Up
Previous Next

Sheriff CSMâ„¢

Enable Plugins from the Sensor (Deputy) Configuration

You can enable up to 100 plugins on a Sheriff CSM Sensor from the Sheriff CSM web UI or from the Sheriff Console.

The Sheriff CSM web UI provides the fastest way to enable plugins on the Sensor, particularly, if you have Sheriff CSM All-in-One.

To enable a plugin on the Sensor configuration page in the Sheriff CSM web UI
  1. In the Sheriff CSM web UI, go to Configuration > Deployment > Components > Sheriff Center.

  2. Click one of the Sheriff CSM Sensors.

  3. Click Senor Configuration > Collection. The left column of the Sensor Configuration page shows the enabled plugins. The right column shows the plugins available for enablement.

    Sensor Configuration

  4. Move a plugin from one side to the other in either of these ways: Drag a plugin from one column to the other. Use the links [+] or [-] next to a specific item.

  5. Click Apply Changes .

  6. Configure rsyslog and logrotate .

    For instructions, see Configure the Sheriff CSM Sensor to Receive Logs Through Syslog.

You can enable all plugins on the Sensor from the Sheriff Console. However, you may find it's faster to enable plugins through the Sheriff CSM web UI, if you have Sheriff CSM All-in-One.

To enable plugins from the Sheriff Console
  1. Connect to the Sheriff Console through SSH and use your credentials to log in.

    The Sheriff Setup menu displays.

  2. Select Configure Sensor.

  3. Select Configure Data Source Plugins.

  4. Use the keyboard arrow keys to move to the plugin, select the plugin by pressing the spacebar, and then press Enter (<OK>).

  5. Press <Back> until you are on the Sheriff Setup menu again. Select Apply all Changes.

  6. Press <Yes> to confirm.

    Sheriff CSM applies the changes and restarts all the services, which may take several minutes.

  7. Configure rsyslog and logrotate.

    For instructions, see Configure the Sheriff CSM Deputy to Receive Logs Through Syslog.

Note: If you want to confirm that the correct plugin has been enabled, jailbreak the system and open /etc/vigilante/agent/config.cfg. The new plugin will appear inside the [plugins] section.
Topic revision: r9 - 31 Oct 2021, SheriffCyberSecurity
Copyright 2020 Sheriff Cyber Security, LLC. All rights reserved.