Skip to main content
Skip table of contents

Least Privileged User: DP, Mediator Server

Purpose

The Mediator Server is the primary Data Processor service, and is responsible for receiving and storing log data from Agents. The service receives communication from Agents and may send communications to the AIE Communication Manager service.

Shared Resources


ReadWriteRead & ExecuteModifyFull ControlChildren Inherent
LogRhythm Installation Directory Path>\LogRhythm\LogRhythm Mediator Server



X
<LogRhythm Active Archive Path>



X
<LogRhythm Inactive Archive Path>



X
<LogRhythm Installation Directory Path>\LogRhythm\LogRhythm Mediator Server\state\DXReliablePersist



X

Archive paths can be changed from the Data Processor Advanced Properties interface in the Deployment Manager/Data Processors tab.

If the Mediator is configured to write inactive archive files to a separate server, additional file permissions must be given so the Mediator service has write permissions to the remote file share. For assistance configuring Mediator offline storage, see Data Archives and Restoration.

Registry Access


Read ControlWrite OwnerWrite DACDeleteCreate LinkEnumerate SubkeysSet ValueQuery ValueFull ControlChildren Inherent

HKEY_LOCAL_MACHINE\
System\CurrentControlSet\
services\eventlog\Security

XXXXXXXX
X

HKEY_LOCAL_MACHINE\System\
CurrentControlSet\services\
eventlog\Application

XXXXXXXX
X
HKEY_LOCAL_MACHINE\System\CurrentControlSet\
Services\WinSock2\Parameters
XXXXXXXX
X

HKEY_LOCAL_MACHINE\
SYSTEM\CurrentControlSet\
services\scmedsvr









X


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows NT\CurrentVersion\Perflib
 






X
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\
Microsoft\Windows NT\CurentVersion\Perflib
 






X
HKEY_LOCAL_MACHINE\
System\CurrentControlSet\
Services\LogRhythm Mediator:LDS
XXXXXXXX
X
HKEY_LOCAL_MACHINE\
System\CurrentControlSet\
Services\LogRhythm Mediator:LogMart
XXXXXXXX
X
HKEY_LOCAL_MACHINE\
System\CurrentControlSet\
Services\LogRhythm Mediator:Processing
XXXXXXXX
X
HKEY_LOCAL_MACHINE\
System\CurrentControlSet\
Services\LogRhythm Mediator:Stats
XXXXXXXX
X
HKEY_LOCAL_MACHINE\
SYSTEM\CurrentControlSet\
services\.NET CLR Data
X







X
HKEY_LOCAL_MACHINE\
SYSTEM\CurrentControlSet\
services\.NET CLR Networking
X







X
HKEY_LOCAL_MACHINE\
SYSTEM\CurrentControlSet\
services\.NET CLR Networking 4.0.0.0
X







X
HKEY_LOCAL_MACHINE\
SYSTEM\CurrentControlSet\
services\.NET Data Provider for Oracle
X







X

HKEY_LOCAL_MACHINE\
SYSTEM\CurrentControlSet\services\.NET Data Provider for SqlServer

X







X

Database Access

The Mediator Server uses the LogRhythmLM database user and the LogRhythmGlobalMedSvr and LogRhythmGlobalMPE security roles to access the LogRhythm EMDBs and the archive database. All permissions are set as required by the default security role.

Ports

Mediator port configuration is handled through the Console‚Äôs Deployment Manager. Click the Data Processors tab, select and right-click a Data Processor, and then click Properties. The port settings can be reached through the Advanced button, the AI Engine tab, or the Automatic Log Source Configuration tab.

PortDefault PortInbound/OutboundPurpose
ServerSSLPort443Inbound from Agent(s)Primary listener port for receiving logs from Agents
Mediator Port40000Inbound from AgentListener port for Mediator to get logs from Agent in unidirectional mode only
SecondaryServerSSLPort443Inbound from Agent(s)External-facing IP port for secondary server (if configured)
TertiaryServerSSLPort443Inbound from Agent(s)External-facing IP port for tertiary server (if configured)
AIE Client Management PortRandom/ EphemeraOutbound to AIE communicationIf this log source reports to AIE, it will call out to the configured AIE server
AIE Client Data PortRandom/ EphemeraOutbound to AIE communicationIf this log source reports to AIE, it will call out to the configured AIE server
Automatic Log Source161Inbound SNMPThe Mediator can be configured to automatically listen to and gather SNMP traps
DX Acknowledgment16000Inbound from DXAcknowledgments for log transfer from the Mediator to the Data Indexer

Other Resources

The Mediator Server does not access any external third-party systems.

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.