Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (2024)

  • Pre-Installation Checklist
  • All-in-one Installation
  • Cluster Installation

Pre-Installation Checklist

Before you begin, check the following:

  • Ensure that your system can connect to the network. You will be asked to provide a DNS Server and a host that can be resolved by the DNS Server and responds to ping. The host can either be an internal host or a public domain host like google.com.

  • Choose deployment type – Enterprise or Service Provider. The Service Provider deployment provides multi-tenancy.
  • Determine whether FIPS should be enabled
  • Choose install type:
    • All-in-one with FortiSIEM Manager
    • Cluster with Manager, Supervisor and Workers
    • All-in-one with Supervisor only, or
    • Cluster with Supervisor and Workers
  • Choose storage type for Supervisor, Worker, and/or Collector
    • Online storage - There are 4 choices
      • ClickHouse - Recommended for most deployments. Please see ClickHouse Reference Architecture for more information.
      • EventDB on local disk
      • EventDB on NFS
      • Elasticsearch
    • Archive storage – There are 2 choices
      • EventDB on NFS
      • HDFS
  • Determine hardware requirements:
Node vCPU RAM Local Disks

Manager

Minimum – 16
Recommended - 32

Minimum

  • 24GB

Recommended

  • 32GB

OS – 25GB

OPT – 200GB

CMDB – 100GB

SVN – 60GB

Supervisor (All in one) Minimum – 12
Recommended - 32

Minimum

  • without UEBA – 24GB
  • with UEBA - 32GB

Recommended

  • without UEBA – 32GB
  • with UEBA - 64GB

OS – 25GB

OPT – 100GB

CMDB – 60GB

SVN – 60GB

Local Event database – based on need

Supervisor (Cluster) Minimum – 12
Recommended - 32

Minimum

  • without UEBA – 24GB
  • with UEBA - 32GB

Recommended

  • without UEBA – 32GB
  • with UEBA - 64GB

OS – 25GB

OPT – 100GB

CMDB – 60GB

SVN – 60GB

Workers Minimum – 8
Recommended - 16

Minimum – 16GB

Recommended – 24GB

OS – 25GB

OPT – 100GB

Collector Minimum – 4
Recommended – 8 ( based on load)

Minimum – 4GB

Recommended – 8GB

OS – 25GB

OPT – 100GB

  • If your Online event database is external (e.g. EventDB on NFS or Elasticsearch), then you must configure external storage before proceeding to FortiSIEM deployment.

    • For NFS deployment, see here.

    • For Elasticsearch deployment, see here.

  • If your Online event database is internal, that is, inside Supervisor or Worker nodes, then you need to determine the size of the disks based on your EPS and event retention needs.

    • For EventDB on local disk, see here.

    • For ClickHouse, see here.

  • For OPT - 100GB, the 100GB disk for /opt will consist of a single disk that will split into 2 partitions, /OPT and swap. The partitions will be created and managed by FortiSIEM when configFSM.sh runs.

All-in-one Installation

This is the simplest installation with a single Virtual Appliance. If storage is external, then you must configure external storage before proceeding with installation.

  • Import FortiSIEM into Oracle Cloud Console
  • Configure FortiSIEM
  • Upload the FortiSIEM License
  • Configure an Event Database
  • Final Check

