SlideShare a Scribd company logo
Deploy RvSIEM
CEO RuSIEM
Olesya Shelestova
https://rusiem.com
support@rusiem.com
Step-by-step
• Download virtual image. You have find download links on
https://rusiem.com
• Deploy image in VMware ESX (5.5+)/Hyper-v
• Power on for VM
• Setup network options (or use DHCP)
• Set required options in the web interface  Settings
• Install RuSIEM agent for Windows OS (links for download you can find on
the site)
• Change management server in LogAgent.config file
• Setup event source for agent in web interface
Download and deploy virtual machine
• For ESX:
https://www.dropbox.com/s/frp9hf02u9qonrg/RvSIEM.ova?dl=1
Deploy in VMWare ESX
Deploy in MS Hyper-V
• Power on VM
• Check IP on console screen (if you have DHCP)
Setup ip and network
• If you not have DHCP on you network:
• Login to ssh or console. Username: rusiem, Password: P@ssw0rd2014
Ex. command:
• ssh rusiem@you_vm_ip
• sudo -i
Setup static ip and network
• Set static ip, gateway in file /etc/network/interfaces
• Save changes and reboot
Access to web interface
• Use https proto and url: https://ip_you_vm
• Username: admin, Password: admin
• Hint: you may be resize web console.
Use ctrl+“–” or cmd “–”
Deploy RvSIEM (eng)
License settings
• For RvSIEM free – you don’t need any license key
• License required only for commercial version (RuSIEM)
Ignore license messages for RvSIEM free
:)
Download agent
• Download x64 Agent http://www.mediafire.com/file/g51v275tac1ynfm/SetupRuAgent_x64-3.msi
• Or x86 http://www.mediafire.com/file/j0p78icfw9judua/SetupRuAgent_x86-3.msi
Install RuSIEM agent
Select Custom installation and set IP/fqdn name you server
RvSIEM instead rusiem.com.
Example: https://172.16.0.109/api/v1/remote/encrypt/agent
• You may check management server for agent after installation in
c:Program FilesRusiemLogAgent.config
• Open web console  “Sources”
• Press “+” icon on you installed agent
• Select ‘Windows Event log’ module
• For localhost – set hostname “.” (dot)
• Set checkbox for event log journals
• Click ‘Save’ button
• For local log collection
(when agent installed) –
don’t need account.
Agent will be use Local/System account
• After adding the source, set checkbox for apply changes
Remote collection
• We may add many remote source for one agent
• For remote log collection – we need add account with required rights
in section ‘Settings  Account for data collection’
Search events
• Open web console  section Events. Select search query “Windows
events” in drop box menu.
When logs not received
All OK, actual events received from agent source (0-10 min)
Server don’t receive events from this source in 10-60 min
Events from this source did not received more than 60 minutes
Query
• Any query may be customized
Query Filter
Period and aggregate
options
Table events fields
order in which the fields
are displayed when viewing
the event
Full text search and searches
Full text search and searches
• Full text search. Ex. Olesya, ‘172.16.0.131’
• For field: key:”value”
• With logical operators
Thank you
support@rusiem.com
https://rusiem.com

More Related Content

PPTX
RuSiem events collection and forwarding
PPTX
15 most valuable reports with CFEngine
PDF
Boris Stoyanov - Troubleshooting the Virtual Router - Run and Get Diagnostics
PPTX
CENTRAL MANAGEMENT OF NETWORK AND CALL SERVICES
PPTX
Install Salsa Windows 2012 Three Servers
PPTX
WAF in Scale
PDF
Remote Console: Say goodbye to RDP
PPTX
Setting up Cisco WSA Proxy in Transparent and Explicit Mode
RuSiem events collection and forwarding
15 most valuable reports with CFEngine
Boris Stoyanov - Troubleshooting the Virtual Router - Run and Get Diagnostics
CENTRAL MANAGEMENT OF NETWORK AND CALL SERVICES
Install Salsa Windows 2012 Three Servers
WAF in Scale
Remote Console: Say goodbye to RDP
Setting up Cisco WSA Proxy in Transparent and Explicit Mode

