Once the ELM management database has been migrated to the preferred location(see previous post), we can set up ELM storage volumes to meet with the compliance and long time retention requirements of the organization.
Storage volumes can be defined using the internal storage of the ELM the additional storage provided by a Direct Attach Storage device (DAS), as well as external Storage devices (like NFS resources or SAN).
The definition of which Storage volume to use is set up by Data Source, a good practice in a shared environment, is to have one storage volume by customer.
Once the storage volume is created and used, the management database of the ELM tracks all the information sent to this volume, this characteristic is specially interesting during the analysis phase as a new tab appear on the event details panel that link the parsed event with its raw information allowing forensic investigation.
This video shows the whole process of defining multiple storage volumes, how to link the volume with the data source and use some of the searching features provided by the ELM to look for specific information.
McAfee ESM provides an interactive dashboard that allows to look for information on the ELM, you can use Regular expressions or natural expressions for that.
One interesting feature related to the ELM, is that when a storage volume is created a virtual file system is created on the ELM accessible via an SFTP service on port 23, we can use the user NGCP and the password used for this user on the SIEM to connect to this service an extract the desired information.
Next video shows this feature.
Last thing to mention about the information stored on the ELM is that it is signed so the system can check if any manipulation has occurred against the information that affected the integrity of the data.
Next picture shows the integrity check feature.
Thanks for reading
Comments
Post a Comment