20170302 zen keynote london...zentral open hub for monitoring monitor events / link to an inventory...
TRANSCRIPT
![Page 1: 20170302 ZEN Keynote London...Zentral Open hub for monitoring Monitor events / link to an inventory setup: 1. Enroll devices and connect inventory (JamfPro, etc.) 2. Near-real-time](https://reader034.vdocument.in/reader034/viewer/2022051603/5feedd3521b67d4a90633f02/html5/thumbnails/1.jpg)
Zentral Open hub for monitoring
20. April 2017 London Apple Admin Meetup
![Page 2: 20170302 ZEN Keynote London...Zentral Open hub for monitoring Monitor events / link to an inventory setup: 1. Enroll devices and connect inventory (JamfPro, etc.) 2. Near-real-time](https://reader034.vdocument.in/reader034/viewer/2022051603/5feedd3521b67d4a90633f02/html5/thumbnails/2.jpg)
event stream processing and alerting
![Page 3: 20170302 ZEN Keynote London...Zentral Open hub for monitoring Monitor events / link to an inventory setup: 1. Enroll devices and connect inventory (JamfPro, etc.) 2. Near-real-time](https://reader034.vdocument.in/reader034/viewer/2022051603/5feedd3521b67d4a90633f02/html5/thumbnails/3.jpg)
solution to verify integrity and monitor endpoints
![Page 4: 20170302 ZEN Keynote London...Zentral Open hub for monitoring Monitor events / link to an inventory setup: 1. Enroll devices and connect inventory (JamfPro, etc.) 2. Near-real-time](https://reader034.vdocument.in/reader034/viewer/2022051603/5feedd3521b67d4a90633f02/html5/thumbnails/4.jpg)
Inventory • Multiple sources • Parallel processing • Store change history
TLS server • Event logging APIs • Dedicated log /
configuration for Osquery & Santa
Framework • Organised deployment
of open source tools • Modular architecture • Python3 / Django
open hub for monitoringZentral -
![Page 5: 20170302 ZEN Keynote London...Zentral Open hub for monitoring Monitor events / link to an inventory setup: 1. Enroll devices and connect inventory (JamfPro, etc.) 2. Near-real-time](https://reader034.vdocument.in/reader034/viewer/2022051603/5feedd3521b67d4a90633f02/html5/thumbnails/5.jpg)
Zentral Open hub for monitoring
Monitor events / link to an inventory setup:
1. Enroll devices and connect inventory (JamfPro, etc.)
2. Near-real-time capture and analysis of system events and data
3. Run probes for event filtering, alerting, and proactive
automations (IFTTT)
![Page 6: 20170302 ZEN Keynote London...Zentral Open hub for monitoring Monitor events / link to an inventory setup: 1. Enroll devices and connect inventory (JamfPro, etc.) 2. Near-real-time](https://reader034.vdocument.in/reader034/viewer/2022051603/5feedd3521b67d4a90633f02/html5/thumbnails/6.jpg)
Elastic Stack Database, log aggregation, visualization
![Page 7: 20170302 ZEN Keynote London...Zentral Open hub for monitoring Monitor events / link to an inventory setup: 1. Enroll devices and connect inventory (JamfPro, etc.) 2. Near-real-time](https://reader034.vdocument.in/reader034/viewer/2022051603/5feedd3521b67d4a90633f02/html5/thumbnails/7.jpg)
Osquery Intrusion detection, infrastructure reliability, and compliance
• Sync config, push events to Zentral (TLS server)
• Low-level operating system analytics
• Query system state with simple SQL syntax
• Distributed queries, file integrity monitoring (FIM)
![Page 8: 20170302 ZEN Keynote London...Zentral Open hub for monitoring Monitor events / link to an inventory setup: 1. Enroll devices and connect inventory (JamfPro, etc.) 2. Near-real-time](https://reader034.vdocument.in/reader034/viewer/2022051603/5feedd3521b67d4a90633f02/html5/thumbnails/8.jpg)
Google Santa Binary logging, blacklisting/whitelisting for macOS
• Sync config, push events to Zentral (TLS server)
• All binary launches are logged
• Client mode: MONITOR
• Client mode: LOCKDOWN (defaults deny)
![Page 9: 20170302 ZEN Keynote London...Zentral Open hub for monitoring Monitor events / link to an inventory setup: 1. Enroll devices and connect inventory (JamfPro, etc.) 2. Near-real-time](https://reader034.vdocument.in/reader034/viewer/2022051603/5feedd3521b67d4a90633f02/html5/thumbnails/9.jpg)
