Sumo Logic asset export
runZero integrates with Sumo Logic so you can export your asset inventory into Sumo Logic and use it in the SIEM.
Integrating runZero with Sumo Logic
You can connect Sumo Logic and runZero in one of three ways, each with its own configuration steps.
Option A: Local script
Option B: AWS Lambda function
Option C: Sumo Logic script source
Once data is flowing, you can start using it in Sumo Logic.
Option A: Local script
Step 1: Create a Sumo Logic HTTP source
- Sign in to Sumo Logic and go to Manage Data > Collection.
- Click Add Collector, then select Hosted Collector.
- Provide a name, such as
runZero Collector, and click Save.
- Provide a name, such as
- If prompted to add a data source, click OK. Otherwise, find your Collector in the list and click Add Source.
- Select the HTTP Logs and Metrics source.
- Provide a name, such as
runZero Assets, then click Save.
- Provide a name, such as
- Copy the URL Sumo Logic provides; you need it in step 2.
Step 2: Configure your host to run the provided script
-
Pick the host that will run the script.
-
Check that the host has Python3 and Pipenv installed.
-
Save the script below on that host.
#!/usr/bin/env python3 import json import requests import os # RUNZERO CONF RUNZERO_EXPORT_TOKEN = os.environ["RUNZERO_EXPORT_TOKEN"] HEADERS = {"Authorization": f"Bearer {RUNZERO_EXPORT_TOKEN}"} BASE_URL = "https://console.runZero.com/api/v1.0" # SUMO LOGIC CONF HTTP_ENDPOINT = os.environ["SUMO_HTTP_ENDPOINT"] def main(): url = BASE_URL + "/export/org/assets.json" assets = requests.get(url, headers=HEADERS) batchsize = 500 if len(assets.json()) > 0 and assets.status_code == 200: for i in range(0, len(assets.json()), batchsize): batch = assets.json()[i:i+batchsize] f = open("upload.txt", "w") f.truncate(0) for a in batch: json.dump(a, f) f.write("\n") f.close() r = open("upload.txt") requests.post(HTTP_ENDPOINT, data=r.read()) r.close() else: print(f"No assets found - status code from runZero API: {assets.status_code}") if __name__ == "__main__": main() -
Set your environment variables with these commands:
export RUNZERO_EXPORT_TOKEN=XXX: your runZero export API token, from an organization detail page in your runZero console. Select the organization you want to export data from, then click Edit organization to view the export API token.export SUMO_HTTP_ENDPOINT=XXX: the Sumo Logic HTTP source URL you copied in step 1.
-
Create a virtual environment for the script by running
pipenv --python /path/to/python3. -
Install the
requestslibrary in the virtual environment for the API calls:pipenv shellpip install requests
-
Test the script by running it from the virtual environment.
- Start with the location from the
pipenvoutput. - Append
/bin/python3to use Python in the virtual environment. - Use the full path to the script.
my-server:~/ $ /home/user/.local/share/virtualenvs/runZero-scripts-mVQtFLDO/bin/python3 \ /home/user/scripts/script.py - Start with the location from the
-
Configure a crontab task to run at the cadence you want.
- On the hour:
0 * * * * RUNZERO_EXPORT_TOKEN=XXX SUMO_HTTP_ENDPOINT=XXX /path/to/virtual/env/python3 /path/to/script.py - Daily at midnight:
0 0 * * * RUNZERO_EXPORT_TOKEN=XXX SUMO_HTTP_ENDPOINT=XXX /path/to/virtual/env/python3 /path/to/script.py - Weekly at midnight on Monday:
0 0 * * 1 RUNZERO_EXPORT_TOKEN=XXX SUMO_HTTP_ENDPOINT=XXX /path/to/virtual/env/python3 /path/to/script.py
- On the hour:
Option B: AWS Lambda function
Step 1: Create a Sumo Logic HTTP source
- Sign in to Sumo Logic and go to Manage Data > Collection.
- Click Add Collector, then select Hosted Collector.
- Provide a name, such as
runZero Collector, and click Save.
- Provide a name, such as
- If prompted to add a data source, click OK. Otherwise, find your Collector in the list and click Add Source.
- Select the HTTP Logs and Metrics source.
- Provide a name, such as
runZero Assets, then click Save.
- Provide a name, such as
- Copy the URL Sumo Logic provides; you need it in step 2.
Step 2: Configure the AWS Lambda function to run the provided script
-
In your AWS Console, open the Lambda page.
-
Click Create a function.
-
Give your function a name.
-
Select Python 3.9 as the runtime.
-
Leave everything else at its default. Click Create function to move to the next page.
-
Click Add Trigger to set up a cron job.
-
Select EventBridge to set up a schedule.
-
Use an existing rule or select Create new rule.
- Give it a name and set Rule type to
Schedule expression. - Use one of these expressions, or write your own for the cadence you want:
- Daily:
rate(1 day) - Every 12 hours:
rate(12 hours) - Every 3 hours:
rate(3 hours)
- Daily:
- Click Add to return to the main Lambda configuration page.
- Give it a name and set Rule type to
-
Under Configuration, select Environment variables.
-
Enter these two environment variables:
RUNZERO_EXPORT_TOKEN: your export API token, from an organization detail page in your runZero console. Select the organization you want to export data from, then click Edit organization to view the export API token.SUMO_HTTP_ENDPOINT: the URL you copied in step 1.
-
Click Save to return to the main Lambda configuration page.
-
Click the Code tab and replace the default code with this script.
import json import urllib3 import os # RUNZERO CONF RUNZERO_EXPORT_TOKEN = os.environ["RUNZERO_EXPORT_TOKEN"] HEADERS = {"Authorization": f"Bearer {RUNZERO_EXPORT_TOKEN}"} BASE_URL = "https://console.runZero.com/api/v1.0" # SUMO LOGIC CONF HTTP_ENDPOINT = os.environ["SUMO_HTTP_ENDPOINT"] def lambda_handler(event, context): http = urllib3.PoolManager() url = BASE_URL + "/export/org/assets.json" response = http.request("GET", url, headers=HEADERS) data = response.data assets = json.loads(data) batchsize = 500 if len(assets.json()) > 0 and assets.status_code == 200: for i in range(0, len(assets.json()), batchsize): batch = assets.json()[i : i + batchsize] f = open("upload.txt", "w") f.truncate(0) for a in batch: json.dump(a, f) f.write("\n") f.close() r = open("upload.txt") http.request("POST", HTTP_ENDPOINT, data=r.read()) r.close() else: print(f"No assets found - status code from runZero API: {assets.status_code}") -
Click Deploy to update the code.
-
Click Test to verify the code works.
The function now posts your asset data export to Sumo Logic at the cadence you configured.
Option C: Sumo Logic script source
Step 1: Install a Sumo Logic collector
Follow the Sumo Logic documentation to install a collector.
Step 2: Create a Sumo Logic script source
Sumo Logic also documents script sources. Once your collector is installed, set up the script source:
-
Go to the Collection page in Sumo Logic.
-
Find your collector and click Add > Add Source.
-
Select
Scriptas the source type. -
Enter a
NameandSource Category. -
Select a
Frequency. -
Select Command type
/usr/bin/python. -
Paste this script into the Script field.
#!/usr/bin/python import json import requests import os # RUNZERO CONF RUNZERO_EXPORT_TOKEN = os.environ['RUNZERO_EXPORT_TOKEN'] HEADERS = {'Authorization': 'Bearer ' + RUNZERO_EXPORT_TOKEN} BASE_URL = 'https://console.runZero.com/api/v1.0' def main(): url = BASE_URL + '/export/org/assets.json' assets = requests.get(url, headers=HEADERS) if assets.status_code == 200: for a in assets.json(): print(json.dumps(a)) else: print(f"No assets found - status code from runZero API: {assets.status_code}") if __name__ == '__main__': main() -
Click Save to start the source.
Working with the asset data in Sumo Logic
Once your asset data is in Sumo Logic, you can use it like any other log source. These sample searches are a starting point for scheduled searches and dashboards.
Search distinct assets
_sourceCategory="runzero"
| json field=_raw "id"
| count_distinct(id) as distinct_assets
Search assets with more than 3 services running
_sourceCategory="runzero"
| json field=_raw "addresses_extra"
| json field=_raw "addresses"
| json field=_raw "id"
| concat("https://console.runzero.com/inventory/", id) as runzero_link
| json field=_raw "service_count"
| where service_count > 3
| count addresses, addresses_extra, service_count, runzero_link
Determine counts of different operating systems
_sourceCategory="runzero"
| json field=_raw "os"
| where !isEmpty(os)
| json field=_raw "id"
| count os, id
| count os