LogRhythm administrators use the Deployment Manager to configure and manage LogRhythm components and functionality such as alarming and reporting.

Deployment Manager Tabs

The Deployment Manager is accessed in any of the following three ways:

  • On the main toolbar, click Deployment Manager.
  • On the Tools menu, click Administration, and then click Deployment Manager.
  • Press Ctrl + y.

When you access Deployment Manager, the following tabs appear.

TabDescriptionAdministrators with Access
EntitiesAn entity represents a physical location in a deployment, such as network records, and host records, and LogRhythm components. The Entities tab opens by default when you access the Deployment Manager.Global/Restricted
Platform ManagerThe Platform Manager is the hub of a LogRhythm deployment and is the central repository for events, configuration and licensing information, the LogRhythm Knowledge Base, and LogMart.Global
Data ProcessorsThe Data Processor provides high-performance, distributed, and highly available processing of machine and forensic data. Processors receive machine and forensic data from Collectors and Forensic Sensors. The number of Data Processors per deployment is based on log data volume and redundancy requirements.Global
AI EngineThe AI Engine is a Windows Server system. It is LogRhythm’s advanced analysis platform that performs correlation, pattern recognition, and behavioral analysis.Global
Network MonitorsLogRhythm NetMon sensor technology provides deep packet inspection (DPI) of network traffic, application identification, application behavior monitoring, and full packet capture.Global
System MonitorsThe System Monitor collects and forwards log data to Data Processors and can perform file integrity monitoring (FIM). When File Integrity Monitor detects changes in files and directories, the System Monitor Pro or Collector license generates and sends a log to the Data Processor.Global/Restricted
Log SourcesLog sources are single, unique origins of log data that is collected from a Host and is assigned a Message Processing Engine (MPE) policy. A single Host can have multiple Log Sources. A Log Source is the key link LogRhythm uses to determine a log message’s origin.Global/Restricted
Log Processing PoliciesPolicies determine which rules are processed against a Log Message Source and how matching logs are treated, including how long it stays online for reporting, if it is archived, and if a copy is sent to the Platform Manager.Global
Alarm RulesAlarm rules are evaluated by the Alarming and Response Manager to determine if an Event should incur an alarm. They can be system rules supplied by LogRhythm, or custom rules created by users.Global/Restricted
People and UsersCreate and maintain person records for user login identification and contact information for alarm notification.Global

Deployment Manager Specific Tools Menu Options

The following table lists the Tools menu options that are available in the Deployment Manager.

An * indicates that the option is not available to Restricted Administrators.

Deployment Manager Specific File Menu Options

The File menu options available from most Deployment Manager tabs are described in the table below.

OptionDescription
NewStarts the process of adding an additional item to the active tab. Does not appear when the Entities tab is active.
New Root EntityStarts the process of creating a top-level Entity and only appears when the Entities tab is active.
New Child EntityStarts the process of creating a child Entity under the selected Entity and only appears when the Entities tab is active.
PropertiesDisplays information about the item currently selected on the active tab.
Import License FileStarts the process to update LogRhythm Licensing.
CloseCloses the Deployment Manager, but does not close the LogRhythm Client Console.
ReconnectRe-establishes the connection to the Platform Manager database (EMDB).
ExitCloses the LogRhythm Client Console.