Académique Documents
Professionnel Documents
Culture Documents
3 Reference Card
Product Names
Data Processor &
Platform Manager
PM Data Processor
DP Data Indexer
DX Data Indexer DPX
Operating System Operating System Operating System Operating System
Gen 3 – Windows 2008 R2
Windows 2012 R2 Windows 2012 R2
Gen 4 – Windows 2012 R2
7.3.3: Windows 2016 new installs only CentOS 7.3 (Linux) (Gen3 LM only)
7.3.3: Windows 2016 new installs only
7.3.4: Windows 2016 7.3.4: Windows 2016
7.3.4: Windows 2016
Databases Databases Databases Databases
Elasticsearch
MSSQL Standard 2016 SP1 No Databases
Influx DB
LogRhythm_Alarms
LogRhythm_CMDB Elasticsearch
LogRhythm_Events Influx DB
LogRhythm_LogMart LogRhythm Archives LogRhythm Archives
LogRhythmEMDB
Active and Inactive Archives Active and Inactive Archives
Anubis Elasticsearch
Ensures logs don’t get dropped between the Data Indexer and the Data
Processor. Also sends acknowledgements back to the DP when it receives the Indexes and persists log data
logs.
Bulldozer GoDispatch
Registers the Elasticsearch Cluster name and Node/s in the EMDB Inserts log data received from the Data Processor and the Archive Restoration
Writes Cluster statistics to the EMDB for use in the Deployment Monitor component into Elasticsearch
Carpenter GoMaintain
Reads EMDB table values that are required for ID to Value translation purposes Maintains disk space below a threshold (80% used by default) on the Cluster
and inserts them into Elasticsearch as individual Indices that are used by volume by removing older indices
Columbo
Columbo Transporter
Runs Investigations, Tails, AI Engine Drilldowns & Report query requests against
Accepts batches of logs from DP and sends individual logs to Denorm
Elasticsearch on behalf of the Web & Client Consoles
Denorm
Grafana NGinx
Manages access to the AllConf, Grafana and Consul web-based front-ends via
Provides web-UI for visualization of metrics stored in InfluxDB
reverse-proxy
HeartThrob Vitals
Monitors the DX micro-services and system health Receives metrics from all DX micro-services
Has the ability to automatically restart DX services Receives metrics from the DP Mediator
InfluxDB
AllConf Consul-template
Renders service level configurations to disk from cluster data, allowing
Provides a web-UI for modifying the Data Indexer configuration
persistence.
Manages configuration files for all DX micro-services A Key Value (KV) store used to share service level configuration changes
All DX micro-services request their configuration files from here between all hosts in a deployment
CloudAI Data Indexer Services
Spawn Watchtower
${DXDATAPATH}\elasticsearch\data
Data Indexer logs- Repository
${DXDATAPATH} = C:\Program Files\LogRhythm\Data Indexer /usr/local/logrhythm/db/elasticsearch/data
(Default Path)
Note: This should be changed to a location other than C:
Destination Operating
Micro-Service Protocol Direction Purpose
Port System
Inbound to DX
AllConf TCP 443 Linux DX configuration
or Local
Inbound to DX
TCP 9100 Windows DX configuration
or Local
Anubis
Outbound from
Bulldozer TCP 1433 Windows & Linux SQL Server access to EMDB
DX to PM
Outbound from
Carpenter TCP 1433 Windows & Linux SQL Server access to EMDB
DX to PM
Outbound to
Denorm TCP 1433 Windows & Linux Used for SQL access
PM
TCP 9200 DX Local Only Windows & Linux Curl queries to Elasticsearch
Elasticsearch
For cluster replication and
TCP 9300-9400 Inter-node Linux federation across nodes in the
same cluster
Inbound to DX
TCP 8111 Linux Grafana dashboard on Linux
or Local
Grafana
Inbound to DX
TCP 8110 Windows Grafana dashboard on Windows
or Local
TCP 8300 Inter-node Windows & Linux Nodes in cluster sharing keys
TCP 8301 Inter-node Windows & Linux Nodes in cluster sharing keys
Inbound to DX
TCP 8112 Linux Consul administration dashboard
or Local
Transporter HTTP n/a Inbound to DX Windows & Linux API Gateway communication
Vitals
Released Versions
Below are the versions of all components that were released for 7.3.x. Please be sure you are on the version below post-upgrade.
