Description
This article will answer Frequently Asked Questions about MSS’s NDR offering.
Stellar has a built-in alerting system that assigns severity ratings (Critical, High, Medium, Low) based on predefined criteria. However, these severity ratings apply only to individual alerts and do not provide a complete picture of the broader security landscape.
The MSS SOC does not rely on Stellar's built-in alerts or severity criteria. Instead, we have developed a proprietary alerting system using artificial intelligence, mathematical algorithms, and cross-product correlation. The system analyzes multiple data points across your entire environment, considering all ingested logs rather than isolated alerts. By doing so, we can effectively filter out noise and focus on actionable intelligence, allowing our SOC team to determine whether an alert requires direct contact.
We recommend logging into Stellar regularly to familiarize yourself with your environment’s baseline. This will help you better understand which types of alerts are considered "normal."
If you have any questions about an alert in your report, our SOC team will be happy to review it with you.
As a general rule, if the SOC has not contacted you, no critical threats have been identified based on MSS’s custom alerting criteria. This means that while there may be "Critical" alerts in Stellar’s reporting, they have not met the threshold for an MSS Critical Alert requiring action.
For successful integration, a Security Sensor appliance is required. This sensor is normally deployed at the same location and (not necessary, but if not) should be reachable from the devices that you be setting up syslog forwarding on. This will allow the device(s) to send logs to the Security Sensor appliance which will then process and securely communicate back to our main SIEM data processor. For more information, see: NDR: Integration Guide (Start Here)
Yes. Stellar will send an email alert to the provided “Alert” email address when Stellar detects that a sensor is disconnected from the DP for 30 minutes.
For information on how to troubleshoot sensors that are disconnected from or that are not sending data to Stellar, see: Offline Sensor Troubleshooting
Stellar supports mode common firewalls and most devices that support normal syslog exporting. For more information, see: NDR: Supported Firewalls
You can verify that data is coming into and being processed by Stellar for any device that is sending syslogs be following the below steps:
Checking Threat Hunting
Yes. Stellar will send an email alert to the provided “Alert” email address when Stellar detects that a sensor is disconnected from the DP for 30 minutes.
Once (and only once) the server is authorized by SGI, you can verify that the server is connected by:
You can verify that data is coming into and being processed by Stellar for a server by following these steps:
Checking Threat Hunting
There are a couple of quick things to check to make sure everything is working correctly.
Yes!
Uninstalling the Server Sensor
During the uninstallation, a Windows command prompt window may appear. Do not close this window manually – it closes automatically when the uninstallation is complete.
Stellar Cyber recommends that you remove the Windows Server Sensor using the Change button in the Programs and Features control panel instead of the Uninstall button.
Using the Change button gives you access to the following additional uninstall options that ensure the program and all its data are removed completely:
If you are planning on reinstalling a 4.2.2+ Windows Server Sensor, Stellar Cyber recommends that you leave these items unchecked.
If you want to uninstall completely, you should check these boxes.
Yes. You can run the Set CM command along with the correct CM IP to change it.
When replacing a server, all you need to do is install the agent on the new server per the above process and open a ticket to let us know that the server has been replaced. Please also provide the server’s name and IP so an engineer can authorize the new server and remove the old one.
To add a new server, all you need to do is install the agent on the new server per the above process and open a ticket to let us know. Please also provide the server’s name and IP so an engineer can authorize the new server.
To remove a server, uninstall the Linux Agent Sensor Agent per the following instructions:
Debian and Ubuntu Uninstall
To uninstall a sensor on Debian or Ubuntu:
apt-get remove aellads
CentOS, Red Hat 6.7, AWS Linux 2 Uninstall
To uninstall a sensor on CentOS or Red Hat:
yum remove aellads
After the agent has been uninstalled: