Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

what is the use of off-box collector in SSIM?

Created: 26 Jan 2012 | 4 comments
utkarsh's picture
+2 2 Votes
Login to vote

I am trying to understand correct use and function of off-box collector?

can anyone direct me to any document explaining use of off-box collector in Security Information Manager?

thanks!

Discussion Filed Under:

Comments

mathell's picture
26
Jan
2012
1 Vote +1
Login to vote

"off-box" really just means

"off-box" really just means the collector and agent don't run on a SSIM software appliance. There are a couple reasons for this.

 

  1. You can't install some of the collectors on the appliance, for example the Vista/2008 collector must be installed on a Windows machine. The Cisco ACS collector is installed right on the Cisco ACS box.
  2. For performance reasons, you may also choose to have a collector off-box.  For example, we have chosen to move our firewall collector to a dedicated system.
Avkash K's picture
26
Jan
2012
4 Votes +4
Login to vote

Hi Utkarsh,   Generally

Hi Utkarsh,

 

Generally following are the reaosns why we use OFFBOX approach:

1. If some application or servers are real critical for you to monitor but due to some reasons you are not able to install the agent & collector on the box, then you will use OFFBOX collection scenario.

2. OFFBOX collectors are remotely logs fetching Agent & collectors.

3. Due considering the performance issues.

4. High java utilization issue, if another java application is also running & imp.

5. Centralized Agent & collector managemt for bunch of servers which will reduce your efforts at some extent.

6. In case OnBox integration is not supported for the product.

Please look for the attached diagram for OFFBOX integration approach.

Regards,

Avkash K

Avkash K's picture
26
Jan
2012
0 Votes 0
Login to vote

Sorry missed the attachement.

Sorry missed the attachement.

OFFBOX.JPG

Regards,

Avkash K

pratik mahadik's picture
25
Mar
2012
0 Votes 0
Login to vote

off box collector ..Less events

OFF BOX COLLECTOR :--Off box Collectors install in agent machine which generate  Less Events ,And it Deployed  over a syslog server.and Installed on a separate piece of equipment and it Uses an agent to transfer the events to SSIM
•E.g.: Servers – AIX  , Windows.

Thanks & Regards

Pratik Mahadik