- Deploy VM from Marketplace
- Log in via SSH
- Run
sudo /witfooprecinct/register
- After a few minutes, access the web interface on port 443 (HTTPS)
In the interface go to Admin -> Settings -> General. Configure all settings.
Configure and test email integration at Admin -> Settings -> Email
Configure supported Integrations at Admin -> Settings -> Integrations (see: https://community.witfoo.com/forums/forum/integrations/)
If configuring SAML with Office 365 see: https://community.witfoo.com/forums/topic/saml-with-azure-ad-office-365/
Send syslog to the IP address of the Streamer node on 514/udp (most common), 514/tcp or 6514/tcp (for SSL or TLS). See https://community.witfoo.com/forums/forum/integrations/ for integration specific guidance.
If sending Winlogbeats or NetFlow, create an additional Streamer for each. Send NetFlow to 2055/udp. Use the following settings for Winlogbeats: https://community.witfoo.com/forums/topic/winlogbeats/
Create additional user accounts at Admin -> Users