Atlassian uses cookies to improve your browsing experience, perform analytics and research, and conduct advertising. Accept all cookies to indicate that you agree to our use of cookies on your device. Atlassian cookies and tracking notice, (opens new window)
Armor can ingest logs from most sources. The logs are stored and can be correlated and analyzed against threat intelligence feeds from Armor and other third parties. Armor provides advanced log search and data visualization capabilities through the Armor Management Portal. The benefits of Armor's log and data management add-on include:
Enhanced security posture through the analysis and correlation of log information with other Armor telemetry sources.
Greater context to aid in more effective detection, alerting and response.
Ability to meet compliance mandates through the storing of log data for up to 13 months.
ARMOR AGENT FOR SERVERS can be configured to collect logs from the following sources:
Apache Server
Microsoft IIS
NGINX
Armor Anywhere
MSSQL
Sysmon
Armor Agent - Collecting Linux and Windows Standard Logs
Use the following commands to manage the Logging service - Filebeat and Winlogbeat (for Windows only).
The following arguments are possible parameters for the Logging CLI feature. This allows customers to manage filebeat modules on Virtual Machines.
COMMAND
ARGUMENTS
RESULT
COMMAND
ARGUMENTS
RESULT
iis-enable
apache-enable
nginx-enable
Enables filebeat IIS/apache/nginx. When run, module yml file will change from disabled state to enable state.
iis-disable
apache- disable
nginx- disable
Disables Filebeat IIS/apache/nginx. When run the module yml file will change from enable state to disable mode.
iis-add-access-paths
apache-add-access-paths
nginx-add-access-paths
path1, path2, path3
Includes the argument paths in module yml file under the 'access_paths' section.
iis-remove-access-paths
apache-remove-access-paths
nginx-remove-access-paths
path1, path2, path3
Removes the argument paths in module yml file under the 'access_paths' section.
iis-add-error-paths
apache-add-error-paths
nginx-add-error-paths
path1, path2, path3
Includes the argument paths in module yml file under the 'error_paths' section.
iis-remove-error-paths
apache-remove-error-paths
nginx-remove-error-paths
path1, path2, path3
Removes the argument paths in module yml file under the 'error_paths' section. Removes the argument paths in module yml file under the 'error_paths' section.
iis-sync-config
apache-sync-config
nginx-sync-config
The command sync the module yml file on vm with latest changes which are required.
iis-describe-config
apache-describe-config
nginx-describe-config
The command displays current access & error paths which are configured in module yml file.
Users can add as many paths in a single command as needed by must be comma-separated.