Distributed search enables you to search across multiple NDR devices and retrieve PCAP data from multiple PX packet capture appliances. Distributed search requires one NDR appliance set up as the director node and other NDR appliances set up as the data nodes. This setup is similar to the NDR cluster setup. See Clusters.
.jpg)
Distributed Search
Distributed Search Components | Definitions |
|---|---|
Director node | An NDR appliance that is a centralized location from which to initiate distributed searches to the data nodes. The director node does not collect metadata directly from NDR data nodes or PX appliances but can pull PCAP from any connected PX appliance. NoteBy default, all NDR appliances are configured as a master data node. Use the CLI to change your NDR appliance master data node configuration to a director. |
Master data node | An NDR appliance that is connected to one PX appliance and one or more NDR data nodes or multiple PX appliances and one or more NDR data nodes. The master data node collects metadata from connected PX appliances and shares the data load across the connected NDR data nodes. |
Data node | NDR appliances connected to the Master Data Node and used to store and search metadata. |
In distributed search, multiple NDR appliances, known as NDR clusters, operate independently. NDR director nodes query these devices. This approach relies on Elasticsearch tribe nodes to operate.
To configure NDR for distributed search, open the following ports on any firewall between the data nodes and the director node:
TCP 22 on both sides.
TCP and UDP 1194 on both sides.
Converting an NDR series appliance to a director node
Converting an NDR appliance to a director node erases Elasticsearch data, and the appliance becomes an aggregation unit.
Perform this procedure on the NDR Series appliance that you want to convert to a director node.
Caution
Converting a Trellix NDR console to a director node is irreversible. You cannot revert an appliance to standard console mode without performing a factory default reset. Running a factory default reset permanently erases all system configurations, search indexes, and collected data.
To convert an NDR Series appliance into a director node in the CLI:
Your NDR appliance is now a director node. You must add master data nodes to the configuration. See Adding data nodes to the director node.
Revert a director node to a standard console
To convert a director node back to a standard Trellix NDR console, you must perform a factory default reset.
Warning
Executing a factory default reset permanently deletes all data, logs, and configurations from the appliance. Back up critical data before proceeding.
Prerequisites:
You must have administrative access credentials (npadmin) to the CLI.
Log in to the Trellix NDR console CLI as npadmin.
Enter privileged mode: enable
Enter the npadmin password.
Enter configuration mode: configure system
Run the factory default reset command: make-factory-defaults
Confirm the system prompt to clear all appliance data and restore factory default settings.
Director menu options reference
When you enter director configuration mode (enable > configure system > director), the CLI displays the director menu options.
.png)
The following table describes all available options in the director menu:
Menu Option | Description |
|---|---|
#: Data Nodes | Displays all data nodes currently connected to the director node. |
#: Delete Data Node | Removes the selected data node from the director node configuration. |
A: Add Data Node | Adds a data node or cluster master to the director node configuration package. |
S: Configure Openvpn Subnet | Defines the subnet from which an IP address is allocated to the OpenVPN tunnel interface on a connected master node. Each director node requires a distinct subnet. |
I: Configure Openvpn ServerID | Specifies the unique server identification IP address of the director node for OpenVPN client connections. |
P: Configure Openvpn Protocol | Specifies the transmission protocol for OpenVPN traffic (udp or tcp). |
C: Cancel without saving changes | Discards all uncommitted menu edits and exits director configuration mode. |
Q: Quit and save changes | Commits all configuration changes and exits director configuration mode. |
Converting an NDR Series Appliance into a Data Node
Converting an NDR Series appliance to a data node stops indexing and Elasticsearch while the change takes effect. Perform this procedure on the NDR Series appliance that you would like to convert to a data node.
To convert an NDR Series appliance to a data node:
Adding data nodes to the director node
You must add the data nodes to the director node. Perform this procedure on the director node.
To add data nodes to the director node:
You must now go to the data node CLI and associate it with this director. This is explained in Adding a data node to the director node.
Adding a data node to the director node
This section provides instructions for adding your NDR data node to your NDR director node.
To add a data node to the director node:
Removing a data node from the director node
Perform this procedure on the data node that you would like to remove from the director node.
To remove a data node from the director node: