Prerequisites
-
System Monitor version 7.26 or higher is installed.
-
JSON Parsing is enabled. For more information, refer to Configure Beats for JSON Parsing.
-
The following port is open:
|
Direction |
Port |
Protocol |
Source |
|---|---|---|---|
|
Outbound |
443 |
HTTPS |
openaibeat |
Initialize the Beat via the Web Console (Recommended)
-
Ensure that the Open Collector Connection to the SIEM (WebUI) setup has been completed.
-
Ensure that the System Monitor Agent to which you intend to send these logs has been Configured for JSON Parsing.
Use either the Enable JSON Parsing on System Monitor Agents or the Enable JSON Parsing for an Existing System Monitor Agent sections at the above link to configure the System Monitor Agent for JSON Parsing.
-
Follow the steps outlined in Add a Beat in the Web Console to create the Beat via the Web UI.
Initialize the Beat via Command Line (Legacy)
-
In the Open Collector, run the following command:
./lrctl openaibeat start -
Enter a unique Beat identifier (name).
-
Enter the hostname of your OpenAI Enterprise instance.
For example, https://api.openai.com is pre-populated by default. -
Enter the Personal Access Token (Secret Key) obtained during the steps outlined in Configure OpenAI.
-
Enter audit_logs as the log type to fetch.
-
Enter the number of days of historical data to fetch, between 1 and 7 days.
The default value is 7 days. -
Enter the number of audit log events to fetch per request, between 1 and 1000.
The default value is 100. -
Enter the polling interval, which is the time period between subsequent calls.
The default value is 60 seconds. -
Enter the hostname or IP address of the System Monitor Agent that has been Configured for JSON Parsing, and then press Enter.
Use either the Enable JSON Parsing on System Monitor Agents or the Enable JSON Parsing for an Existing System Monitor Agent sections at the above link to configure the System Monitor Agent for JSON Parsing.
-
Enter the port on which the System Monitor Agent is configured to listen for JSON data (the default is 5044), and then press Enter.
The openaibeat service started message appears. -
Check the status of the service to confirm that it’s running:
./lrctl openaibeat status -
(Optional) Edit the ChatGPT Beat configuration to update the values set above if needed.
Ensure that you have all the needed information for each step available as you will need to re-enter it:./lrctl openaibeat config edit