7.3.2
Service Version
LogRhythm Administration API 7.3.2.198
LogRhythm Advanced Intelligence (AI) Engine 7.3.2.8000
LogRhythm AI Engine Cache Drilldown 7.3.2.59
LogRhythm Alarming Engine 7.3.2.9000
LogRhythm Authentication Services 7.3.2.135
LogRhythm Common 7.3.2.196
LogRhythm Configuration Manager 7.3.2.12
LogRhythm Console 7.3.2.9002
LogRhythm DX 7.3.2.5230
LogRhythm Infrastructure Installer 7.3.2.505
LogRhythm Job Manager 7.3.2.8000
LogRhythm Mediator Server Service 7.3.2.9002
LogRhythm Notification Service 7.3.2.18
LogRhythm System Monitor Service 7.3.2.8000
LogRhythm Web Services 7.3.2.436
7.3.3
Service Version
LogRhythm Administration API 7.3.3.183
LogRhythm Advanced Intelligence (AI) Engine 7.3.3.8000
LogRhythm AI Engine Cache Drilldown 7.3.3.81
LogRhythm Alarming Engine 7.3.3.8000
LogRhythm Authentication Services 7.3.3.95
LogRhythm Common 7.3.3.221
LogRhythm Configuration Manager 7.3.3.5
LogRhythm Console 7.3.3.8003
LogRhythm DX 7.3.3.5566
LogRhythm Infrastructure Installer 7.3.3.567
LogRhythm Job Manager 7.3.3.8000
LogRhythm Mediator Server Service 7.3.3.8004
LogRhythm Notification Service 7.3.3.12
LogRhythm System Monitor Service 7.3.3.8002
LogRhythm Web Services 7.3.3.167
7.3.3 HF1
Service Version
LogRhythm Administration API 7.3.3.183
LogRhythm Advanced Intelligence (AI) Engine 7.3.3.8000
LogRhythm AI Engine Cache Drilldown 7.3.3.81
LogRhythm Alarming Engine 7.3.3.8000
LogRhythm Authentication Services 7.3.3.95
LogRhythm Common 7.3.3.221
LogRhythm Configuration Manager 7.3.3.6
LogRhythm Console 7.3.3.8003
LogRhythm DX 7.3.3.5566
LogRhythm Infrastructure Installer 7.3.3.567
LogRhythm Job Manager 7.3.3.8000
LogRhythm Mediator Server Service 7.3.3.8004
LogRhythm Notification Service 7.3.3.12
LogRhythm System Monitor Service 7.3.3.8002
LogRhythm Web Services 7.3.3.167
7.3.3 HF2
Service Version
LogRhythm Administration API 7.3.3.183
LogRhythm Advanced Intelligence (AI) Engine 7.3.3.9000
LogRhythm AI Engine Cache Drilldown 7.3.3.84
LogRhythm Alarming Engine 7.3.3.8000
LogRhythm Authentication Services 7.3.3.95
LogRhythm Common 7.3.3.221
LogRhythm Configuration Manager 7.3.3.6
LogRhythm Console 7.3.3.9000
LogRhythm DX 7.3.3.5566
LogRhythm Infrastructure Installer 7.3.3.567
LogRhythm Job Manager 7.3.3.8000
LogRhythm Mediator Server Service 7.3.3.9000
LogRhythm Notification Service 7.3.3.15
LogRhythm System Monitor Service 7.3.3.9000
LogRhythm Web Services 7.3.3.167
7.3.3 HF3
Service Version
LogRhythm Administration API 7.3.3.183
LogRhythm Advanced Intelligence (AI) Engine 7.3.3.9000
LogRhythm AI Engine Cache Drilldown 7.3.3.84
LogRhythm Alarming Engine 7.3.3.9200
LogRhythm Authentication Services 7.3.3.95
LogRhythm Common 7.3.3.221
LogRhythm Configuration Manager 7.3.3.6
LogRhythm Console 7.3.3.9000
LogRhythm DX 7.3.3.5566
LogRhythm Infrastructure Installer 7.3.3.567
LogRhythm Job Manager 7.3.3.8000
LogRhythm Mediator Server Service 7.3.3.9000
LogRhythm Notification Service 7.3.3.15
LogRhythm System Monitor Service 7.3.3.9000
LogRhythm Web Services 7.3.3.167
7.3.4
Service Version
LogRhythm Administration API 7.3.4.176
LogRhythm Advanced Intelligence (AI) Engine 7.3.4.8008
LogRhythm AI Engine Cache Drilldown 7.3.4.13
LogRhythm Alarming Engine 7.3.4.8009
LogRhythm Authentication Services 7.3.4.55
LogRhythm Common 7.3.4.284
LogRhythm Configuration Manager 7.3.4.6
LogRhythm Console 7.3.4.8005
LogRhythm DX 7.3.4.6032
LogRhythm Infrastructure Installer 7.3.4.779
LogRhythm Job Manager 7.3.4.8000
LogRhythm Mediator Server Service 7.3.4.8000
LogRhythm Notification Service 7.3.4.12
LogRhythm System Monitor Service 7.3.4.8000
LogRhythm Web Services 7.3.4.119
7.3.4 HF1
Service Version
LogRhythm Administration API 7.3.4.176
LogRhythm Advanced Intelligence (AI) Engine 7.3.4.9000
LogRhythm AI Engine Cache Drilldown 7.3.4.13
LogRhythm Alarming Engine 7.3.4.8009
LogRhythm Authentication Services 7.3.4.55
LogRhythm Common 7.3.4.284
LogRhythm Configuration Manager 7.3.4.6
LogRhythm Console 7.3.4.9000
LogRhythm DX 7.3.4.6032
LogRhythm Infrastructure Installer 7.3.4.779
LogRhythm Job Manager 7.3.4.9000
LogRhythm Mediator Server Service 7.3.4.9000
LogRhythm Notification Service 7.3.4.12
LogRhythm System Monitor Service 7.3.4.8000
LogRhythm Web Services 7.3.4.119
7.3.4 HF2
Service Version
LogRhythm Administration API 7.3.4.176
LogRhythm Advanced Intelligence (AI) Engine 7.3.4.9000
LogRhythm AI Engine Cache Drilldown 7.3.4.13
LogRhythm Alarming Engine 7.3.4.8009
LogRhythm Authentication Services 7.3.4.55
LogRhythm Common 7.3.4.294
LogRhythm Configuration Manager 7.3.4.6
LogRhythm Console 7.3.4.9000
LogRhythm DX 7.3.4.6361
LogRhythm Infrastructure Installer 7.3.4.906
LogRhythm Job Manager 7.3.4.9000
LogRhythm Mediator Server Service 7.3.4.9000
LogRhythm Notification Service 7.3.4.12
LogRhythm System Monitor Service 7.3.4.9100
LogRhythm Web Services 7.3.4.126