Two log collectors can be configured for high availability to reduce the risk of data loss. In your environment, configure one device as the primary active node and the other as the secondary backup node. If the primary node becomes offline, the secondary becomes active.
Note:
- High availability is supported on physical and virtual sensors for log collection.
- After you configure high availability, syslog still listens on both the original device management IP address and the new virtual IP address.
These resources are required:
- Two activated log collectors
- A unique Virtual Router Redundancy Protocol (VRRP) ID
- An available virtual IP for the cluster
- Both device of the same type in the same environment
These actions are required:
- Contact your Concierge Security® Team (CST) to make sure that your log sources are configured correctly.
- Connect to the serial console. For more information, see Connect to the serial console.
- On the main task screen, on the management interface, select Configure high availability for log collection, and then select Next.
- At the prompt Please select an option for high availability for log collection, select Enable.
- Select Next.
- In the VRRP router ID field, enter a unique VRRP router ID between 1 and 255 for the cluster, and then press tab.
- In the Virtual IP field, enter a unique IPv4 address for the cluster, and then press tab.
Note:
- The VRRP IP address must be different than the two management IP addresses of the cluster's nodes.
- This is the IP address that is assigned to collect forwarded syslog events.
- Check your firewall to make sure that the IP address that you configure as a virtual IP address is not already assigned to another device.
- Choose an IP address that is in the same subnet as the management IP address of the log collector.
- In the Priority field, enter the priority for the cluster node, and then select Next.
Note: Arctic Wolf recommends 110 for the primary cluster node and 90 for secondary cluster node.
Applying configuration displays.
- Configure syslog forwarding on your log sources to send log data to the new virtual IP address.
Note: If you use AD Sensor and NXLog, Arctic Wolf recommends reconfiguring them to send log data to the new virtual IP address. Contact your CST for assistance.
After you have completed the high availability configuration, contact your Arctic Wolf Concierge Security® Team (CST) to confirm that configuration was successful.