Probe Bundle filters, actions and optional configuration
• Filter on events, inventory, metadata
• Organize Santa rules or Osquery SQL (dynamic config)
• Control and minimize event overhead
• Trigger actions (API calls, notify)
• Export, share as Gist (GitHub)
![Page 10: 20170302 ZEN Keynote London...Zentral Open hub for monitoring Monitor events / link to an inventory setup: 1. Enroll devices and connect inventory (JamfPro, etc.) 2. Near-real-time](https://reader034.vdocument.in/reader034/viewer/2022051603/5feedd3521b67d4a90633f02/html5/thumbnails/10.jpg)
Open hub for deployed toolsCombine powerful existing tools to meet your operational requirements
JamfPro Client management Inventory MDM solution
Munki Client management Inventory
Filewave Client management Inventory
Watchman Monitoring Health monitoring agent
Munki
Supported inventory
![Page 11: 20170302 ZEN Keynote London...Zentral Open hub for monitoring Monitor events / link to an inventory setup: 1. Enroll devices and connect inventory (JamfPro, etc.) 2. Near-real-time](https://reader034.vdocument.in/reader034/viewer/2022051603/5feedd3521b67d4a90633f02/html5/thumbnails/11.jpg)
Supported actions
Open hub for deployed toolsCombine powerful existing tools to meet your operational requirements
Slack Team chat notifications
Trello Kanban Board workflows
Zendesk Ticketing system workflows
Jira Ticketing system workflows
+ actions / notifications available for GitHub, Email, SMS, Push Notifications,…
![Page 12: 20170302 ZEN Keynote London...Zentral Open hub for monitoring Monitor events / link to an inventory setup: 1. Enroll devices and connect inventory (JamfPro, etc.) 2. Near-real-time](https://reader034.vdocument.in/reader034/viewer/2022051603/5feedd3521b67d4a90633f02/html5/thumbnails/12.jpg)
Workshop/ Demo
![Page 13: 20170302 ZEN Keynote London...Zentral Open hub for monitoring Monitor events / link to an inventory setup: 1. Enroll devices and connect inventory (JamfPro, etc.) 2. Near-real-time](https://reader034.vdocument.in/reader034/viewer/2022051603/5feedd3521b67d4a90633f02/html5/thumbnails/13.jpg)
Deployment options
GoogleCloudPlatform
zentral-all-in-one image
SaaS Zentral + Support contract
Amazon AWS
zentral-all-in-one AMI
SaaS Zentral + Support contract
Docker
Docker-Compose
(development env)
OVA / Vagrant
VMware ESXi / vSphere + on prem support option
Vagrant (eval) production production
![Page 14: 20170302 ZEN Keynote London...Zentral Open hub for monitoring Monitor events / link to an inventory setup: 1. Enroll devices and connect inventory (JamfPro, etc.) 2. Near-real-time](https://reader034.vdocument.in/reader034/viewer/2022051603/5feedd3521b67d4a90633f02/html5/thumbnails/14.jpg)
Combine tools & meet operational requirements
• Integrate services already deployed • Combine system monitoring and automation
• Full audit trail for management frameworks• Enhance control and monitor endpoints
Flexible, proactive, actionable
• Tight integration with JamfPro and other APIs
![Page 15: 20170302 ZEN Keynote London...Zentral Open hub for monitoring Monitor events / link to an inventory setup: 1. Enroll devices and connect inventory (JamfPro, etc.) 2. Near-real-time](https://reader034.vdocument.in/reader034/viewer/2022051603/5feedd3521b67d4a90633f02/html5/thumbnails/15.jpg)
Service / Support • SaaS (Cloud based service) • Professional services, custom development • Integration support (on premise)
Community support via github (free) Paid support / integration / development (on request)
![Page 16: 20170302 ZEN Keynote London...Zentral Open hub for monitoring Monitor events / link to an inventory setup: 1. Enroll devices and connect inventory (JamfPro, etc.) 2. Near-real-time](https://reader034.vdocument.in/reader034/viewer/2022051603/5feedd3521b67d4a90633f02/html5/thumbnails/16.jpg)
Thank you !