Configure file analysis
File analysis enables you to specify files to be hashed with the SHA-256 hashing algorithm. File hashes that match a threat collection generate a detection, and file hash data can be queried in records.
ExtraHop recommends that you manage these settings from an ExtraHop console, which is the default configuration in RevealX 360. For RevealX Enterprise, sensors manage these settings by default. If you prefer to manage the settings on a console instead of a sensor, you can transfer management to a console.
Prerequisites
- You must have System and Access Administration or System Administration (RevealX 360 only) user privileges.
Configure a size limit for file filters
You can specify a size limit that applies globally to all file filters. Any file that exceeds this limit will not be hashed.
Create a file filter
You can create custom file filters that determine which files are hashed on the ExtraHop system. The ExtraHop Default filter is automatically enabled and is configured to hash executable media type files and files observed on any protocols, localities, and file extensions supported by file analysis. You can disable the default filter but you cannot modify the filter configuration.
Note: | Enabling a large number of custom file filters might affect system performance. |
Transfer management of file analysis settings
For RevealX 360, ExtraHop consoles manage file analysis settings by default. For RevealX Enterprise, ExtraHop sensors manage these settings.
Note: | Transferring management for these settings also transfers management for all shared settings. |
- Log in to the console or sensor that is currently managing file analysis settings through https://<extrahop-hostname-or-IP-address>.
- Click the System Settings icon and then click File Analysis.
-
Transfer management of file analysis to a different system.
Option Description Transfer from sensor to console - Click Transfer Management.
- From the Managing Console drop-down list, select a console name.
Transfer from console to sensor - Click N of N connected
sensors.
The Management Settings window displays a list of sensors that the console manages shared settings and a list of sensors that manage their own settings.
- Click the name of the sensor that you want to manage its own settings.
- Log in to the sensor.
- Click Transfer Management.
- From the Managing Console drop-down list, select Sensor Appliance - Self.
Thank you for your feedback. Can we contact you to ask follow up questions?