Skip to content

Commit 0fe8a11

Browse files
authored
Knowledge content update and SFD readme update (#71)
* Update to Readme with latest knowledge content * Update SFD readme
1 parent 9616131 commit 0fe8a11

10 files changed

+40
-25
lines changed

README.md

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,12 @@ Logging Analytics knowledge content consists of one or more of the following:
1919
| :arrow_double_down: Oracle E-Business Suite | Packaged App | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: | :soon:
2020
| :arrow_double_down: Oracle Integration Cloud | OCI Cloud Service | :heavy_check_mark: | :gift: | :raising_hand: |:raising_hand:| :no_entry_sign:
2121
| :arrow_double_down: Security Fundamentals Dashboards | OCI Cloud Service | :heavy_check_mark: | :gift: | :raising_hand: |:raising_hand:| :no_entry_sign:
22-
| :arrow_double_down: APEX Monitoring | OCI Cloud Service | :heavy_check_mark: | :gift: | :raising_hand: |:raising_hand:| :no_entry_sign:
22+
| :arrow_double_down: APEX Monitoring | OCI Cloud Service | :heavy_check_mark: | :heavy_check_mark: | :raising_hand: |:raising_hand:| :no_entry_sign:
23+
| :arrow_double_down: GPU Cluster Monitoring | OCI Cloud Service | :heavy_check_mark: | :heavy_check_mark: | :heavy_check_mark: |:raising_hand:| :no_entry_sign:
24+
| :arrow_double_down: Oracle Enterprise Manager monitored by O&M Services | OCI Cloud Service or On-prem | :heavy_check_mark: | :heavy_check_mark: | :raising_hand: |:raising_hand:| :no_entry_sign:
25+
| :arrow_double_down: ZFS Storage Appliance Monitoring | OCI Cloud Service | :heavy_check_mark: | :heavy_check_mark: | :raising_hand: |:raising_hand:| :no_entry_sign:
26+
| :arrow_double_down: GenAI Solutions Monitoring using APM | OCI Cloud Service | :heavy_check_mark: | :raising_hand: | :raising_hand: |:raising_hand:| :no_entry_sign:
27+
2328

2429
Legend
2530

knowledge-content/MAP/security-fundamentals-dashboards/README.md

Lines changed: 34 additions & 24 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
# Security Fundamentals Dashboards for MAP
1+
# Security Fundamentals Dashboards
22

33
[![Deploy to Oracle Cloud](https://oci-resourcemanager-plugin.plugins.oci.oraclecloud.com/latest/deploy-to-oracle-cloud.svg)](https://cloud.oracle.com/resourcemanager/stacks/create?zipUrl=https://github.com/jujufugh/oci-o11y-solutions/releases/download/sfd-la-2.1/sfd-la-2.1.zip)
44

@@ -9,14 +9,15 @@
99
![Out-of-Box Dashboard for Identity Security](images/identity_security_dashboard_identity_domain2.png)
1010

1111
* Network Dashboard
12-
![Out-of-Box Dashboard for Network Security](images/network_analytics_dashboard_screenshot.png)
12+
![Out-of-Box Dashboard for Network Security](images/sfd-network-security-vcn.png)
13+
![Out-of-Box Dashboard for Network Security](images/sfd-network-security-vcn-changes.png)
14+
![Out-of-Box Dashboard for Network Security](images/sfd-network-security-lb.png)
15+
![Out-of-Box Dashboard for Network Security](images/sfd-network-security-waf.png)
16+
![Out-of-Box Dashboard for Network Security](images/sfd-network-security-nfw.png)
1317

1418
* Security Operations
1519
![Out-of-Box Dashboard for Security Operations](images/security_operations_dashboard.png)
1620

17-
### Enable Security Fundamentals Dashboards
18-
19-
![Enable Security Fundamentals Dashboards in 4 days](images/SFD_full_workflow_diagram_square.png)
2021

2122
### Security Fundamentals Dashboards Onboarding
2223
* Logging Analytics should be set up in your tenancy
@@ -26,11 +27,17 @@
2627
* [Prerequisite IAM Policies](https://docs.oracle.com/en-us/iaas/logging-analytics/doc/prerequisite-iam-policies.html)
2728
* [Enable Access to Logging Analytics and Its Resources](https://docs.oracle.com/en-us/iaas/logging-analytics/doc/enable-access-logging-analytics-and-its-resources.html)
2829