Import FortiSIEM into Oracle Cloud Console

  1. Go to the Fortinet Support website https://support.fortinet.com to download the KVM package FSM_Full_All_KVM_7.1.5_build0181.zip. See Downloading FortiSIEM Products for more information on downloading products from the support website.
  2. Download the packages for Super/Worker and Collector to the location where you want to install the image. For example: FSM_Full_All_KVM_7.1.5_build0181.zip.
  3. Unzip the .zip file to get the FortiSIEM-7.1.5.0181.qcow2 file.
  4. Login to the Oracle Cloud Console.
  5. At the top of the console, use the Region drop-down list to set the region where you want to deploy FortiSIEM.
  6. Open the navigation menu, and click Storage, then under Object Storage & Archive Storage, click Buckets.
  7. Under List Scope, select the compartment from the provided list. All buckets in that compartment are listed in tabular form. This is the compartment where the bucket you create will be located.
  8. Click Create Bucket.
  9. In the Bucket Name field, enter a unique bucket name, such as "fortisiem-images".
    Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (1)
  10. Click Create.
  11. Click on your bucket name, in this example, "fortisiem-images", and you will see a Upload button at the bottom of the page.
    Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (2)
  12. Click Upload, choose the qcow2 image for FortiSIEM, and from the Upload Objects window, click Upload.
    Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (3)
  13. From the left pane navigation menu, click on Compute > Custom Images.
  14. Create or select a compartment to organize your resource, for example "fortisiem".
  15. Click Import image.
  16. From the Import image window, take the following steps:
    1. In the Name field, enter the name of the image that will be imported, in this example, "FortiSIEM-VA-7.1.0.0.142".
    2. In the Operating system field, enter "Rocky Linux", and select Import from an Object Storage bucket.
    3. In the Create in compartment field, select the compartment for your image, in this example, fortisiem.
    4. In the Bucket in <compartment> field, where <compartment> is the name of your compartment, select your bucket, in this example, fortisiem-images.
    5. In the Object name field, select your image, in this example, FortiSIEM-VA-7.1.0.0142.qcow2.
    6. Under Image type, select QCOW2.
    7. Under Launch mode, ensure Paravirtualized mode is selected. If it isn't, select it.
      Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (4)
  17. Click Import image.
  18. Wait for the creation of the image to be completed successfully before proceeding.
  19. Click on Edit image capabilities, and from the Edit Image Capabilities window, set Preferred firmware to BIOS, then click Save changes.
    Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (5)
  20. Additional disks are needed by FortiSIEM. FortiSIEM requires an opt-disk, cmdb-disk, svn-disk, and depending on whether you EventDB on local storage or ClickHouse, an additional 5th disk, called the data-disk. Determine the number of disks you require before proceeding. The following steps provide the general configuration, including an example for the opt-disk.
    DiskSizeDisk Name
    opt-disk (Hard Disk 2)100GB

    /opt

    For OPT - 100GB, the 100GB disk for /opt will consist of a single disk that will split into 2 partitions, /OPT and swap. The partitions will be created and managed by FortiSIEM when configFSM.sh runs.

    cmdb-disk (Hard Disk 3)60GB/cmdb
    svn-disk (Hard Disk 4)60GB/svn
    data-disk (Hard Disk 5)60GB+ /data (see the following note)

    Note on Hard Disk 5:

    • Add the 5th disk only if using EventDB on local storage or ClickHouse. In all other cases, this disk is not required. ClickHouse is recommended for most deployments. Please see ClickHouse Reference Architecture for more information.

    • For EventDB on local disk, choose a disk based on your EPS and event retention policy. See EventDB Sizing Guide for guidance. 60GB is the minimum.

    • For ClickHouse, choose disks based on the number of Tiers and disks on each Tier. These depend on your EPS and event retention policy. See ClickHouse Sizing Guide for guidance. For example, you can choose 1 large disk for Hot Tier. Or you can choose 2 Tiers - Hot Tier comprised of one or more SSD disks and Warm Tier comprised of one or more magnetic hard disks.

