collector – SGBox Next Generation SIEM & SOAR https://www.sgbox.eu Next Generation SIEM & SOAR Wed, 11 Jun 2025 08:56:08 +0000 en-US hourly 1 https://wordpress.org/?v=6.8.1 https://www.sgbox.eu/wp-content/uploads/2025/02/cropped-SGBox-symbol-png-32x32.webp collector – SGBox Next Generation SIEM & SOAR https://www.sgbox.eu 32 32 The SGBox Collector (v6) https://www.sgbox.eu/en/knowledge-base/the-sgbox-collector-v6/ Wed, 26 Mar 2025 14:02:25 +0000 https://www.sgbox.eu/?post_type=epkb_post_type_1&p=30440  

The collector is a virtual appliance based on the Linux operating system, and is responsible for performing certain tasks of SGBox, such as collecting logs from local data sources and sending them to SGBox, via HTTPS (port 443) by establishing an encrypted channel. In addition the collector offers caching capabilities if the communication between the collector and SGBox should interrupt during the sending of data from the sources.

Requirements:

  • A collector must be deployed in your virtual infrastructure.
    • HDD 50 GB
    • RAM 4 GB
    • CPU 2 Core
    • The ports utilized by collector can be seen here Network Requirements

Notes: minimum requirements given above indicates what the appliance image will take automatically when deploying in virtualization environment, the hardware resources should be resized according to the tasks the collector will have to perform, for example, If the collector is used to run vulnerability scan you need to increase the resources: We suggest to set the minimum to 4CPU and 8GB of RAM (preferred 8CPU and 16GB of RAM).

Collector network configuration

You can configure the Collector network configuration using the cli tool present on the collector. Connect via ssh (using a program like Putty, or, virtualization console) to Collector specifying the User and Password.

version 6
User: cli
Pass: changeme

 

Choose Network configuration

The SGBox Collector (v6)

Select Configure Collector interfaces

The SGBox Collector (v6)

This option allows you to configure all the parameters (IP, Gateway, DNS and Domain) by

following the wizard

Select the interface you want to configure.

The SGBox Collector (v6)

Select static option from the menu

The SGBox Collector (v6)

Configure all the parameters

Configure all mandatory parameters (IP, Gateway, DNS and Domain). Note: If you want to add more than one DNS, you must use the character “,” to distinguish the first DNS from the second, e.g. 1.2.3.254,8.8.8.8.

The SGBox Collector (v6)

Click on Submit to finish the configuration and choose when to apply it.

Establishing a connection with SGBox

This article explains how to configure the communication between collector and SGBox. It’ll be used to download collector updates and to send logs received by the local devices to SGBox.

This communication is also useful to configure NVS checks made by the collector.

Requirements:

  • A collector must be deployed in your virtual infrastructure.
  • The configuration of the collector network must be finished.

Configure and register collector for SGBox Multi tenant

Connect via ssh (using a program like Putty, or, virtualization console) to Collector specifying the User and Password.

Tenant configuration

Choose Tenant configuration

The SGBox Collector (v6)

Configure all the parameters by entering the SGBox IP address and Tenant UID.

The SGBox Collector (v6)

Click on Submit to finish the configuration.

SGBox IP address: it depends on where SGBox is located you can insert a hostname, public IP or private IP.

TenantUID: is the code that identifies the tenant. You can find it in SGMaster on section SCM > Multi tenant > Manager then select TENANTS and identify the code in column ID

Register the collector

Choose Collector

The SGBox Collector (v6)

Select Register collector

The SGBox Collector (v6)

Enter Key Probe for Connection: the password you have configured during tenant creation activities.

The SGBox Collector (v6)

 If you can’t remember the password, you always have an option to reset it and get a new one from SGMaster on section SCM > Multi tenant > Manager and then click the “Reset” button under the Connection key column. After that follow the section on this page below to restart process.

SGBox Cloud

If your tenant is on SGBox Cloud, customers are asked to open a ticket to SGBox support via the ticket platform (https://sgboxportal.sgbox.it) by entering “collector registration for cloud tenant” in the subject of the ticket. 

External Cloud

Contact the person/company who manages SGBox for more guidance on how to obtain the key to register the collector and connect it to your tenant.

Configure a collector for SGBox Single tenant

Connect via ssh (using a program like Putty, or, virtualization console) to Collector specifying the User and Password.

Choose Tenant configuration

The SGBox Collector (v6)

Configure all the parameters by entering the SGBox IP address.

The SGBox Collector (v6)

Note: Configuring the TenantUID field is not necessary so you can leave it blank.

Click on Submit to finish the configuration.

