Security Compliance

Install and configure SEM agent on a Solaris server

This article describes how to install and configure the Solaris agent to log data to SEM.

First published date

10/9/2018 8:19 PM

Last published date

10/28/2021 1:51 PM

Overview

This article provides steps on how to Install and configure the Solaris agent and connectors to log Solaris daemon logs to the Security Event Manager (formerly Log & Event Manager).

Following assumptions are made:
i) You have access to an account on the Solaris server with root or super user privileges to be able to install the binaries.
ii) You are already aware of and configured Solaris server for auditing or logging for the specific daemon/services and the log file paths.

If you are not the Solaris server administrator, then consult the person who is responsible for and the the required information of log file paths etc to configure the connectors once they have installed the SEM agnet.

Product section

Security Event Manager

Cause

NA

Resolution

Below steps tested for SEM agent 6.4 and below, should work for newer versions as well.

Part One: Installing Solarwinds SEM Agent
  1. Download the agent installer from your solarwinds customer portal to a computer.
  2. Unzip the agent to expose the setup.bin file (skip this step if you downloaded the executable directly in version 6.7 and above the file is named with  <SEM ver><Agent><Linux/Unix/Solaris><Platform>Installer.bin (package with openJDK JVM) OR <SEM ver><Agent><Linux/Unix/Solaris><Platform>Installer-NoVM.bin (No JVM)
  3. Use WINSCP/Filezilla/SCP other methods to copy the setup.bin file to the Solaris server on /tmp for example
  4. Log on to the Solaris server either as root a user that has superuser privileges and then go to the directory where the installer was copied via SCP.
  5. If you uploaded the file as a user other than root, then check if the file has execute perm for the user if not give executable perm via chmod +x setup.bin
  6. Launch the installer by entering  ./setup.bin or the relevant name depending on the SEM Agent version
  7. Answer all the questions and specify the IP address or hostname of SEM Appliance when prompted.
  8. Solaris (like all Unix and Linux) can be customized where startup scripts are kept.

    Copy the file "SWLEM-agent" (from /usr/local/contego/ContegoSPOP/SWLEM-agent) to the startup scripts, ie...  /etc/init.d/ 

  9. Manually start the Solaris agent:  /usr/local/contego/ContegoSPOP/SWLEM-agent start
Part Two: Configure Connectors for Solaris Agents to start monitoring logs
  1. If using Flash console navigate to Manage > Nodes and then watch for the Solaris agent to connect.
  2. Follow the steps to Configure SEM connectors for Agent to configure individual connectors for the logs you like to monitor.
  3. OR use Configure > Connector profiles from the top navigation to create a new connector profile to create connectors and configure the file paths based on what Solaris logs you are trying to monitor.

Note: This procedure assumes that you have installed either the BSM or the Snare auditing for Solaris.

Optional:

  • Create a filter under Live events, or create an nDepth search "AnyAlert.ToolAlias = solaris", and observe the log data to verify if data is coming from Solaris Agent for the specific logs you are monitoring.
Disclaimer: Please note, any content posted herein is provided as a suggestion or recommendation to you for your internal use. This is not part of the SolarWinds software or documentation that you purchased from SolarWinds, and the information set forth herein may come from third parties. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment.  You elect to use third party content at your own risk, and you will be solely responsible for the incorporation of the same, if any.