  21. From the navigation menu, click Storage, and under Block Storage, click Block Volumes.
  22. Click on Create Block Volume.
  23. From the Create block volume window, take the following steps.
    1. In the Name field, enter a name for the volume, for example, "opt-disk".
    2. In Create in compartment, select the compartment to create the volume in if it differs from the compartment you wish to use.
    3. In Volume size and performance, select Custom.
    4. In the Volume size (in GB) field, enter the size for the disk you wish to create. In this example, for the opt-disk, enter "100", for 100GB.
    5. Click Create Block Volume.
      Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (6)
  24. Repeat steps 22-23 to add all disks that you require before proceeding.
  25. From the left pane navigation menu, click Compute, and under Compute, click Instance Configurations.
  26. Click Create instance configuration.
  27. Specify a name for your instance configuration, for example, "FortiSIEM-7.1.0-Super".
  28. In Image and Shape, configure the Image to the custom image you created above. For example, FortiSIEM-VA-7.1.0.0142, and configure Shape to have at least 12 vCPU and 32 GB RAM (use the minimum/recommended values from Pre-Installation Checklist at the beginning of this install guide).
  29. Create a new VNIC, or use an existing VNIC and subnet if you already have one.
  30. Automatically assign a public IPv4 address if you plan to connect to it over the Internet.
  31. You can generate a new SSH key pair and save the private/public keys.
  32. Attach the necessary Block Volumes required by taking the following steps.
    1. In the left pane navigation menu, click Compute, and under Compute, click Instances.
    2. Under List scope, select the compartment that contains your instance.
    3. From the Instances list, click your instance name that you wish to add a volume to.
    4. In Resources, click Attached block volumes.
    5. Click Select volume, and select a volume from the Volume list, with it configured as Attachment type – Paravirtualized. Repeat this process until you've attached all necessary volumes (opt, cmdb, svn, and data disks).
  33. Click Create.
  34. With this instance configuration, click on Launch instance, provide a name, and click Create.
  35. Once the instance is successfully created, click Start to get the instance running.
  36. After the instance has booted up, which can take a minute or two, you can SSH to the instance with the default password and change it, or use the Console connection > Launch Cloud Shell connection.
  37. Log in with the default login credentials:
    User: root
    Password: ProspectHills
  38. You will be required to change the password. Remember this updated password for future use. At this point, you can continue configuring FortiSIEM by using the GUI.

Configure FortiSIEM

Follow these steps to configure FortiSIEM by using a simple GUI.

  1. Log in as user root with the updated password you set in Import FortiSIEM into Oracle Cloud Console above.
  2. At the command prompt, go to /usr/local/bin and enter configFSM.sh, for example:

    # configFSM.sh

  3. In VM console, select 1 Set Timezone and then press Next.

    Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (7)

  4. Select your Region, and press Next.

    Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (8)

  5. Select your Country, and press Next.

    Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (9)

  6. Select the Country and City for your timezone, and press Next.

    Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (10)

  7. If installing a Supervisor, select 1 Supervisor, and press Next.
    If installing a Worker, select 2 Worker, and press Next.
    If installing a Collector, select 3 Collector, and press Next.
    If Installing FortiSIEM Manager, select 4 FortiSIEM Manager, and press Next.
    If Installing FortiSIEM Supervisor Follower, select 5 Supervisor Follower and press Next.
    Note: The appliance type cannot be changed once it is deployed, so ensure you have selected the correct option.

    Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (11)

    Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (12)

    Regardless of whether you select FortiSIEM Manager,Supervisor, Supervisor Follower, Worker, or Collector, you will see the same series of screens with only the header changed to reflect your target installation, unless noted otherwise.

    A dedicated ClickHouse Keeper uses a Worker, so first install a Worker and then in later steps configure the Worker as a ClickHouse Keeper.

  8. Select the Network Interface you wish to use, and press Next.

    Note: If a bond interface is configured, it will appear in the Select Network Interface window.

    Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (13)

  9. If you want to enable FIPS, then choose 2. Otherwise, choose 1. You have the option of enabling FIPS (option 3) or disabling FIPS (option 4) later.
    Note: After Installation, a 5th option to change your network configuration (5 change_network_config) is available. This allows you to change your network settings and/or host name.

    Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (14)

  10. Determine whether your network supports IPv4-only, IPv6-only, or both IPv4 and IPv6 (Dual Stack). Choose 1 for IPv4-only, choose 2 for IPv6-only, or choose 3 for both IPv4 and IPv6.
    Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (15)
  11. If you choose 1 (IPv4) or choose 3 (Both IPv4 and IPv6), and press Next, then you will move to step 12. If you choose 2 (IPv6), and press Next, then skip to step 13.
  12. Configure the network by entering the following fields. Press Next.
    OptionDescription
    IPv4 AddressThe Manager/Supervisor/Worker/Collector's IPv4 address
    NetMaskThe Manager/Supervisor/Worker/Collector's subnet
    GatewayNetwork gateway address
    DNS1, DNS2Addresses of the DNS servers

    Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (16)

