3.10 Configuring the Collector Manager

You must configure the Collector Manager to enable communication between Sentinel and the central computer.

Sentinel Agent Manager is installed with a built-in self-signed certificate. You can use either this certificate or import a custom certificate to establish communication. If you use a built-in certificate, you must import this certificate to Sentinel.

If you want to use a custom certificate, you must configure the certificate in Sentinel Agent Manager and import this certificate into Sentinel.

To configure the Collector Manager:

  1. In Sentinel Agent Manager, do the following:

    1. Select Agent Manager Console > Configuration Wizard > Collector Manager Configuration.

    2. In the Server name field, specify the IP address or DNS name of the Sentinel server.

    3. In the Port number field, specify the port number of the Agent Manager Connector.

    4. Select SSL or TCP from the Connection type drop-down.

    5. Click Set Client Certificate.

      The details of the built-in certificate are displayed by default.

    6. (Conditional) To use a custom certificate:

      1. Specify the subject of the certificate in the Subject field.

        IMPORTANT:If you want to configure a strict authentication policy for the certificate in Sentinel, do the following:

        • Ensure that there are no spaces between the key, =, and the value.

        • If there are multiple attributes, separate the attributes using a comma followed by a space.

        For example,

        CN=sam.mf.example.com, C=US

      2. Specify the location of the certificate.

      3. Specify the name of the trust store.

  2. Import the certificate into Sentinel:

    1. Do one of the following:

      • From Sentinel Main, go to Collection > Event Source Servers > Agent Manager Servers > Client Authentication and select Strict.

      • From Sentinel Control Center, select Agent Manager Event Source Server > Edit > Security > Strict.

    2. Import the certificate.