Skip to main content

Arcsight Logger 5.3 CentOS 5.9 Virtualisation

Get the VirtualBox CentOS 5 as a 7z file from:

http://virtualboxes.org/images/centos/
  • Uncompress and save the Centos64.vbox and Centos64.vdi files.
  • Open the Oracle VM VirtualBox manager and select the vbox file to install
  • Make > 20GB disc or there will not be room for logger.
  • Login as root/reverse
Install Gnome Desktop as follows and start:
  • yum groupinstall "X Window System" "GNOME Desktop Environment" 
  • login root/reverse and startx
Check version of CentOS and other prelim:
  • cat /etc/redhat-release #CentOS release 5.9 (Final)
  • uname -a # somewhere x86_64 
  • create user logger
  • open port 443
  • check logger bin file execute box and double click.
  • run in terminal
If not enough space to install logger:
  • C:\Program Files\Oracle\VirtualBox\VBoxManage.exe modifyhd "D:\virtual machines\Centos\centos64.vdi" --resize 20000
  • shutdown centos VM
  • attach gparted-live-0.16.2-1b-i486.iso to CD drive
  • resize sda up to increased size 
  • start Centos VM and find free PE (Physical Extents) #lvm lvgdisplay
Free PE / Size 369 / 11.53 GB
  • Find the current LE (Logical Extents) with #lvm lvdisplay /dev/mapper/VolGroup00-LogVol00
Current LE 220
  • lvm lvresize -l 589 /dev/mapper/VolGroup00-LogVol00
  • resize2fs  /dev/mapper/VolGroup00-LogVol00
  • df -h # To check Centos file system has new allocated space.
Complete install of Arcsight Logger. Log into HTTPS server admin/password

Comments

SecurityBlogger said…
Hi Geoff,
Thanks for the post. Is it possible for you to share a pre-configured VM with arcsight loaded in it. It saves lot of time & effort for many people. Pls suggest.

Thanks.

Popular posts from this blog

FT 817 Power Amplifier

This very simple 2 Fet power amplifier easily achieves 250W output with an FT817 5W drive. The key design details as follows: 3:1 broadband input transformer matches the 5.5 ohm gate load resistor (4 x 22 ohms in parallel) to the 50 ohms required by the FT817 . The 4:1 output broadband transformer presents 3 ohms (16:1 impedance ratio) to the balanced HEXFET pair each mounted on a 3mm copper heat spreader which is insulated from the 2 1w/degC heatsinks. These are blown cool by a fan underneath. The power supply required is 28v at 30 amps. The amp is around 50% efficient with a standing 750mAmp temperature compensated bias. An IC 703, with 10watts output will drive the output to around 400 watts. The output filter shown is a 5 pole topband filter with T130-2 torroids and 400v silver mica caps. Peak output voltage on 160 metres with 5 watts drive is 160v or 320v p-p in 50 ohms equating to 250watts. This is slightly higher than the reading on the 3kw MFJ power meter. The inline F...

Splunk Cheat Sheet (Linux)

1. set root's password:  sudo su passwd root Enter new UNIX password: < new_root_password > Retype new UNIX password: < new_root_password > passwd: password updated successfully # su - 2. Remove any existing Splunk directories & create user etc: # rm -rf /opt/splunkforwarder # userdel -r splunk # this will remove as above if user splunk's home directory # groupadd siem # useradd -g siem -s /bin/bash -d /home/siem -m siem # vi ~/.profile # chage -I -1 -m -0 -M -99999 -E -1 siem If above fails because of multiple passwd fails: # pam_tally --reset check with #chage -l siem # uname -a # check OS version # dpkg -i splunk-4.3.1...........intel.deb # chown -R siem:siem /opt/splunk # su - siem : $SPLUNK_HOME/bin/splunk start --accept-license : $SPLUNK_HOME/bin/splunk edit user admin -password newpassword -role admin -auth admin:changeme 3. vi ~/.profile (as follows) (OR .bash_profile) # ~/.profile: executed by the command interpreter for log...