  13. If you chose 1 in step 10, then you will need to skip to step 14. If you chose 2 or 3 in step 10, then you will configure the IPv6 network by entering the following fields, then press Next.
    OptionDescription
    IPv6 AddressThe Manager/Supervisor/Worker/Collector's IPv6 address
    prefix (Netmask)The Manager/Supervisor/Worker/Collector's IPv6 prefix
    Gateway ipv6IPv6 Network gateway address
    DNS1 IPv6, DNS2 IPv6Addresses of the IPv6 DNS server 1 and DNS server2

    Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (17)
    Note: If you chose option 3 in step 10 for both IPv4 and IPv6, then even if you configure 2 DNS servers for IPv4 and IPv6, the system will only use the first DNS server from IPv4 and the first DNS server from the IPv6 configuration.
    Note: In many dual stack networks, IPv4 DNS server(s) can resolve names to both IPv4 and IPv6. In such environments, if you do not have an IPv6 DNS server, then you can use public IPv6 DNS servers or use IPv4-mapped IPv6 address.

  14. Configure Hostname for FortiSIEM Manager/Supervisor/Worker/Collector. Press Next.
    Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (18)
    Note: FQDN is no longer needed.
  15. Test network connectivity by entering a host name that can be resolved by your DNS Server (entered in the previous step) and can respond to a ping. The host can either be an internal host or a public domain host like google.com. Press Next.

    Note: By default, “google.com” is shown for the connectivity test, but if configuring IPv6, you must enter an accessible internally approved IPv6 DNS server, for example: “ipv6-dns.fortinet.com"
    Note: When configuring both IPv4 and IPv6, only testing connectivity for the IPv6 DNS is required because the IPV6 takes higher precedence. So update the host field with an approved IPv6 DNS server.

    Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (19)

  16. The final configuration confirmation is displayed. Verify that the parameters are correct. If they are not, then press Back to return to previous dialog boxes to correct any errors. If everything is OK, then press Run.

    Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (20)

    The options are described in the following table.

    OptionDescription
    -rThe FortiSIEM component being configured
    -zThe time zone being configured
    -iIPv4-formatted address
    -mAddress of the subnet mask
    -gAddress of the gateway server used
    --hostHost name
    -fFQDN address: fully-qualified domain name
    -tThe IP type. The values can be either 4 (for ipv4) or 6 (for v6) or 64 (for both ipv4 and ipv6).

    --dns1, --dns2

    Addresses of the DNS servers

    --i6

    IPv6-formatted address

    --m6

    IPv6 prefix

    --g6

    IPv6 gateway

    -o

    Installation option (install_without_fips, install_with_fips, enable_fips, disable_fips, change_network_config*)
    *Option only available after installation.

    -zTime zone. Possible values are US/Pacific, Asia/Shanghai, Europe/London, or Africa/Tunis

    --testpinghost

    The URL used to test connectivity

  17. It will take some time for this process to finish. When it is done, proceed to Upload the FortiSIEM License. If the VM fails, you can inspect the ansible.log file located at /usr/local/fresh-install/logs to try and identify the problem.

Upload the FortiSIEM License

Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (21)

Before proceeding, make sure that you have obtained valid FortiSIEM license from Forticare. For more information, see the Licensing Guide.

You will now be asked to input a license.

  1. Open a Web browser and log in to the FortiSIEM UI. Use link https://<supervisor-ip> to login. Please note that if you are logging into FortiSIEM with an IPv6 address, you should input https://[IPv6 address] on the browser tab.
  2. The License Upload dialog box will open.

    Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (22)

  3. Click Browse and upload the license file.

    Make sure that the Hardware ID shown in the License Upload page matches the license.

  4. For User ID and Password, choose any Full Admin credentials.

    For the first time installation, enter admin as the user and admin*1 as the password. You will then be asked to create a new password for GUI access.

  5. Choose License type as Enterprise or Service Provider.

    This option is available only for a first time installation. Once the database is configured, this option will not be available.
    For FortiSIEM Manager, License Type is not an available option, and will not appear. At this point, FortiSIEM Manager installation is complete. You will not be taken the Event Database Storage page, so you can skip Configure an Event Database.
    Note: The FortiSIEM Manager license allows a certain number of instances that can be registered to FortiSIEM Manager.

  6. Proceed to Configure an Event Database.

Configure an Event Database

Choose the event database.

Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (23)

If the Event Database is one of the following options, additional disk configuration is required.

  • ClickHouse: See Case 2 in Creating ClickHouse Online Storage.

    Recommended for most deployments. Please see ClickHouse Reference Architecture for more information.

  • EventDB on Local Disk: See Case 2 in Creating EventDB Online Storage.

Final Check

FortiSIEM installation is complete. If the installation is successful, the VM will reboot automatically. Otherwise, the VM will stop at the failed task.

You can inspect the ansible.log file located at /usr/local/fresh-install/logs if you encounter any issues during FortiSIEM installation.

After installation completes, ensure that the phMonitor is up and running, for example:

# phstatus

For the Supervisor, Supervisor Follower, Worker and Collector, the response should be similar to the following.

Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (24)

For FortiSIEM Manager, the response should look similar to the following.
Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (25)

Cluster Installation

For larger installations, you can choose Worker nodes, Collector nodes, and external storage (NFS, ClickHouse, or Elasticsearch).

  • Install Supervisor
  • Install Workers
  • Register Workers
  • Create ClickHouse Topology (Optional)
  • Install Collectors
  • Register Collectors
  • Install Manager
  • Register Instances to Manager

Install Supervisor

Follow the steps in All-in-one Installation, except with the following differences.

  1. Event Database choices are EventDB on NFS, ClickHouse, or Elasticsearch.

  2. If you choose EventDB on NFS

    1. Disk 5 is not required (See Import FortiSIEM into Oracle Cloud Console Step 20).

    2. You need to configure NFS after license upload.

      Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (26)

  3. If you choose ClickHouse

    1. You need to create disks during Import FortiSIEM into Oracle Cloud Console Step 20 based on the role of the Supervisor node in the ClickHouse cluster. See the ClickHouse Sizing Guide for details.

    2. You need to configure disks after license upload.

      Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (27)

  4. If you choose Elasticsearch, define Elasticsearch endpoints after license upload. See the Elasticsearch Sizing Guide for details.

    Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (28)

Install Workers

Once the Supervisor is installed, take the same steps in All-in-one Installation to install a Worker with the following differences.

  1. Choose appropriate CPU and memory for the Worker nodes based on Sizing guide.

  2. Two hard disks for Operating Systems and FortiSIEM Application:

    • OS – 25GB

    • OPT – 100GB

      For OPT - 100GB, the 100GB disk for /opt will consist of a single disk that will split into 2 partitions, /OPT and swap. The partitions will be created and managed by FortiSIEM when configFSM.sh runs.

  3. If you are running ClickHouse, then create additional data disks based on the role of the Worker in ClickHouse topology. If it is a Keeper node, then a smaller disk is needed. If it is a data node, then a bigger disk is needed based on your EPS and retention policy. See ClickHouse Sizing Guide for details.

Sizing Guide References:

  • ClickHouse Sizing Guide

  • EventDB Sizing Guide

  • Elasticsearch Sizing Guide

Register Workers

Once the Worker is up and running, add the Worker to the Supervisor node.

  1. Go to ADMIN > License > Nodes.
  2. Select Worker from the Mode drop-down list and enter the following information:

    1. In the Host Name field, enter the Worker's host name.

    2. In the IP Address field, enter the Worker's IP address.

    3. If you are running ClickHouse, then select the number for Storage Tiers from the Storage Tiers drop-down list, and input disk paths for disks in each Tier in the Disk Path fields.

      For Disk Path, use one of the following CLI commands to find the disk names.

      fdisk -l

      or

      lsblk

      When using lsblk to find the disk name, please note that the path will be /dev/<disk>. As an example, /dev/sdc.

    4. Click Test.

      Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (29)

    5. If the test succeeds, then click Save.

  3. See ADMIN > Health > Cloud Health to ensure that the Workers are up, healthy, and properly added to the system.

    Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (30)

Create ClickHouse Topology (Optional)

If you are running ClickHouse, you need to configure ClickHouse topology by specifying which nodes belong to ClickHouse Keeper and Data Clusters. Follow the steps in Configuring ClickHouse Topology.