30+
* Enable logs for Network Security
31+
* [Enable Logs for VCN Flow Logs](https://docs.oracle.com/en-us/iaas/Content/Network/Tasks/vcn-flow-logs-enable.htm#:~:text=Enable%20VCN%20Flow%20Logs%20for,balancers%2C%20or%20network%20load%20balancers.&text=Open%20the%20navigation%20menu%2C%20click,Click%20Enable%20flow%20logs.)
32+
* [Enable Logs for OCI Network Firewall Traffic Logs and Threat Logs](https://docs.oracle.com/en-us/iaas/Content/network-firewall/enable-logs.htm#:~:text=Enable%20the%20Oracle%20Cloud%20Infrastructure,Click%20Enable%20Service%20Log.)
33+
* [Enable Logs for OCI Load Balancer Access Logs and Error Logs](https://docs.oracle.com/en-us/iaas/Content/Balance/Tasks/enable_log.htm)
34+
* [Enable Logs for OCI Web Application Firewall](https://docs.oracle.com/en-us/iaas/Content/Logging/Reference/details_for_lbwaf.htm)
35+
2936
### Security Fundamentals Dashboards Log Ingestion
3037
* [Ingest OCI VCN Flow Logs into OCI Logging Analytics](https://blogs.oracle.com/observability/post/how-to-ingest-oci-vcn-flow-logs-into-oci-logging-analytics)
3138
* [Ingest OCI Audit logs into OCI Logging Analytics](https://redthunder.blog/2021/06/01/getting-insights-with-oci-audit-log-with-logging-analytics-via-service-connector/)
3239

33-
* Enable Threat Intelligence Integration
40+
* Enable Threat Intelligence Enrichment for Log Sources
3441
Logging Analytics is integrated with Oracle Threat Intelligence to automatically receive the threat feed as the logs are ingested. The feature is available for all the log sources in the regions where both Logging Analytics and Oracle Threat Intelligence services are enabled. The Threat IPs widget makes use of this feature, which is not enabled by default.
3542
To enable:
3643

@@ -39,24 +46,27 @@
3946
3. Edit each source. On the Edit screen, click the “Field Enrichment” tab. Ensure the "Enabled" checkbox is checked for the "Geo location" function
4047
4. Edit the "Geo location" function by clicking the three dots, and check "Threat Intelligence enrichment" checkbox.
4148
5. If it is not, check the checkbox and click "Save Changes"
42-
6. Repeat above 5 steps for "OCI Audit Logs" Log Source.
43-
44-
### Security Fundamentals Dashboards Deployment
45-
Download the files to your local workstation. There are 3 files with “.json” extension corresponding to the 3 security dashboards
46-
1. Identity Security: Identity Security.json
47-
2. Network Security: Network Security.json
48-
3. Security Operations: Security Operations.json
49-
50-
Follow these steps to import the JSON files:
51-
1. Login to tenancy
52-
2. Navigate to LA Dashboards Console -> Observability & Management -> Logging Analytics -> Dashboards
53-
3. Click on “Import Dashboards”
54-
4. Navigate to folder containing dashboards and select the first dashboard JSON file
55-
5. Select “Specify a compartment for all dashboards” and choose compartment
56-
6. Select “Specify a compartment for all saved searches” and choose compartment
57-
7. Click on “Import”
58-
8. Repeat steps 3-7 for the second JSON file
59-
9. Navigate to LA Administration -> VCN Flow Log and Audit Log Source -> Field Enrichment tab -> Enable Threat Intelligence enrichment for Public IP or Source IP
49+
6. Repeat above 5 steps for OCI Network Firewall Traffic Logs, OCI Network Firewall Threat Logs, OCI Load Balancer Access Logs, OCI Load Balancer Error Logs, OCI WAF Logs, OCI Audit Logs Sources.
50+
51+
### Security Fundamentals Dashboards Deployment using OCI Marketplace App
52+
Security Fundamentals Dashboards (SFD) OCI Marketplace App offers a seamless, one-click solution for customers to effortlessly deploy SFD dashboards and automate the collection of essential security-related logs in Logging Analytics. This streamlined approach simplifies the setup of comprehensive security monitoring across OCI environments, empowering customers to enhance their cloud security posture with minimal effort.
53+
54+
To launch the Marketplace app:
55+
56+
* In OCI console, Navigate to Marketplace -> All Applications
57+
* Search “Security Fundamentals Dashboards”
58+
* Check I have reviewed and accept the Oracle standard Terms and Restrictions.
59+
* ![Security Fundamentals Dashboards Marketplace App](images/sfd-network-security-marketplace-app1.png)
60+
* Click Launch Stack
61+
* Review the Stack Information and Click Next
62+
* Select the Dashboard Compartment from the dropdown to deploy the dashboards
63+
* Check Create Service Connector for IAM Identity Domain Audit?
64+
* Update the Logging Analytics Log Group Name if needed
65+
* Switch Service Connector Hub State from INACTIVE to ACTIVE
66+
* Check Include Network Related Logs? checkbox
67+
* Add the Logging service Network related logs Log Group OCIDs
68+
* Click Next for the final Review, Click Create to run the stack
69+
* ![Security Fundamentals Dashboards Launch the Stack](images/sfd-network-security-marketplace-app3.png)
6070

6171
It may take some time for the data to start flowing into the dashboard. You will not see any data unless there are activities on the target system(s) that would be picked up by the corresponding widget/query.
6272

280 KB
Loading
608 KB
Loading
172 KB
Loading
198 KB
Loading
606 KB
Loading
439 KB
Loading
376 KB
Loading
452 KB
Loading

0 commit comments

Comments
 (0)