Go to back to main menu and select Configuration

The SGBox Collector (v6)

Select  Collector configuration editor

The SGBox Collector (v6)

Change collector_legacy from 0 to 1

The SGBox Collector (v6)

Click on Save to finish the configuration.

To Restart Process

After configured, go on System’s option:

The SGBox Collector (v6)

Go on Process Handling

The SGBox Collector (v6)

go on Services Management

The SGBox Collector (v6)

For example if we want to restart a service we proceed to click on:

The SGBox Collector (v6)

We want in this case to restart sgbox-transfer so we click on our choice

The SGBox Collector (v6)

Now we click on stop service and after on start service

Configure a collector as a probe

This section explains how to configure a collector as a probe in SGBox in order to launch a Vulnerability Scan check.

Requirements:

  • A collector must be deployed in your virtual infrastructure. (link)
  • The configuration of the collector network must be finished. (link)
  • Configure and register the collector (link)
  • Connect to the SGBox web interface inside the Tenant.

    Go to SGBOX > SCM > Network > Probe 

    Click on ➕ Add New Probe button and specify:

    • Collector IP Address
    • Collector Name
    • Network or networks that belong to this collector

    The SGBox Collector (v6)
    The SGBox Collector (v6)

    ]]>
    The SGBox Collector (v5) https://www.sgbox.eu/en/knowledge-base/the-sgbox-collector/ Wed, 31 Jan 2024 10:51:16 +0000 https://www.sgbox.eu/?post_type=epkb_post_type_1&p=19442

    The collector is a virtual appliance based on the Linux operating system, and is responsible for performing certain tasks of SGBox, such as collecting logs from local data sources and sending them to SGBox, via HTTPS (port 443) by establishing an encrypted channel. In addition the collector offers caching capabilities if the communication between the collector and SGBox should interrupt during the sending of data from the sources. The collector is used in order to make  Network Vulnerability Scanner available (NVS kb).

    Requirements:

    • A collector must be deployed in your virtual infrastructure.
      • HDD 50 GB
      • RAM 4 GB
      • CPU 2 Core
      • The ports utilized by collector can be seen here Network Requirements

    Notes: minimum requirements given above indicates what the appliance image will take automatically when deploying in virtualization environment, the hardware resources should be resized according to the tasks the collector will have to perform, for example, If the collector is used to run vulnerability scan you need to increase the resources: We suggest to set the minimum to 4CPU and 8GB of RAM (preferred 8CPU and 16GB of RAM).

    Collector network configuration

    You can configure the Collector network configuration using the cli tool present on the collector. Connect via ssh (using a program like Putty, or, virtualization console) to Collector specifying the User and Password.

    version 5
    User: sgbox
    Pass: sgbox

    Choose Network configuration

    The SGBox Collector (v5)

    Select Configure Collector interfaces

    The SGBox Collector (v5)

    This option allows you to configure all the parameters (IP, Gateway, DNS and Domain) by

    following the wizard

    Select the interface you want to configure.

    The SGBox Collector (v5)

    Select static option from the menu

    The SGBox Collector (v5)

    Configure all the parameters

    Configure all mandatory parameters (IP, Gateway, DNS and Domain). Note: If you want to add more than one DNS, you must use the character “,” to distinguish the first DNS from the second, e.g. 1.2.3.254,8.8.8.8.

    The SGBox Collector (v5)

    Click on Submit to finish the configuration and choose when to apply it.

    Establishing a connection with SGBox

    This article explains how to configure the communication between collector and SGBox. It’ll be used to download collector updates and to send logs received by the local devices to SGBox.

    This communication is also useful to configure NVS checks made by the collector.

    Requirements:

    • A collector must be deployed in your virtual infrastructure.
    • The configuration of the collector network must be finished.

    Configure and register collector for SGBox Multi tenant

    Connect via ssh (using a program like Putty, or, virtualization console) to Collector specifying the User and Password.

    Username: sgbox
    Password: sgbox

    Tenant configuration

    Choose Tenant configuration

    The SGBox Collector (v5)

    Configure all the parameters by entering the SGBox IP address and Tenant UID.

    The SGBox Collector (v5)

    Click on Submit to finish the configuration.

    SGBox IP address: it depends on where SGBox is located you can insert a hostname, public IP or private IP.

    TenantUID: is the code that identifies the tenant. You can find it in SGMaster on section SCM > Multi tenant > Manager then select TENANTS and identify the code in column ID

    Register the collector

    Choose Collector

    The SGBox Collector (v5)

    Select Register collector

    The SGBox Collector (v5)

    Enter Key Probe for Connection: the password you have configured during tenant creation activities.

