1. Manage file-related transfers
The 'Service Management' tab allows you to start or stop the transfer of files and/or the history of events between the GCap and the GCenter. This menu also allows the filtering of files, their retention periods and the compression of logs.
The 'eve-log' du GCap are the network anomaly detection service scan logs. These events are timestamped and ordered according to the time of capture.
The functionality for generating and sending 'eve-log' events are enabled by default. Extracting and sending files to the GCenter management server is also enabled.
'Stop eve-log generation' allows you to stop the generation and storage of events on the detection probe GCap. This has the effect of stopping capturing files.
'Stop sending eve-logs (but keep on generating them)' is intended to stop sending events to the GCenter server. Note that this action has no influence on the generation of logs.
'Stop file extraction' is the action that stops extracting files captured by the probe.
'Stop sending files (but keep on extracting them)' a pour but de stopper l'envoi des fichiers au serveur GCenter. À noter que cette action n'a pas d'influence sur l'extraction des fichiers.
Services can be restarted according to the preferences of the solution administrator. Note that starting the service 'Start eve-log generation' allows to leave the possibility of launching the extraction of the files.
'Remove fileinfo events for observed files' and 'Keep fileinfo events for observed files' allow the automatic deletion or preservation of events of type 'fileinfo' about files that would not be kept for analysis by the GCenter. The goal is to reduce the signal-to-noise ratio and limit the amount of logs sent to the GCenter.
'Compress eve-log' and 'Do not compress eve-log' allow to compress or not the events captured by the GCap. This feature is disabled by default, as it consumes computing power unnecessarily. In case of intermittent connectivity, or any other issue preventing logs from being sent to the GCenter , it is advisable to enable this feature to maximize the log retention time on the GCap.
You can do it with the following CLI command :
services status [eve-compress|eve-generation|eve-upload|file-extraction|file-upload|filter-fileinfo]
services start [eve-compress|eve-generation|eve-upload|file-extraction|file-upload|filter-fileinfo]
services stop [eve-compress|eve-generation|eve-upload|file-extraction|file-upload|filter-fileinfo]