15.3 Installing the Sentinel OVF Appliance

This section provides information about installing Sentinel, Collector Manager, and Correlation Engine as an OVF appliance image.

The OVF format is a standard virtual machine format that is supported by most hypervisors, either directly or by a simple conversion. Sentinel supports OVF appliance with two certified hypervisors, but you can also use it with other hypervisors.

15.3.1 Installing Sentinel

To install the Sentinel OVF appliance:

  1. Download the OVF virtual appliance image from the Download Website.

  2. In your hypervisor's management console, import the OVF image file as a new virtual machine. Allow the hypervisor to convert the OVF image into the native format if you are prompted to do so.

  3. Review the virtual hardware resources allocated to your new virtual machine to ensure that they meet the Sentinel requirements.

  4. Power on the virtual machine.

  5. Select the language of your choice.

  6. Select the keyboard layout.

  7. Click Next.

  8. Read and accept the SUSE Enterprise Server Software License Agreement. Click Next.

  9. Read and accept the Sentinel Server Appliance License Agreement. Click Next.

  10. Set the Sentinel appliance passwords, NTP configuration and the time zone.

    Set vaadmin user credentials for logging on to Sentinel Appliance Management Console.

    NOTE:After installation, you can change the NTP configuration and time zone in the following ways:

    • Go to the command prompt and enter yast->Network Services->NTP Configuration

    • Go to Sentinel Appliance Management Console and click Time.

    If the time appears out of sync immediately after the install, run the following command to restart NTP:

    rcntp restart
    
  11. On the Sentinel Server Appliance Network Settings page, specify the hostname and domain name. Select either Static IP Address or DHCP IP Address.

  12. Click Next.

  13. (Conditional), If you have selected Static IP Address in Step 11, specify the network connection settings.

  14. Click Next.

  15. Set the Sentinel admin password, then click Next.

    It might take a few minutes for all services to start after installation because the system performs a one-time initialization. Wait until the installation finishes before you log in to the server.

  16. Make a note of the appliance IP address that is shown in the console. Use the same IP address to access the Sentinel Main interface.

15.3.2 Installing Collector Managers and Correlation Engines

To install a Collector Manager or a Correlation Engine on a VMware ESX server as an OVF appliance image:

  1. Complete Step 1 through Step 14 in Installing Sentinel.

    The installation checks for the available memory and disk space. If the available memory is less than 1 GB, the installation will not let you proceed and the Next button is greyed out.

  2. Specify the host name/IP address of the Sentinel server that the Collector Manager should connect to.

  3. Specify the Communication Server port number. The default port is 61616.

  4. Specify credentials of any user in Administrator role. Enter the user name and the password.

  5. (Conditional) If your environment uses multi-factor or strong authentication, you must provide the Sentinel client id and Sentinel client secret. For more information about authentication methods, see Authentication Methods in the Sentinel Administrator Guide.

    To retrieve the Sentinel client ID and Sentinel client secret, go to the following URL:

    https://Hostname:port/SentinelAuthServices/oauth/clients

    Where:

    • Hostname is the host name of the Sentinel server.

    • Port is the port Sentinel uses (typically 8443).

    The specified URL uses your current Sentinel session to retrieve the Sentinel client ID and Sentinel client secret.

  6. Click Next.

  7. Accept the certificate.

  8. Click Next to complete the installation.

    When the installation is complete, the installer displays a message indicating that this appliance is the Sentinel Collector Manager or the Sentinel Correlation Engine depending on what you chose to install, along with the IP address. It also displays the Sentinel server user interface IP address.