Está en la página 1de 4

orreLog

Security Correlation Server


Quick Installation Guide
Server System Installation Requirements
CorreLog Server is specifically designed for fast and easy installation. The
system does not scatter DLL or other files into system directories. All files reside
in the CorreLog root directory, by default the directory C:\CorreLog. Specific
system requirements of the CorreLog Framework system are described below.

Operating System. The system can be installed on Microsoft Windows


XP, Vista, Windows 7, Windows 8, as well as Windows NT 2003, 2008
and 2012 systems. CorreLog does not require Java, or .NET to be
installed on the platform.

Disk Space. The CorreLog Server software, by itself, has a small footprint
of less than 20 Mbytes, but the actual disk space may vary depending
upon the particular applications installed (or which might later be installed)
as part of the framework. A 500 GB high performance disk is typical for
most production systems.

CPU Requirements. CorreLog makes variable use of CPU. It can often


co-exist with other server components and applications. The CPU usage
of the CorreLog program may range from 20% to much higher, depending
on the message load. For high volume systems, a dual core CPU is
recommended. CorreLog is a 32-bit application, but can run on 64-bit
machines.

Memory Requirements. CorreLog can run in as little as 512 Kbytes of


memory, but 2 to 4 GB of main memory is recommended for a production
system, especially under high message loading.

TCP Connectivity. The system is a web server and web-based


application. It cannot be installed on a platform that does not have TCP
connectivity. For best results the host platform should have a permanent
IP address, and DNS services.

TCP Service Ports. The system requires control of a single TCP service
port, normally port 80, but possibly any other port selected by the user,
during the install process. The installer attempts to auto-detect a free
service port. Port blocking and virus protection programs (in particular
McAfee Virus Scan) may interfere with this.

UDP Service Ports. The system requires a single UDP service port: port
514 is used for listening for Syslog messages. Optionally, port 162 is used
for listening for SNMP Trap messages (if the SNMP Trap receiver adapter
is installed.) These two service ports should be free at the time of
installation, or the program will not operate properly.

In the absence of any other requirements, CorreLog recommends a Windows


2008 Server with 500 GB of disk space, 32-bit dual core CPU, 4 GB of main
memory, a high performance NIC. A static IP address for the CorreLog Server
platform is required for all production implementations.

Install Guide, Page - 2

Required And Optional Default Service Ports


The following table summarizes all the service ports that can be used by the
system. The administrator should verify that firewalls permit communication
between the agent and the manager. Note that not all the various port numbers
below are required (and depend upon specific options not used or installed at
your site.)
TCP

80

HTTP Server

Used at the CorreLog


Server to listen for
Web Browser
requests. (Required.)

TCP

443

Secure HTTP

Used at the CorreLog


Server to listen for
HTTPS requests.
(Optional.)

UDP

514

Syslog Receiver

Used at the CorreLog


Server to listen for
Syslog messages.
(Required.)

UDP

162

SNMP Trap Receiver

Used at the CorreLog


Server to listen to
SNMP traps.
(Optional.)

TCP

55514

Remote Agent Config

Used at the CorreLog


Windows Agent to
listen for remote
configuration requests.
(Optional but
recommended.)

TCP

51462

Tunnel Receiver

Used at the CorreLog


Server to listen for
tunneled messages
from agents.
(Optional.)

Install Guide, Page - 3

Software Installation Procedure


1. Obtain the signed CorreLog installation package, in self-extracting WinZip
format. This file will be named "co-n-n-n.exe". This package can be
downloaded from the web, or obtained from an installation CDROM.
2. Login to the target Windows platform with an "Administrator" type login.
3. Disable any firewall and virus scanning software during the installation.
The Syslog port number (UDP port 514) and the SNMP Trap port number
(UDP port 162) should be available for use.
4. Execute the self-extracting WinZip file, and extract files to the
target directory, by default the directory "C:\CorreLog".

Install Guide, Page - 4

También podría gustarte