Install Collectors

Once Supervisor and Workers are installed, follow the same steps in All-in-one Install to install a Collector except you need to only choose OS and OPT disks. The recommended settings for Collector node are:

  • CPU = 4
  • Memory = 8GB
  • Two hard disks:
    • OS – 25GB
    • OPT – 100GB
      For OPT - 100GB, the 100GB disk for /opt will consist of a single disk that will split into 2 partitions, /OPT and swap. The partitions will be created and managed by FortiSIEM when configFSM.sh runs.

Register Collectors

Collectors can be deployed in Enterprise or Service Provider environments.

  • Enterprise Deployments
  • Service Provider Deployments

Enterprise Deployments

For Enterprise deployments, follow these steps.

  1. Log in to Supervisor with 'Admin' privileges.
  2. Go to ADMIN > Settings > System > Event Worker.
    1. Enter the IP of the Worker node. If a Supervisor node is only used, then enter the IP of the Supervisor node. Multiple IP addresses can be entered on separate lines. In this case, the Collectors will load balance the upload of events to the listed Event Workers.
      Note: Rather than using IP addresses, a DNS name is recommended. The reasoning is, should the IP addressing change, it becomes a matter of updating the DNS rather than modifying the Event Worker IP addresses in FortiSIEM.
    2. Click OK.
  3. Go to ADMIN > Setup > Collectors and add a Collector by entering:
    1. Name – Collector Name
    2. Guaranteed EPS – this is the EPS that Collector will always be able to send. It could send more if there is excess EPS available.
    3. Start Time and End Time – set to Unlimited.
  4. SSH to the Collector and run following script to register Collectors:

    phProvisionCollector --add <user> '<password>' <Super IP or Host> <Organization> <CollectorName>

    The password should be enclosed in single quotes to ensure that any non-alphanumeric characters are escaped.

    1. Set user and password using the admin user name and password for the Supervisor.
    2. Set Super IP or Host as the Supervisor's IP address.
    3. Set Organization. For Enterprise deployments, the default name is Super.
    4. Set CollectorName from Step 2a.

      The Collector will reboot during the Registration.

  5. Go to ADMIN > Health > Collector Health for the status.

    Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (31)

Service Provider Deployments

For Service Provider deployments, follow these steps.

  1. Log in to Supervisor with 'Admin' privileges.
  2. Go to ADMIN > Settings > System > Event Worker.
    1. Enter the IP of the Worker node. If a Supervisor node is only used, then enter the IP of the Supervisor node. Multiple IP addresses can be entered on separate lines. In this case, the Collectors will load balance the upload of events to the listed Event Workers.
      Note: Rather than using IP addresses, a DNS name is recommended. The reasoning is, should the IP addressing change, it becomes a matter of updating the DNS rather than modifying the Event Worker IP addresses in FortiSIEM.
    2. Click OK.

      Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (32)

  3. Go to ADMIN > Setup > Organizations and click New to add an Organization.

    Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (33)

  4. Enter the Organization Name, Admin User, Admin Password, and Admin Email.
  5. Under Collectors, click New.
  6. Enter the Collector Name, Guaranteed EPS, Start Time, and End Time.

    The last two values could be set as Unlimited. Guaranteed EPS is the EPS that the Collector will always be able to send. It could send more if there is excess EPS available.

    Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (34)

  7. SSH to the Collector and run following script to register Collectors:

    phProvisionCollector --add <user> '<password>' <Super IP or Host> <Organization> <CollectorName>

    The password should be enclosed in single quotes to ensure that any non-alphanumeric characters are escaped.

    1. Set user and password using the admin user name and password for the Organization that the Collector is going to be registered to.
    2. Set Super IP or Host as the Supervisor's IP address.
    3. Set Organization as the name of an organization created on the Supervisor.
    4. Set CollectorName from Step 6.

      Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (35)

      The Collector will reboot during the Registration.

  8. Go to ADMIN > Health > Collector Health and check the status.

    Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (36)

Install Manager

Starting with release 6.5.0, you can install FortiSIEM Manager to monitor and manage multiple FortiSIEM instances. An instance includes a Supervisor and optionally, Workers and Collectors. The FortiSIEM Manager needs to be installed on a separate Virtual Machine and requires a separate license. FortiSIEM Supervisors must be on 6.5.0 or later versions.

