You can set up forwarding of filtered flows. You can use filtered flows to split flow
forwarding across multiple boxes, and to forward specific flows for specific
investigations.
Procedure
-
On the target system, set up the source system as an off-site source.
-
On
the navigation menu (
), click
Admin.
-
Click .
-
Add the source system IP address, and select Receive Events and/or
Receive Flows.
-
Select Manage Connections and select which host is expecting to receive
the off-site connection.
-
Click Save.
-
Select Deploy Full Configuration from the
Advanced menu for the changes to take effect.
-
On the source system, set up the forwarding destination, IP address, and port number.
-
Click .
-
Click .
-
Set the IP address of the target system and the destination port.
-
Enter 32000 for the port number on the source system. Port 32000 is used for flow
forwarding.
-
Select Normalized from the Event Format
list.
-
Set up routing rules.
-
Click .
-
Click .
-
Select the rules that you want to add.
Note: Rules forward flows that are based on offenses, or based on CRE information when
Offline Forwarding is selected on the Routing Rules page.
The flows that are filtered on the Routing Rules screen are
forwarded.