What's hot (20)

PPTX
Socks Over RDP
PDF
Presentation Progress TA
PPTX
Overdracht
PPTX
Zumasys Citrix Top 10 Tips and Tricks
PDF
SAP LVM Custom Instances
PDF
Oracle Enterprise Manager Cloud Control 13c13.3 Installation On Oracle Linux-7
PPT
Class.devops.chapter.1.intro
PDF
Oracle virtual server-2-t0-3-upgrade
PDF
Deploying Elixir/Phoenix with Distillery - Yaroslav Martsynuyk
PPTX
Backend Server Validation
PPTX
Factory setup wsa_9.2_v1.0
PDF
OSMC 2014: Monitoring VoIP Systems | Sebastian Damm
PDF
Virtual Security Lab Setup - OWASP Broken Web Apps, Webgoat, & ZAP
PDF
Season 4 [Free OpManager training] Part3 - Monitoring Network Performance
PPT
Managing Oracle Enterprise Manager Cloud Control 12c with Oracle Clusterware
PPTX
Season 4 [Free OpManager training] Part2- Monitoring Server Performance
PPTX
Season 4 [Free OpManager training] Part1- Discovery and classification
PPTX
Заполучили права администратора домена? Игра еще не окончена
PPTX
Windows Phone 8 - 9 Push Notifications
PDF
How To Check IE Enhanced Security Is Enabled Windows PowerShell
Socks Over RDP
Presentation Progress TA
Overdracht
Zumasys Citrix Top 10 Tips and Tricks
SAP LVM Custom Instances
Oracle Enterprise Manager Cloud Control 13c13.3 Installation On Oracle Linux-7
Class.devops.chapter.1.intro
Oracle virtual server-2-t0-3-upgrade
Deploying Elixir/Phoenix with Distillery - Yaroslav Martsynuyk
Backend Server Validation
Factory setup wsa_9.2_v1.0
OSMC 2014: Monitoring VoIP Systems | Sebastian Damm
Virtual Security Lab Setup - OWASP Broken Web Apps, Webgoat, & ZAP
Season 4 [Free OpManager training] Part3 - Monitoring Network Performance
Managing Oracle Enterprise Manager Cloud Control 12c with Oracle Clusterware
Season 4 [Free OpManager training] Part2- Monitoring Server Performance
Season 4 [Free OpManager training] Part1- Discovery and classification
Заполучили права администратора домена? Игра еще не окончена
Windows Phone 8 - 9 Push Notifications
How To Check IE Enhanced Security Is Enabled Windows PowerShell
Ad

Similar to Deploy RvSIEM (eng) (20)

PDF
AWS DataSync.pdf
PPTX
IIS Web Ecosystem
PPT
Free tools for win server administration
PPTX
Automating That "Other" OS
PDF
Open Mic - IBM Sametime Proxy Clustering
DOC
SOP - 2013 Server Build
PPTX
Build cloud os in one day belgium
PDF
Windows Hosting Documentation
PDF
Native apps in html5 with chrome packaged apps
PDF
DCHQ Cloud Application Platform | Linux Containers | Docker PaaS
ODP
Google Cloud Platform for DeVops, by Javier Ramirez @ teowaki
PDF
How to create an identifeye ar game – tech specs
PPT
Sdwest2008 V101 F Dpowerpoint Final
PDF
Step by step installation of microsoft dynamics 365 finance and operations on...
PPTX
Best free tools for win database admin
PPTX
Best free tools for w d a
PPTX
System Client Details
PPTX
Opscode Webinar: Cooking with Chef on Microsoft Windows
PPT
Tech X Virtualization Tips
PDF
Malware analysis
AWS DataSync.pdf
IIS Web Ecosystem
Free tools for win server administration
Automating That "Other" OS
Open Mic - IBM Sametime Proxy Clustering
SOP - 2013 Server Build
Build cloud os in one day belgium
Windows Hosting Documentation
Native apps in html5 with chrome packaged apps
DCHQ Cloud Application Platform | Linux Containers | Docker PaaS
Google Cloud Platform for DeVops, by Javier Ramirez @ teowaki
How to create an identifeye ar game – tech specs
Sdwest2008 V101 F Dpowerpoint Final
Step by step installation of microsoft dynamics 365 finance and operations on...
Best free tools for win database admin
Best free tools for w d a
System Client Details
Opscode Webinar: Cooking with Chef on Microsoft Windows
Tech X Virtualization Tips
Malware analysis
Ad

