Configuring the Data Analyzer Profile

You must have Root scope to use this feature.

The Data Analyzer (DA) is one of the main components inside a Stellar Cyber data processor. Each installation must have at least one DA and can include more than one for the purposes of capacity and high availability. The System | DATA MANAGEMENT | Data Analyzer page lists the installed DA instances.

Stellar Cyber uses Data Analyzer Profiles to store configuration parameters in a reusable bundle that can be used by one or more DA instances. In deployments with multiple DAs, this arrangement avoids having to enter configuration multiple times, and, more importantly, helps prevent possible configuration conflicts and inconsistencies.

There is always one Data Analyzer Profile in the system named "Default." In most installations this is all that will be needed.

The System | DATA MANAGEMENT | Data Analyzer Profiles interface lets Stellar Cyber administrators create and manage Data Analyzer profiles.

Data Analyzer Profiles Table

When you choose the System | DATA MANAGEMENT |Data Analyzer Profiles option, Stellar Cyber displays a list of the currently configured Data Analyzer profiles, as shown below:

The Data Analyzer Profiles table lists each configured Data Analyzer profile with a summary of its settings. See the following sections for details.

You can perform the following tasks in the Data Analyzer Profiles table:

  • Click Create to add a new Data Analyzer profile to the list. The available settings are described in the following sections.
  • Click to edit the corresponding Data Analyzer profile's settings.
  • Click to delete the corresponding Data Analyzer profile.

See the Tables page for more information on working with tables.

Adding or Editing a DA Profile

When you add or edit a Data Analyzer profile, Stellar Cyber displays a dialog box similar to the one shown below.

The following fields can be entered:

  • Profile Name – A unique name for the profile. Default is the conventional name for the default profile. This field does not support multibyte characters.
  • Optional Data Source
    • Available – A selection list shows the available data sources that can feed data to the DA. Select one and click the Add button to add it to the Added list. Only connectors that are set to run on the Data Processor and have Collect enabled appear in this list.

      The following types of connectors do not appear in the list:

      • Respond-only connectors run through a separate service and do not need a profile.

      • XDR and webhook-ingest connectors cannot be added to a profile.

      • Some connector types may be hidden for your organization.

    • Added – The data sources that have been added. To remove an item from the list click the button on the right hand side of the row.

    To pull data, a connector must be added to a Data Analyzer profile if it is running on the Data Processor.

    A connector that runs on the Data Processor is not active by default. The Data Analyzer profile tells the Data Processor which connectors to activate.

Advanced Settings

Data Lake Selection

Enable the Use Local Data Lake option to instruct the DA to rely only on the locally installed data lake.

Submitting Changes

When you have finished setting up your Data Analyzer profile, click Submit to apply your changes. Alternatively, you can use the button in the upper right corner of the dialog box to dismiss the dialog box and discard all changes.