Enabling and disabling the Investigation Dashboard
This topic describes how to enable and disable the Investigation Dashboard.
Before you begin
- 64-bit architecture
- 24 GB RAM
- 4-core CPU
- Investigation Dashboard functionality opens ports 8983 and 9983 on both central managers and collectors. The ports are opened when the Investigation Dashboard is enabled and closed when it is disabled. To use the Investigation Dashboard, ensure that bidirectional communication between Central managers and collectors on ports 8983 and 9983 is not blocked by any firewall.
- Central managers and managed units must be able to reach each other via host name and IP address: ensure that DNS is configured to resolve IP addresses and host names in both forward and reverse lookup. If DNS cannot be used, use the support store hosts command to manually add IP-host name combinations. For more information, see support store hosts.
Restriction: The Investigation Dashboard and Data Level Security cannot be enabled
concurrently.
Procedure
Results
After you have enabled the Investigation Dashboard, see Accessing the investigation dashboard to learn more and begin using the investigation dashboard.
Attention: Indexed search data is retained for 3 days. Use the purge object Guardium CLI
command to change the retention period. For example, the following command changes the retention
period to 5 days: store purge object age 36 5. Note that
36 is the default object identification number associated with the search
index. For additional information, see Configuration and Control CLI Commands reference information.