step 5 and confirm the correct log path for your version and server role in step 4.
- Go to "Settings" → "Data Collection" then click on "+ Device" :
2. Select "SMB" :
- You can enter Administrator credentials, or the second way is creating a local user. You can go to the MessageTracking file path and share it with the local user that you created. Also, you should add this user under the security tab on the same screen.
The remote host includes the following information:
- Host: IP address of the remote Exchange Server.
- Username: "Administrator"
- Password: The password for the Administrator account.
- Workgroup: The Network Workgroup.
- Under the "Directory Tree" make sure to select the actual Message Tracking log folder, not just a bare "/MessageTracking" name. On Exchange 2010/2013, this is nested under the Transport role's log directory, typically:
C:\Program Files\Microsoft\Exchange Server\V14\TransportRoles\Logs\MessageTracking\(Exchange 2010, Hub Transport role) orC:\Program Files\Microsoft\Exchange Server\V15\TransportRoles\Logs\MessageTracking\(Exchange 2013+). The exact path depends on your install location and server role; confirm it in the Exchange Management Shell withGet-TransportService | fl MessageTrackingLogPath(2013+) or the equivalent 2010 cmdlet, rather than assuming the default.
- Enter the filenames pattern to be followed by the logsign system :
- Pattern Name: "Exchange"
- Include Pattern "*LOG"
- Vendor: "Microsoft"
- Product: "Exchange Server"
- Version : "2010" (or your actual version)
- Format: "Comma"
Vendor: Specify the brand information of the system you have used in this section. Choose Microsoft because you are configuring on Windows operating system.
Product: Specify product information in this section. Exchange Server option is selected because you are setting Exchange Server on Windows.
Then click the Save Pattern button to save the settings.
Please note that: You can add multiple pattern information.
Read Static Files: All files in the shared folder will be read when you tick the box.
Period: Determine how long the logs will be taken from the source. You need to specify in minutes, and the default value is thirty (30) minutes.
EPS: The expansion of the EPS variant used in the shared network world is known as Event Per Second. You can refer to the amount of data on your network that comes from the products such as Intrusion Detection System, Hardware or Software Firewall, Server, Switch and Router to the Logsign Unified SecOps Platform. In the Logsign Unified SecOps Platform product, the EPS value is set to default one thousand "1000" in the specified configurations, which is normal.
Please note that: If you think that the EPS value on your system is high, please contact the Logsign Customer Support Unit.
Data Policy: You can filter in or out of incoming data. In the Data Policy section, you can specify the kind of logs (word, event movement type, etc.) that you want to receive or not from the source. The default setting here is the Default Policy, which has the default rule is "collect all logs."
Offset: To explain it in terms of definition, let's say “time difference.” If the "system" time you want to log in is forward or backward from the real-time difference, you can edit it accordingly. The symbol "+" moves forward, and "-" moves backward. Time information is specified in minutes.
Check Health: Check this box to be informed about the service and operability of the Logsign Unified SecOps Platform product. The Health Check Period tab will come up when you tick the box. This part is the time interval information to be checked.
Description: You must enter a descriptive name according to the configuration that you made (For ex. Exchange1). It can provide convenience for people who analyze logs. Think of the Description field as a resource-specific area.
Tag: Slightly different from the Description section, it can be used for a broader purpose. For example, you can query by tag, and make tag-based definitions while creating a report if you use multiple Exchange and define each tag as exc1 or exc2. If you want to query about an event, you will get a shorter result when you search according to exc1 name.