Size: a a a

2020 February 24

ML

Mr Linkoln in MaxPatrol SIEM
Mohammed Houssani
RoleId = '3f678b9a-eb86-405b-bf64-72c53c0dcd19' (String)
HostAddress = '192.168.0.6' (String)
CybsiEnabled = 'False' (String)
CybsiHost = 'localhost' (String)
CybsiPort = '2443' (String)
SiemAddress = '192.168.0.9' (String)
SiemRMQUser = 'mpx_siem' (String)
SiemRMQPassword = 'P@ssw0rd' (String)
SiemElasticsearchHost = '192.168.0.9' (String)
CoreSiteId = '4D617850-6174-726F-6C39-536974654964' (String)
CoreInstallationId = 'd328246d-7a98-4ff0-ad67-e3cfdba00f41' (String)
SiteName = 'SIEM' (String)
DistributedDeployment = 'False' (Bool)
SqlServerName = 'localhost\MaxPatrolXCore' (String)
SqlServerUserName = 'sa' (String)
SqlServerPassword = 'P@ssw0rdP@ssw0rd' (String)
PostgreHost = 'localhost' (String)
PostgreUserName = 'pt_system' (String)
PostgrePassword = 'P@ssw0rdP@ssw0rd' (String)
SSLCertificateThumb = '805A6F12A9BF2978BCC718D718DB7E9F269E2D53' (String)
SmtpSender = 'Notification System <NoReply@SiemNotifications.com>' (String)
SmtpHost = 'localhost' (String)
SmtpPort = '25' (String)
SmtpUseDefaultCredentials = 'True' (Bool)
SmtpUser = '' (String)
SmtpPassword = '' (String)
SmtpSslEnabled = 'False' (Bool)
EmailNotificationRetryPeriodSeconds = '60' (String)
EmailNotificationRetryCount = '10' (String)
PtkbDbName = 'vm_content' (String)
UsePtbkServer = 'True' (Bool)
MongoDbHost = 'localhost' (String)
MongoDbPort = '27017' (String)
MongoDbLogin = 'admin' (String)
MongoDbPassword = 'P@ssw0rd' (String)
MongoDbAuthSource = 'admin' (String)
HideVulnerabilityGroups = 'False' (Bool)
PtkbFeatureHost = '192.168.0.6' (String)
DataVersion = '21.1.3058' (String)
InstallerVersion = '21.1.3058' (String)
RMQHost = 'localhost' (String)
RMQVirtualHost = 'mpx' (String)
RMQUser = 'mpx_core' (String)
RMQPassword = 'P@ssw0rd' (String)
RMQSslServerName = 'localhost' (String)
RMQSslCertPath = 'E:\Program Files\Positive Technologies\MaxPatrol SIEM Core\.install\scripts\Certificates\RMQ_Core_Client.p12' (String)
RMQSslCertPassword = 'oxah4kie2O' (String)
ServicesRMQHost = 'localhost' (String)
ServicesRMQVirtualHost = '/' (String)
ServicesRMQUser = 'mpx_core' (String)
ServicesRMQPassword = 'P@ssw0rd' (String)
ServicesRMQSslServerName = 'localhost' (String)
ServicesRMQSslCertPath = 'E:\Program Files\Positive Technologies\MaxPatrol SIEM Core\.install\scripts\Certificates\RMQ_Core_Client.p12' (String)
ServicesRMQSslCertPassword = 'oxah4kie2O' (String)
Replication = 'False' (Bool)
ReplicationPerScan = 'False' (Bool)
ReplicationInterval = '00:30:00' (String)
ReplicatedCores = '' (String)
StopOnMicroserviceError = 'False' (Bool)
IncidentAggregationTimeout = '00:01:00' (String)
IncidentIdenticalNotificationLimit = '100' (String)
PtmcHostAddress = '192.168.0.6' (String)
DefaultLocale = 'en-US' (String)
DefaultAssetTtl = '90.00:00:00' (String)
TtlCheckPeriod = '01.00:00:00' (String)
SaltMasterHost = '192.168.0.9' (String)
SaltMasterPort = '9035' (String)
MicroservicesCertificateThumb = '7EA87DDE95A95FD2D2BA8C9C1237110A9177DA46' (String)
OnlineHelpPortalUrl = '' (String)
UseOnlineHelpPortal = 'False' (Bool)
ConsiderEventsImportance = 'True' (Bool)
Be carefull with screenshots like thelis. There are deefault creds. Avoid sending screenshots like this in chats
источник

К

Кац in MaxPatrol SIEM
Mr Linkoln
Be carefull with screenshots like thelis. There are deefault creds. Avoid sending screenshots like this in chats
There is not a screenshot, but text paste. and creds are replaced by default, so I think it's just already anonymized
источник

MH

Mohammed Houssani in MaxPatrol SIEM
👍🏻👍🏻
источник

ML

Mr Linkoln in MaxPatrol SIEM
Mohammed Houssani
.
источник

MH

Mohammed Houssani in MaxPatrol SIEM
thanks guys
источник

MH

Mohammed Houssani in MaxPatrol SIEM
i think it worked
источник

IY

Ivan Yakushev in MaxPatrol SIEM
Mohammed Houssani
i think it worked
It worked if u got a green light in web interface
источник

MH

Mohammed Houssani in MaxPatrol SIEM
Yes I got it
источник

IY

Ivan Yakushev in MaxPatrol SIEM
Mohammed Houssani
Yes I got it
источник

MH

Mohammed Houssani in MaxPatrol SIEM
But there is a space issue ☹️
источник

IY

Ivan Yakushev in MaxPatrol SIEM
Mohammed Houssani
But there is a space issue ☹️
Uh
источник

MH

Mohammed Houssani in MaxPatrol SIEM
It for testing now will get a bigger server tomorrow
источник

MH

Mohammed Houssani in MaxPatrol SIEM
do i have to install UC when installing medium load version ?
источник
2020 February 25

SR

Sergey Rybkin in MaxPatrol SIEM
Mohammed Houssani
do i have to install UC when installing medium load version ?
You need PT Update and Configuration service for all type of installation
источник

MH

Mohammed Houssani in MaxPatrol SIEM
👍👍
источник

RR

Roman Redikultsev in MaxPatrol SIEM
Всем привет. Подскажите, при срабатывании правила корреляции не  привязываются активы, в чем может быть проблема?  Версия 21.0.2826
источник

R

RB in MaxPatrol SIEM
В 21.0 привязка происходит по полям dst.asset и src.asset (object и subject). Если они не заполнены в процессе корреляции то и привязка не происходит. А это нужно правила править. Вроде вот так вот.
источник

R

RB in MaxPatrol SIEM
В 21.1 механизмы привязки менялись, но я не могу подсказать как.
источник

RS

Roman Sergeev in MaxPatrol SIEM
RB
В 21.1 механизмы привязки менялись, но я не могу подсказать как.
активы наследуются из исходных событий
источник

RS

Roman Sergeev in MaxPatrol SIEM
вообще немного странно
это вливали в 21.0
может не попало в ранние билды
источник