More from Olesya Shelestova (17)

PPTX
Руководство по формату событий для разработчиков
PPTX
RuSIEM vs SOC (En)
PPTX
RuSIEM vs SOC (Rus)
PPTX
RuSIEM IT assets
PPTX
How to create correlation rule for threat detection in RuSIEM
PPTX
From SIEM to Business processes
PPTX
Free RvSIEM. Intro (Rus)
PPTX
RuSIEM overview (english version)
PPTX
Rusiem 2017_обзор
PPTX
SIEM use cases - как их написать
PPTX
Корреляция в SIEM системах
PPTX
SIEM для ИТ
PPTX
RuSIEM. Потребители. Состав продукта. Отличия. Применение.
PPTX
RuSIEM 2016
PPTX
RuSIEM (15.11.2015)
PPTX
PPTX
автоматизируем пентест Wifi сети
Руководство по формату событий для разработчиков
RuSIEM vs SOC (En)
RuSIEM vs SOC (Rus)
RuSIEM IT assets
How to create correlation rule for threat detection in RuSIEM
From SIEM to Business processes
Free RvSIEM. Intro (Rus)
RuSIEM overview (english version)
Rusiem 2017_обзор
SIEM use cases - как их написать
Корреляция в SIEM системах
SIEM для ИТ
RuSIEM. Потребители. Состав продукта. Отличия. Применение.
RuSIEM 2016
RuSIEM (15.11.2015)
автоматизируем пентест Wifi сети

Recently uploaded (20)

PPTX
CHAPTER 2 - PM Management and IT Context
PDF
T3DD25 TYPO3 Content Blocks - Deep Dive by André Kraus
PDF
Flood Susceptibility Mapping Using Image-Based 2D-CNN Deep Learnin. Overview ...
PDF
Why TechBuilder is the Future of Pickup and Delivery App Development (1).pdf
PDF
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
PDF
How Creative Agencies Leverage Project Management Software.pdf
PDF
How to Choose the Right IT Partner for Your Business in Malaysia
PDF
SAP S4 Hana Brochure 3 (PTS SYSTEMS AND SOLUTIONS)
PDF
Adobe Illustrator 28.6 Crack My Vision of Vector Design
PDF
Odoo Companies in India – Driving Business Transformation.pdf
PDF
EN-Survey-Report-SAP-LeanIX-EA-Insights-2025.pdf
PPTX
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
PDF
AI in Product Development-omnex systems
PDF
PTS Company Brochure 2025 (1).pdf.......
PPTX
ai tools demonstartion for schools and inter college
PDF
System and Network Administraation Chapter 3
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 41
PDF
Understanding Forklifts - TECH EHS Solution
PDF
Design an Analysis of Algorithms II-SECS-1021-03
CHAPTER 2 - PM Management and IT Context
T3DD25 TYPO3 Content Blocks - Deep Dive by André Kraus
Flood Susceptibility Mapping Using Image-Based 2D-CNN Deep Learnin. Overview ...
Why TechBuilder is the Future of Pickup and Delivery App Development (1).pdf
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
How Creative Agencies Leverage Project Management Software.pdf
How to Choose the Right IT Partner for Your Business in Malaysia
SAP S4 Hana Brochure 3 (PTS SYSTEMS AND SOLUTIONS)
Adobe Illustrator 28.6 Crack My Vision of Vector Design
Odoo Companies in India – Driving Business Transformation.pdf
EN-Survey-Report-SAP-LeanIX-EA-Insights-2025.pdf
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
AI in Product Development-omnex systems
PTS Company Brochure 2025 (1).pdf.......
ai tools demonstartion for schools and inter college
System and Network Administraation Chapter 3
Internet Downloader Manager (IDM) Crack 6.42 Build 41
Understanding Forklifts - TECH EHS Solution
Design an Analysis of Algorithms II-SECS-1021-03