Follow the steps in All-in-one Install to install Manager. After any Supervisor, Workers, and Collectors are installed, you add the Supervisor instance to Manager, then Register the instance to Manager. See Register Instances to Manager.

Register Instances to Manager

To register your Supervisor instance with Manager, you will need to do two things in the following order.

  • First, add the instance to Manager

  • Then register the instance itself to Manager

Note that Communication between FortiSIEM Manager and instances is via REST APIs over HTTP(S).

Adding Instance to Manager

You can add an instance to Manager by taking the following steps.
Note: Make sure to record the FortiSIEM Instance Name, Admin User and Admin Password, as this is needed when you register your instance.

  1. Login to FortiSIEM Manager.

  2. Navigate to ADMIN > Setup.

  3. Click New.

  4. In the FortiSIEM Instance field, enter the name of the Supervisor instance you wish to add.

  5. In the Admin User field, enter the Account name you wish to use to access Manager.

  6. In the Admin Password field, enter the Password that will be associated with the Admin User account.

  7. In the Confirm Admin Password field, re-enter the Password.

  8. (Optional) In the Description field, enter any information you wish to provide about the instance.

  9. Click Save.
    Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (37)

  10. Repeat steps 1-9 to add any additional instances to Manager.
    Now, follow the instructions in Register the Instance Itself to Manager for each instance.

Register the Instance Itself to Manager

To register your instance with Manager, take the following steps.

  1. From your FortiSIEM Supervisor/Instance, navigate to ADMIN > Setup > FortiSIEM Manager, and take the following steps.

    1. In the FortiSIEM Manager FQDN/IP field, enter the FortiSIEM Manager Fully Qualified Domain Name (FQDN) or IP address.

    2. If the Supervisor is under a Supervisor Cluster environment, in the FortiSIEM super cluster FQDN/IP field, enter the Supervisor Cluster Fully Qualified Domain Name (FQDN) or IP address.

    3. In the FortiSIEM Instance Name field, enter the instance name used when adding the instance to Manager.

    4. In the Account field, enter the Admin User name used when adding the instance to Manager.

    5. In the Password field, enter your password to be associated with the Admin User name.

    6. In the Confirm Password field, re-enter your password.

    7. Click Test to verify the configuration.

    8. Click Register.
      A dialog box displaying "Registered successfully" should appear if everything is valid.
      Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (38)

    9. Login to Manager, and navigate to any one of the following pages to verify registration.

      • ADMIN > Setup and check that the box is marked in the Registered column for your instance.

      • ADMIN > Health, look for your instance under FortiSIEM Instances.

      • ADMIN > License, look for your instance under FortiSIEM Instances.

The install ansible log file is located here: /usr/local/fresh-install/logs/ansible.log.

Errors can be found at the end of the file.

Fresh Installation | Oracle Cloud Infrastructure (OCI) Installation Guide (2024)

FAQs

How to setup Oracle cloud infrastructure? ›

Get started with Oracle Cloud Infrastructure basics
  1. Introduction. ...
  2. Create a VCN. ...
  3. Launch Compute Instance. ...
  4. Connect to the Instance. ...
  5. Create and Mount Block Storage. ...
  6. Install and Configure a Web Application. ...
  7. Reuse the Boot and Block Volumes for a New Instance. ...
  8. More Learning Resources.

How to install Oracle step by step? ›

A: To install Oracle software, follow these steps:
  1. Download the Oracle software installation files from the official website.
  2. Extract the downloaded files to a specific directory.
  3. Launch the installer and choose the installation type (such as server or client).

How to install oci client? ›

Offline Installation
  1. Go to the OCI CLI release page on GitHub and select the version of the CLI that you want to install.
  2. Scroll down to the Assets section of the release page and click on the zip file to download it.
  3. Optionally validate the downloaded file.
  4. Copy the zip file to the target system.
  5. Unzip the zip file.

Which tool can automatically install Oracle Cloud infrastructure CLI? ›

The installer script automatically installs the CLI and its dependencies, Python and virtualenv.

