The Centralized JSON Policy Management system automatically delivers, installs, and updates JSON-based parsing policies to .NET 8 System Monitors without any manual intervention.
This feature is only available to users of LogRhythm SIEM version 7.26.0 and above who are using .NET8 System Monitor Agents (Windows/Linux).
.NET4 Agents and pre-7.26.0 .NET8 System Monitor Agents continue operating as before and require manual policy management.
Enable or Disable Automatic Delivery of JSON Policies
When the AutoPolicyUpdate setting is enabled, your agents only receive the policies that match the log sources they are configured to monitor. An agent monitoring AWS sources receives AWS policies; an agent monitoring endpoint sources receives endpoint policies. The catchAll policy, a fallback for any unrecognized log source, is always included for every agent regardless of configuration.
Each System Monitor Agent has an Auto Policy Update setting (enabled by default). When enabled, the agent receives the latest policy version whenever Job Manager publishes an update. Users can disable this per agent to keep a specific agent on a pinned version, which is useful for controlled environments or staged rollouts.
The AutoPolicyUpdate setting can be adjusted in the System Monitor Advanced Properties.
Centralized JSON Policy Management Functionality
Centralized JSON Policy Management works in four stages:
Policy Package Delivered by the Installer
The LogRhythm Job Manager installer bundles the policy package (policies.dat) directly. On both new installations and upgrades to LogRhythm SIEM version 7.26.0 or later, the installer automatically places this file in the correct Job Manager import folder.
After the initial installation/upgrade, LogRhythm publishes updated policy packages to the LogRhythm Community portal approximately every two weeks. These packages contain the latest parsing rules for new and updated log sources. Customers download the updated package and drop it in the import folder.
Automatic Import by Job Manager
Job Manager detects the policy package and imports it into the central EMDB database. This happens automatically when the Job Manager service starts. For each policy, Job Manager:
-
Checks whether the policy is new or has changed since the last import;
-
Skips policies that are already up to date, minimizing processing time;
-
Records the policy version, content, and release notes in the database; and
-
Removes the package file once import is complete.
Selective Delivery by Data Processor
The Data Processor manages which policies each agent receives. Rather than sending all policies to every .NET8 agent, it builds a tailored package for each agent containing only the policies relevant to its configured log sources. This package typically contains five to ten policies. The package is:
-
Delivered to the agent when it starts up;
-
Delivered only to those .NET8 agents where the Enable JSON Parser setting is enabled; and
-
Automatically pushed to the agent whenever Job Manager pushes new policy versions and the agent has auto-update enabled.
Policy Applied by .NET8 System Monitor Agent (Windows/Linux)
The .NET8 System Monitor Agent (Windows/Linux) receives its tailored policy package, verifies the integrity of each file, and loads the policies into memory. The agent then uses these policies to parse and normalize incoming log events from your connected sources.
Platform and Version Compatibility
Centralized JSON Policy Management is supported only on .NET 8 System Monitor Agents (Windows/Linux), version 7.26 or later, when paired with a Data Processor running 7.26. Both the agent and the Data Processor must be on 7.26 for automated policy delivery to function.