<?xml version="1.0" encoding="ISO-8859-1"?>
<!-- ***************************************************************************** -->
<!-- Trisul Configuration File -->
<!-- Edit only if you have to, all properties must exist and contain a value -->
<!-- -->
<!-- (c) 2011-12 Unleash Networks, All rights reserved -->
<!-- ***************************************************************************** -->
<USNFPulseConfig>
<App>
<Setuid>sguil.sguil</Setuid>
<IdeallyUseThisSetuid>trisul.trisul</IdeallyUseThisSetuid>
<TempFolder>/tmp</TempFolder>
<DBRoot>/usr/local/var/lib/trisul/CONTEXT0</DBRoot>
<ConfigDB>/usr/local/var/lib/trisul/CONTEXT0/config/TRISULCONFIG.SQDB</ConfigDB>
<TrafficDBRoot>/usr/local/var/lib/trisul/CONTEXT0/meters</TrafficDBRoot>
<DBSkeletons>/usr/local/share/trisul/skeletons</DBSkeletons>
<PluginsLibDirectory>/usr/local/lib/trisul/plugins</PluginsLibDirectory>
<PluginsConfDirectory>/usr/local/etc/trisul</PluginsConfDirectory>
<PluginsDataDirectory>/usr/local/share/trisul/plugins</PluginsDataDirectory>
<ProbeID>SE-LINK</ProbeID>
<ProbeDesc>This Trisul Probe monitors the S-E link traffic only</ProbeDesc>
<PidFile>/usr/local/var/run/trisul.pid</PidFile>
<LiveStatsDumpFile>/tmp/pulse.lst</LiveStatsDumpFile>
<ThisPath>/usr/local/share/trisul</ThisPath>
<TrisulMode>TAP</TrisulMode>
<ValidTrisulModes>TAP,NETFLOW_TAP</ValidTrisulModes>
<LicenseFile>/usr/local/etc/trisul/LicenseKey.txt</LicenseFile>
<LibpcapMode>select</LibpcapMode>
<Compatibility>2.4</Compatibility>
</App>
<Logging>
<Logdir>/usr/local/var/log/trisul</Logdir>
<Logfile>ns-???.log</Logfile>
<Loglevel>DEBUG</Loglevel>
<LogRotateSize>5000000</LogRotateSize>
<LogRotateCount>5</LogRotateCount>
<EnableAccessLog>TRUE</EnableAccessLog>
<AccessLogfile>as-???.log</AccessLogfile>
<AccessLogRotateSize>5000000</AccessLogRotateSize>
<AccessLogRotateCount>5</AccessLogRotateCount>
</Logging>
<Syslog>
<Enabled>True</Enabled>
<Program>trisul</Program>
<Alerts>
<Alert name="ThresholdCrossing" guid="{03AC6B72-FDB7-44c0-9B8C-7A1975C1C5BA}">INFO</Alert>
<Alert name="FlowTracker" guid="{18CE5961-38FF-4aea-BAF8-2019F3A09063}">INFO</Alert>
<Alert name="Badfellas" guid="{5E97C3A3-41DB-4e34-92C3-87C904FAB83E}">INFO</Alert>
<Alert name="IDS" guid="{9AFD8C08-07EB-47E0-BF05-28B4A7AE8DC9}"></Alert>
</Alerts>
</Syslog>
<StatsEngine>
<HiWaterPolicy>FLEXIBLE</HiWaterPolicy>
<SQLInsertThresholdMSecs>60000</SQLInsertThresholdMSecs>
<SQLBusyTimeoutMsecs>2</SQLBusyTimeoutMsecs>
<SQLTRPBusyTimeoutMsecs>8000</SQLTRPBusyTimeoutMsecs>
<SQLSynchronousMode>0</SQLSynchronousMode>
<SQLFlushThreads>2</SQLFlushThreads>
<SQLJournalMode>default</SQLJournalMode>
<SQLCacheSize>0</SQLCacheSize>
<SQLPageSize>0</SQLPageSize>
<OverlayExistingSlices>FALSE</OverlayExistingSlices>
<SlicePolicy>
<SliceWindow>DAILY</SliceWindow>
<Operational>
<SliceCount>32</SliceCount>
<SlideAt>00:30</SlideAt>
</Operational>
<Reference>
<SliceCount>32</SliceCount>
<SlideAt>01:30</SlideAt>
</Reference>
<Archive>
<SliceCount>32</SliceCount>
<SlideAt>02:30</SlideAt>
</Archive>
</SlicePolicy>
</StatsEngine>
<Security>
<Protocol>TLS</Protocol>
<ClientAuth>true</ClientAuth>
<ServerCertificate>/usr/local/etc/trisul/certs/trisuls/Demo_TrisulServer.crt</ServerCertificate>