How do I set up cloud infrastructure? ›

7 Steps To Building a Cloud Infrastructure
  1. Select a Foundation.
  2. Determine Your Delivery Infrastructure.
  3. Sketch the “Big Picture”
  4. Don't Forget Security.
  5. Prepare Your Network.
  6. Automate Management Tasks.
  7. Integrate Components.
Nov 15, 2022

Which two steps must be taken before installing a management agent for the Oracle Cloud infrastructure OCI database management service? ›

Set Up Oracle Cloud Infrastructure for Management Agent Service
  1. Step 1: Create or designate compartment(s) to use.
  2. Step 2: Create a user group.
  3. Step 3: Create policies for user group.

How do I find Oracle installation? ›

Go to your windows start program and type Oracle – HOME_NAME and select Open file location. This will take you to the Oracle home directory in your windows folder. This is where Oracle software is installed.

Where to install Oracle software? ›

Installing Oracle Database on Windows
  • Go to Oracle Database Software Downloads in your browser.
  • Download the 64-bit . ...
  • Run the setup.exe and select the installation options according to your database and Windows user requirements.

How to connect to Oracle OCI? ›

To connect to an Oracle Autonomous Database: Sign in from https://cloud.oracle.com. In Cloud Account Name, enter your cloud account name and click Next. On the Oracle Cloud Account Sign In page, enter your user name in User Name and password in Password and then click Sign In.

How to install OCI utils? ›

Installing the OCI Utilities
  1. Create the SDK configuration file for the host. ...
  2. Use instance principals by adding the instance to a dynamic group that was granted access to Oracle Cloud Infrastructure services. ...
  3. Configure oci-utils to allow root to use a non-privileged user's Oracle Cloud Infrastructure configuration files.
Apr 22, 2024

How to set up OCI? ›

  1. Install OCI-CLI.
  2. Download the latest image.
  3. Create a compartment.
  4. Create storage bucket.
  5. Upload an OVA to an OCI storage bucket.
  6. Import an OVA to OCI.
  7. Create Instance in OCI.
  8. Launch and configure an instance in OCI.

What is CLI in OCI? ›

Command Line Interface (CLI)

How to check if OCI is installed in Linux? ›

Validate OCI

You can either check this using which command or oci –version, If it is not installed on your profile then you need to install it however as you already installed it now you should see OCI is installed in your profile.

How to create Oracle Cloud Infrastructure account? ›

Get an Oracle.com Account
  1. Go to the Oracle Cloud website.
  2. Click. View Accounts.
  3. Click Create an Account.
  4. Enter your email address and other details in the appropriate fields. Be sure to complete all the required fields.
  5. Click Create Account. ...
  6. Follow the instructions in the email to verify your email address.

How to create a CDB in Oracle? ›

To create a CDB with the CREATE DATABASE command, the ENABLE_PLUGGABLE_DATABASE initialization parameter must be set to true . To create the CDB, Oracle Database must know the names and locations of the files for the CDB root and PDB$SEED . You can use the PDB seed ( PDB$SEED ) as a template to create new containers.

What is the Oracle Cloud Infrastructure? ›

Oracle Cloud Infrastructure (OCI) is a platform of cloud services that enable you to build and run a wide range of applications in a highly-available, consistently high-performance environment.

How to set up Oracle Integration cloud? ›

Steps to Create the Oracle Integration Cloud Instance:
  1. Open the navigation menu. Under Developer Services, go to Application Integration and click Integration. ...
  2. After that click on Create Integration Instance.
  3. Specify the details it prompts for and Confirm your selections, then click Create at last.
Oct 14, 2022

References

Top Articles
Latest Posts
Article information

Author: Wyatt Volkman LLD

Last Updated:

Views: 5842

Rating: 4.6 / 5 (66 voted)

Reviews: 89% of readers found this page helpful

Author information

Name: Wyatt Volkman LLD

Birthday: 1992-02-16

Address: Suite 851 78549 Lubowitz Well, Wardside, TX 98080-8615

Phone: +67618977178100

Job: Manufacturing Director

Hobby: Running, Mountaineering, Inline skating, Writing, Baton twirling, Computer programming, Stone skipping

Introduction: My name is Wyatt Volkman LLD, I am a handsome, rich, comfortable, lively, zealous, graceful, gifted person who loves writing and wants to share my knowledge and understanding with you.