Deploy RvSIEM (eng)

  • 1. Deploy RvSIEM CEO RuSIEM Olesya Shelestova https://rusiem.com support@rusiem.com
  • 2. Step-by-step • Download virtual image. You have find download links on https://rusiem.com • Deploy image in VMware ESX (5.5+)/Hyper-v • Power on for VM • Setup network options (or use DHCP) • Set required options in the web interface  Settings • Install RuSIEM agent for Windows OS (links for download you can find on the site) • Change management server in LogAgent.config file • Setup event source for agent in web interface
  • 3. Download and deploy virtual machine • For ESX: https://www.dropbox.com/s/frp9hf02u9qonrg/RvSIEM.ova?dl=1
  • 5. Deploy in MS Hyper-V
  • 6. • Power on VM • Check IP on console screen (if you have DHCP)
  • 7. Setup ip and network • If you not have DHCP on you network: • Login to ssh or console. Username: rusiem, Password: P@ssw0rd2014 Ex. command: • ssh rusiem@you_vm_ip • sudo -i
  • 8. Setup static ip and network • Set static ip, gateway in file /etc/network/interfaces • Save changes and reboot
  • 9. Access to web interface • Use https proto and url: https://ip_you_vm • Username: admin, Password: admin • Hint: you may be resize web console. Use ctrl+“–” or cmd “–”
  • 11. License settings • For RvSIEM free – you don’t need any license key • License required only for commercial version (RuSIEM) Ignore license messages for RvSIEM free :)
  • 12. Download agent • Download x64 Agent http://www.mediafire.com/file/g51v275tac1ynfm/SetupRuAgent_x64-3.msi • Or x86 http://www.mediafire.com/file/j0p78icfw9judua/SetupRuAgent_x86-3.msi
  • 13. Install RuSIEM agent Select Custom installation and set IP/fqdn name you server RvSIEM instead rusiem.com. Example: https://172.16.0.109/api/v1/remote/encrypt/agent
  • 14. • You may check management server for agent after installation in c:Program FilesRusiemLogAgent.config
  • 15. • Open web console  “Sources”
  • 16. • Press “+” icon on you installed agent • Select ‘Windows Event log’ module • For localhost – set hostname “.” (dot) • Set checkbox for event log journals • Click ‘Save’ button • For local log collection (when agent installed) – don’t need account. Agent will be use Local/System account
  • 17. • After adding the source, set checkbox for apply changes
  • 18. Remote collection • We may add many remote source for one agent • For remote log collection – we need add account with required rights in section ‘Settings  Account for data collection’
  • 19. Search events • Open web console  section Events. Select search query “Windows events” in drop box menu.
  • 20. When logs not received All OK, actual events received from agent source (0-10 min) Server don’t receive events from this source in 10-60 min Events from this source did not received more than 60 minutes
  • 21. Query • Any query may be customized Query Filter Period and aggregate options Table events fields order in which the fields are displayed when viewing the event
  • 22. Full text search and searches
  • 23. Full text search and searches • Full text search. Ex. Olesya, ‘172.16.0.131’ • For field: key:”value” • With logical operators