3.1 Installing and Configuring the Universal CEF Collector

The Universal CEF Collector parses non-event data and transform the raw scan data into a format understood by Sentinel. Sentinel then stores the vulnerability data in the database and includes it in the Exploit Detection map. For more detailed information about Sentinel collectors, see the Sentinel Collector Script User’s Guide.

To install the Universal CEF Collector,

  1. Download the latest Universal CEF Collector (.zip file) from the Sentinel Plug-ins website.

  2. Log in to the Sentinel Control Center.

  3. Select the Event Source Management > Live View, then select Tools > Import plugin.

  4. Browse to and select the .zip file you just downloaded, then click Next.

  5. Follow the remaining prompts, then click Finish.

The Universal CEF Collector must be configured to work. To configure the Universal CEF Collector,

  1. In the Event Source Management live view, right-click Sentinel Server, then click Add Collector.

  2. Select Universal in the Vendor column.

  3. Select Common Event Format in the Name column, then click Next.

  4. From the Installed Collectors column, select Universal_Common-Event-Format_Collector_Version, then click Next. For example, Universal Common Event Format 2011.1r4.

  5. Follow the prompts and click Finish.

The next step is to proceed to Section 4.0, Installing the Syslog Connector.