{"id":20,"date":"2015-04-09T01:30:10","date_gmt":"2015-04-09T01:30:10","guid":{"rendered":"http:\/\/www.blakecorbitt.com\/blog\/?p=20"},"modified":"2015-04-24T03:07:24","modified_gmt":"2015-04-24T03:07:24","slug":"how-to-properly-add-a-sensor-to-alienvaultossim","status":"publish","type":"post","link":"https:\/\/www.blakecorbitt.com\/blog\/?p=20","title":{"rendered":"How to properly add a sensor to AlienVault\/OSSIM"},"content":{"rendered":"<p>I recently re-deployed our\u00a0SIEM environment since it&#8217;s initial incarnation was never meant to be &#8220;production&#8221;. One of the issues I had immediately is that after adding the sensor machines, they didn&#8217;t show up under the &#8220;Alienvault Center&#8221; \u00a0section of the Components page. \u00a0They did show up under &#8220;Sensors&#8221; and were basically functioning normally as they were sending data and I was able to run discovery and vulnerability scans with them. However, not having them under the AV Center section prevented me from viewing and editing much of the sensor configuration (including applying updates) from the web interface.<\/p>\n<p>It seems there is a specific way sensors need to be added. I had manually added the sensor in the web interface, which I guess is &#8220;wrong&#8221;. \u00a0Here&#8217;s how I fixed it:<\/p>\n<p>1) SSHed to the sensor and changed the framework IP to 127.0.0.1 and the AV Server IP to an unused\u00a0IP.<\/p>\n<p>2) \u00a0&#8220;disassociate&#8221; any Groups, Networks and Assets from the sensor. In my case, I kept the networks and just associated them with the &#8220;master&#8221;, but ended up just deleting the 100+ assets, since I\u00a0<em>really\u00a0<\/em>didn&#8217;t want to manually edit all of those and haven&#8217;t found a way to bulk-edit assets. Please let me know in the comments if you do!<\/p>\n<p>3) Delete the sensor from the Deployment-&gt;Components-&gt;Sensors list.<\/p>\n<p>4) SSHed to the sensor again and changed both the Framework IP and the AV Server IP back to the IP of the Master.<\/p>\n<p>5) Log into the web interface and go back to Deployment-&gt;Components-&gt;Sensors<\/p>\n<p>Here you should now be notified that a sensor is &#8220;reported as enabled but hasn&#8217;t been configured.&#8221;\u00a0 Clicking &#8220;Insert&#8221; on this message\u00a0\u00a0appears to be the correct way to add a sensor.<\/p>\n<p><a href=\"http:\/\/www.blakecorbitt.com\/blog\/wp-content\/uploads\/2015\/04\/New-Sensor-Msg.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-21\" src=\"http:\/\/www.blakecorbitt.com\/blog\/wp-content\/uploads\/2015\/04\/New-Sensor-Msg-300x26.png\" alt=\"New-Sensor-Msg\" width=\"300\" height=\"26\" srcset=\"https:\/\/www.blakecorbitt.com\/blog\/wp-content\/uploads\/2015\/04\/New-Sensor-Msg-300x26.png 300w, https:\/\/www.blakecorbitt.com\/blog\/wp-content\/uploads\/2015\/04\/New-Sensor-Msg-1024x89.png 1024w, https:\/\/www.blakecorbitt.com\/blog\/wp-content\/uploads\/2015\/04\/New-Sensor-Msg-1038x92.png 1038w, https:\/\/www.blakecorbitt.com\/blog\/wp-content\/uploads\/2015\/04\/New-Sensor-Msg.png 1063w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Once I had &#8220;Inserted&#8221; the sensor, it showed up properly under both the &#8220;Alienvault Center&#8221; view as well as under &#8220;Sensors&#8221;.<\/p>\n<p>I didn&#8217;t find this exact issue in any of the forums (but did find a hint here: https:\/\/www.alienvault.com\/forums\/discussion\/1322\/adding-sensors-to-the-alienvault-centre-display), so thought I&#8217;d post it here. Hope it helps someone.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I recently re-deployed our\u00a0SIEM environment since it&#8217;s initial incarnation was never meant to be &#8220;production&#8221;. One of the issues I had immediately is that after adding the sensor machines, they didn&#8217;t show up under the &#8220;Alienvault Center&#8221; \u00a0section of the Components page. \u00a0They did show up under &#8220;Sensors&#8221; and were basically functioning normally as they &hellip; <a href=\"https:\/\/www.blakecorbitt.com\/blog\/?p=20\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">How to properly add a sensor to AlienVault\/OSSIM<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_exactmetrics_skip_tracking":false,"footnotes":""},"categories":[7],"tags":[8,9,10],"class_list":["post-20","post","type-post","status-publish","format-standard","hentry","category-ossim","tag-alienvault","tag-ossim","tag-siem"],"_links":{"self":[{"href":"https:\/\/www.blakecorbitt.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/20","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.blakecorbitt.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.blakecorbitt.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.blakecorbitt.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.blakecorbitt.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=20"}],"version-history":[{"count":2,"href":"https:\/\/www.blakecorbitt.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/20\/revisions"}],"predecessor-version":[{"id":23,"href":"https:\/\/www.blakecorbitt.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/20\/revisions\/23"}],"wp:attachment":[{"href":"https:\/\/www.blakecorbitt.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=20"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.blakecorbitt.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=20"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.blakecorbitt.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=20"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}