    The SGBox Collector (v5)

     If you can’t remember the password, you always have an option to reset it and get a new one from SGMaster on section SCM > Multi tenant > Manager and then click the “Reset” button under the Connection key column.

    Restart processes

    After configured, go on Process & stats and click on Restart processes

    The SGBox Collector (v5)
    The SGBox Collector (v5)

    Cloud consideration

    SGBox Cloud

    If your tenant is on SGBox Cloud, customers are asked to open a ticket to SGBox support via the ticket platform (https://sgboxportal.sgbox.it) by entering “collector registration for cloud tenant” in the subject of the ticket. 

    External Cloud

    Contact the person/company who manages SGBox for more guidance on how to obtain the key to register the collector and connect it to your tenant.

    Configure a collector for SGBox Single tenant

    Connect via ssh (using a program like Putty, or, virtualization console) to Collector specifying the User and Password.

    Username: sgbox
    Password: sgbox

    Choose Tenant configuration

    The SGBox Collector (v5)

    Configure all the parameters by entering the SGBox IP address.

    The SGBox Collector (v5)

    Note: Configuring the TenantUID field is not necessary so you can leave it blank.

    Click on Submit to finish the configuration.

    Go to back to main menu and select Configuration

    The SGBox Collector (v5)

    Select  Collector configuration editor

    The SGBox Collector (v5)

    Change collector_legacy from 0 to 1

    The SGBox Collector (v5)

    Click on Save to finish the configuration.

    After configured, go on Process & stats and click on Restart processes

    The SGBox Collector (v5)
    The SGBox Collector (v5)

    Configure a collector as a probe

    This section explains how to configure a collector as a probe in SGBox in order to launch a Vulnerability Scan check.

    Requirements:

    • A collector must be deployed in your virtual infrastructure. (link)
    • The configuration of the collector network must be finished. (link)
    • Configure and register the collector (link)

    Connect to the SGBox web interface inside the Tenant.

    Go to SGBOX > SCM > Network > Probe 

    Click on ➕ Add New Probe button and specify:

    • Collector IP Address
    • Collector Name
    • Network or networks that belong to this collector
    The SGBox Collector (v5)
    The SGBox Collector (v5)

    Click on OK to finish the configuration.

    ]]>
    Network Requirements https://www.sgbox.eu/en/knowledge-base/network-requirements/ Tue, 30 May 2023 15:16:23 +0000 http://10.253.1.91/?post_type=epkb_post_type_1&p=8649

    SGBox and Collector network requirements

    Following table explains the different network configuration you in order to: 

    • Manage SGBox and the Collector using WebUI and CLI.
    • Keep SGBox and the Collector updated.
    • Make a correct communication between SGBox and the Collector.
    • Allow data sources to send data to SGBox and Collector.

    From To Port Description
    Client (User) SGBox 443/tcp HTTPS WebUI
    Client (User) SGBox  22/tcp SSH (CLI)
    Client (User) Collector 22/tcp SSH (CLI)
    Client (User) Collector (v5) 4000/tcp OpenVAS console HTTPS
    Client (User) / SGBox SGBox 4000/tcp HTTPS (API)
    SGBox/Collector apps.sgbox.it 80/tcp
    443/tcp
    HTTP/S (Updates)
    SGBox/Collector *.ubuntu.com 80/tcp
    443/tcp
    HTTP/S (Updates)
    Collector (v5) feed.community.greenbone.net 873/tcp RSYNC (Updates)
    SGBox / Qualys probe qualysguard.qg3.apps.qualys.it 443/tcp Cloud (scans, results)
    SGBox / Collector (v6) registry.sgcloud.it 7442/tcp HTTPS (Updates)
    SGBox / Collector (v6) No Syslog datasources eg. 1433/tcp, 1521/tcp, 443/tcp DB, other (receive data)
    SGBox / Collector (v6) Active Directory (LDAP) 389/tcp, 636/tcp LDAP/LDAPS
    Collector  SGBox 443/tcp HTTPS (send data)
    SGAgent Collector / SGbox 443/tcp HTTPS (send data)
    Data source Collector / SGbox 514/udp Syslog (send data)
    Data source Collector / SGBox 514/tcp Syslog (send data)
    Data source Collector / SGBox 6514/tcp Syslog + TLS (send data)

    Containers networks

    SGBox and Collector (V6) introduce containers for different activities.
    Here you can find the default networks used. If for some reason your internal networks overlap the default containers networks you can change them by connecting to the collector’s CLI:
    Network Configuration > Change Docker network configuration

    VM Network Name Network Address
    SGBox, Collector default 10.42.78.0/24
    Collector sg-internal 10.10.0.0./16
    Collector sg-external 10.20.0.0/24
    Collector swarm 172.18.0.0/16

    ]]>