- CheckMates
- :
- Products
- :
- CloudMates Products
- :
- Cloud Network Security
- :
- Discussion
- :
- Cloudguard Azure Smartevents
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Cloudguard Azure Smartevents
We have a VMSS cluster deployed in Azure with SMS, now we are looking to deploy a seperate Smartevents server in Azure.
What would be the best way to implement the Smartevent solution in Azure and integrate it into the current CME/SMS configuration? Is there a Azure template available and some documentation?
- Labels:
-
Azure
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There isn't a template for management configuration, generally speaking.
You would spin up a new management instance with just SmartEvent installed.
Or, you can also add SmartEvent to your existing management VM, though you might want to spin up a larger instance if you go that route.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There isn't a template for management configuration, generally speaking.
You would spin up a new management instance with just SmartEvent installed.
Or, you can also add SmartEvent to your existing management VM, though you might want to spin up a larger instance if you go that route.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
we decided to enable smartevent on the SMS, so we can simply enable the blade Smartevent server on the SMS in Azure?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Assuming you have a license for it, yes.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@dehaasm as @PhoneBoy mentioned there is no specific template for an Azure SmartEvent server. I would definitely recommend spinning up a separate SmartEvent server using premium SSD for the IOPS.
In Azure you can select the Check Point Security Management template then chose to configure manually. (See screenshot below) At this point you would follow the traditional setup instructions with the first time wizard (FTW).
It's worth noting that MDS has an installation type that is specific to the log server setup. (mds-logserver)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Bryan,
Thanks for sharing your knowledge. At the moment we have management server+smartevents license on single SMS IP, would it be possible to transfer the Smartevent license/component to the dedicated smartevents server with the new IP address?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@dehaasm that is a good question. I would double check with your account team to make sure you are licensed to run a dedicated SmartEvent server. I believe you need to have a dedicated SmartEvent server license to split it out.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Bryan,
We want to install Smartevent server on the same SMS what would you recommend for the system requriements, we currently have 4 CPU / 16GB mem and the there are about 150 log events per second.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That is the configuration I use for my lab installation of SMS+SmartEvent, which I consider a bare minimum installation.
It should suffice as a starting point, but doesn't give you a ton of headroom.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
should we go for 8CPU with 32GB RAM doubling it?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If it were me, I would.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@dehaasm 8 vCPU / 32GB RAM is a great starting point to run the correlation unit.
High Level Overview of Event Identification (checkpoint.com)