Trustwave SpiderLabs Exposes Unique Cybersecurity Threats in the Public Sector. Learn More

Trustwave SpiderLabs Exposes Unique Cybersecurity Threats in the Public Sector. Learn More

Services
Capture
Managed Detection & Response

Eliminate active threats with 24/7 threat detection, investigation, and response.

twi-managed-portal-color
Co-Managed SOC (SIEM)

Maximize your SIEM investment, stop alert fatigue, and enhance your team with hybrid security operations support.

twi-briefcase-color-svg
Advisory & Diagnostics

Advance your cybersecurity program and get expert guidance where you need it most.

tw-laptop-data
Penetration Testing

Test your physical locations and IT infrastructure to shore up weaknesses before exploitation.

twi-database-color-svg
Database Security

Prevent unauthorized access and exceed compliance requirements.

twi-email-color-svg
Email Security

Stop email threats others miss and secure your organization against the #1 ransomware attack vector.

tw-officer
Digital Forensics & Incident Response

Prepare for the inevitable with 24/7 global breach response in-region and available on-site.

tw-network
Firewall & Technology Management

Mitigate risk of a cyberattack with 24/7 incident and health monitoring and the latest threat intelligence.

Solutions
BY TOPIC
Offensive Security
Solutions to maximize your security ROI
Microsoft Exchange Server Attacks
Stay protected against emerging threats
Rapidly Secure New Environments
Security for rapid response situations
Securing the Cloud
Safely navigate and stay protected
Securing the IoT Landscape
Test, monitor and secure network objects
Why Trustwave
About Us
Awards and Accolades
Trustwave SpiderLabs Team
Trustwave Fusion Security Operations Platform
Trustwave Security Colony
Partners
Technology Alliance Partners
Key alliances who align and support our ecosystem of security offerings
Trustwave PartnerOne Program
Join forces with Trustwave to protect against the most advance cybersecurity threats
Loading...
Loading...

HOWTO: Changing the Server IP Addresses on SIEM Enterprise (SE)

Expand / Collapse


This article applies to:

  • SIEM SE 2.x
  • SIEM LME 2.x

Question:

  • How do I correctly change the IP address of the SIEM SE/LME after installation?

Procedure:

If an IP address within the SE configuration changes (for example, if the network IP address changes), you can run this procedure to make sure that the new IP address is registered with all tiers in the configuration. If required, you can change the IP addresses of all servers.

  1. Log in to the SIEM UI
  2. Navigate to Configuration > Nodes > Node Type  [Select SDW]  (Network | Interfaces sub-tab).
  3. Select the interface whose IP address you want to change, and then click Save.

    (click image to enlarge)
     
  4. The Save Network Settings dialog box displays.

     
  5. Select an Individual interfaces restart option, and then select the interface related to the IP address you just changed and click Save. Alternatively you can restart the Network Service by clicking Network Service and clicking Save).
    • Warning: If you need routes to access SIEM and if they are not persistent routes, then restarting Network Service might make SIEM inaccessible via SSH and UI
  6. Click Save.
    • Note: If you changed the SDW eth1 active IP address, and see a network settings error, close the browser and run the script (in step 7) on the command line of the machine with the new active IP address.
  7. Only run the following command when the server IP address of eth1 has changed (the active IP): 
    /opt/nsm/util/bin/change_local_ip.sh<newip> <interface>. 

    <newip> is the new IP address to set
    <interface> is the interface with the new IP address (for example, eth1)

    If this command is run on the SDW (assuming this is the active IP), it is propagated to all other tiers.
  8. For non-SDW servers, run this script on the server where the IP address was changed in step 1,2 and 3
  9. Log on to the web interface and ensure the IP addresses in the Node configuration are up to date (if the SDW active IP address was changed, log on to the web interface using the new active IP in the URL).

Notes:

This information is taken from the Trustwave_SIEM_Enterprise_2.4_Administration_Guide - Page 179


To contact Trustwave about this article or to request support:


Rate this Article:
     

Add Your Comments


Comment submission is disabled for anonymous users.
Please send feedback to Trustwave Technical Support or the Webmaster
.