<ServerKey>/usr/local/etc/trisul/certs/trisuls/Demo_TrisulServer.key</ServerKey>
<CACertChain>/usr/local/etc/trisul/certs/Demo_CACerts.pem</CACertChain>
<ClientCertificateBaseDir>/usr/local/etc/trisul/certs/unsniffs</ClientCertificateBaseDir>
<DiffieHellmanParameters>/usr/local/etc/trisul/certs/TrisulDH1024.pem</DiffieHellmanParameters>
<CipherPrefs>AES256-SHA</CipherPrefs>
</Security>
<Redis>
<Enabled>True</Enabled>
<UnixSocket>/nsm/sensor_data/cfd-sosensor1-eth2/barnyard2_alert</UnixSocket>
<ConfigFile>/usr/local/etc/trisul/redis.conf</ConfigFile>
<ServerImage>/usr/local/bin/redis-server</ServerImage>
</Redis>
<Server>
<Port>12001</Port>
<DebugComms>true</DebugComms>
<DebugCommsFile>/tmp/pulse_comms.dbg</DebugCommsFile>
<ZipThreshold>100000</ZipThreshold>
<ZipProtocol>DEFLATE</ZipProtocol>
<ACL>
<ACLItem Address="
127.0.0.1" Mask="
255.255.255.255"/>
<ACLItem Address="
192.168.2.0" Mask="
255.255.255.0"/>
<ACLItem Address="
192.168.1.0" Mask="
255.255.255.0"/>
<ACLItem Address="
10.1.1.0" Mask="
255.255.255.0"/>
</ACL>
</Server>
<Ring>
<Enabled>True</Enabled>
<BaseDir>/usr/local/var/lib/trisul/CONTEXT0/caps</BaseDir>
<PassphraseFile>/usr/local/etc/trisul/certs/ringpass.txt</PassphraseFile>
<FilePrefix>RCF_</FilePrefix>
<FileSizeMB>1000</FileSizeMB>
<ProcSampleSecs>30</ProcSampleSecs>
<SysStatsUpdateSecs>10</SysStatsUpdateSecs>
<RunStatsUpdateSecs>30</RunStatsUpdateSecs>
<LiveStatsFlipSecs>100</LiveStatsFlipSecs>
<DefaultMode>FULL</DefaultMode>
<RuleChain>
<Rule mode="FULL"></Rule>
<Rule mode="FLOWCAP10M"></Rule>
<Rule mode="FLOWCAP1M"></Rule>
<Rule mode="FLOWCAP100K"></Rule>
<Rule mode="FLOWCAP10K"></Rule>
<Rule mode="HEADERS"></Rule>
<Rule mode="IGNORE"></Rule>
</RuleChain>
<SlicePolicy>
<Operational>
<SliceCount>8</SliceCount>
</Operational>
<Reference>
<SliceCount>8</SliceCount>
</Reference>
<Archive>
<SliceCount>0</SliceCount>
</Archive>
</SlicePolicy>
</Ring>
<Reassembly>
<IPDefrag>
<Enabled>True</Enabled>
</IPDefrag>
<TCPFlowTrack>
<Enabled>False</Enabled>
<HiWater>8000</HiWater>
<LoWater>6000</LoWater>
</TCPFlowTrack>
<TCPReassembly>
<Enabled>False</Enabled>
<MaxBytes>0</MaxBytes>
<KickoffBytes>5000</KickoffBytes>
<Ports>3000,80,443,22,21</Ports>
<Direction>INOUT</Direction>
<Applications>
<EnableXFFDeproxy>True</EnableXFFDeproxy>
<EnableURILog>True</EnableURILog>
<EnableHostMeter>True</EnableHostMeter>
<EnableContentTypeMeter>True</EnableContentTypeMeter>
</Applications>
</TCPReassembly>
</Reassembly>
<IDSAlerts>
<Enabled>True</Enabled>
<UnixSocket>/nsm/sensor_data/cfd-sosensor1-eth2/barnyard2_alert</UnixSocket>
<SnortVersion>2.9+</SnortVersion>
</IDSAlerts>
<OfflineImport>
<LoopCount>1</LoopCount>
<AppendMode>FALSE</AppendMode>
<InterfileGapSecs>60</InterfileGapSecs>
<AutoSortByCaptime>TRUE</AutoSortByCaptime>
<ResumeStalledImport>FALSE</ResumeStalledImport>
<AddEthernetFCS>FALSE</AddEthernetFCS>
</OfflineImport>
<TimerJump>
<MaxJumpForwardSecs>86400</MaxJumpForwardSecs>
<IgnoreJumpOnStartup>True</IgnoreJumpOnStartup>
</TimerJump>
<Tuning>
<QueueCapacity>200000</QueueCapacity>
<GrainSize>64</GrainSize>
<SpongeWindow>1</SpongeWindow>
<InflightTokens>8</InflightTokens>
<RxRingBlockCountExponent>13</RxRingBlockCountExponent>
</Tuning>
</USNFPulseConfig>