Logs Data Platform - Responsibility model

Bases de conhecimento

Logs Data Platform - Responsibility model


Icons/System/eye-open Created with Sketch. 234 visualizações 01.07.2024 Cloud / Logs Data Platform

The Logs Data Platform is an interface for collecting, indexing and analyzing logs. Wherever your logs come from, you can use the platform to choose different entry points depending on the protocol, security level and format. You can analyze and use data with a variety of different APIs and web interfaces.

The RACI below details shared responsibilities between OVHcloud and the customer for Logs Data Platform services. This shared model can help relieve the customer’s operational burden.

RACI definition

Roles
R: Is in charge of carrying out the process
A: Accountable for the successful completion of the process
C: Is consulted during the process
I: Is informed of the results of the process

For your information, a Log forwarder agent is considered as a tool (full software, script or library) that is required to forward logs to LDP.

1. Before subscription

1.1. Specify service as needed

ActivityCustomerOVHcloud
Learn about the capabilities and limitations of the service detailed in the OVHcloud documentation or commercial pageRAI
Choose service locationRAI
Choose service offer: standard or enterpriseRAI

2. Service availability

2.1. Install service

ActivityCustomerOVHcloud
Install, configure, and deliver functional components of the serviceIRA
Setup audit trails as stream on dedicated clusters (enterprise)IRA
Produce, route, deliver and maintain physical machines, virtual machines and hosting buildingsRA

2.2. Reversibility model

ActivityCustomerOVHcloud
Offer standard solutions and protocols for importing and exporting data using API for logs and dashboardsIRA
Decide to use ldp-archive-mirror for data export and local analysisRA

2.3. Customer Information System setup

ActivityCustomerOVHcloud
Choose service options following business needsRAI
Order and configure streams on Logs Data PlatformRAI
Define retention policy following legal requirements (for hot storage and cold storage)RA
Install and configure the log forwarder agent and adapt its buffer following needs and purpose of the processingRA
Manage cold storage archives with encryption keys provided by the CustomerAIR

3. Service usage

3.1. Operations

3.1.1. Daily operations
ActivityCustomerOVHcloud
Manage network accessibility of the PlatformRA
Decide to add/delete resources to the existing serviceRA
Manage confidentiality, integrity of data hosted on the serviceRA
Manage risks of the log forwarder agentRA
Manage backups on the service (logs and dashboards)RA
Manage backups on service management infrastructureRA
Adapt log forwarder agent configuration following IS evolutionRA
Decide to observe audit trails available in audit stream (enterprise)RA
3.1.2. Access management
ActivityCustomerOVHcloud
Manage OVHcloud teams’ physical access to infrastructuresRA
Manage OVHcloud teams’ logical access to infrastructuresIRA
Manage access to the OVHcloud Control Panel (Manager, network acls, MFA, API, token, ..)RAI
Decide to renew password at least on a quarterly basisRAI
Manage access to management interfaces specific to Logs Data Platform (streams, dashboards,...)RAI
Manage security risks of the log forwarding configuration (transport, protocols, ...)RA
Manage network configuration of the subscribed data gathering tool(s)RAI
3.1.3. Monitoring
ActivityCustomerOVHcloud
Monitor the proper functioning of log forwarder agentRA
Monitor physical (e.g. devices) and virtual resource performanceRA
Manage hardware sizing on the serviceRA
Monitor service performanceRA
Keep logs of the Control Plane that manages Logs Data PlatformRA
3.1.4. Storage
ActivityCustomerOVHcloud
Keep the content sent to Logs Data Platform adequate, relevant and appropriateRA
Manage data immutabilityIRA
Perform storage device maintenanceRA
Create, modify, control, restore, delete internal backup jobs on management infrastructureIRA
3.1.5. Connectivity
ActivityCustomerOVHcloud
Operate network management systems (architecture, implementation, software and hardware maintenance for deployed public and private networks)RA
Manage IP addressing plan on hosted data gathering toolsRAI
Manage IP addressing plan on dedicated clusters (enterprise)RAI
3.1.6. Management
ActivityCustomerOVHcloud
Provide inventory of the service usedIRA
Manage service register following legal requirementsRA
Manage the physical security of equipment and infrastructures hosted at OVHcloudIRA
Maintain Standard Logs Data Platform services and their extensionsIRA
Maintain Enterprise Logs Data Platform services and their extensionsCIRA
Ensure that external tools remain compatible with the Logs Data Platform major updatesRA
Handle the major upgrade of the subscribed data gathering tool(s) regarding the external tools compatibilityRA
3.1.7. Business continuity
ActivityCustomerOVHcloud
Manage automatic management systems for the infrastructure providedIRA
Maintain a business continuity and disaster recovery plan for hosted services (logs, dashboards, ...)RAI

3.2. Event management

3.2.1. Incidents
ActivityCustomerOVHcloud
Intervene with Logs Data Platform managed elementsIRA
Manage incidents and their consequences on log forwarder agent componentRA
Notify incidents on the LDP service with ticketing systemRAI
3.2.2. Changes
ActivityCustomerOVHcloud
Deploy patches, update software and information systems hosted in Logs Data Platform (standard)IRA
Deploy patches, update software and information systems hosted in Logs Data Platform (enterprise)CIRA
Deploy patches, update and configure the log forwarder agent using Logs Data PlatformRA
Perform preventive interventions on managed elements of Logs Data PlatformIRA

4. Reverting

4.1. Reversibility model

ActivityCustomerOVHcloud
Schedule reversibility operationsRA
Choose fallback infrastructuresRA

4.2. Data recovery

ActivityCustomerOVHcloud
Manage reversibility operations : manual extract, using API, ldp-archive-mirrorRA
Migrate/transfer dataRA

5. End of service

5.1. Configuration destruction

ActivityCustomerOVHcloud
Delete Logs Data Platform objects configuration (streams, dashboards, index, ...)RAI
Decommission log forwarder agentRA
Decommission of the client service following contract terminationIRA

5.2. Data destruction

ActivityCustomerOVHcloud
Destroy indexed activityIRA
Destroy long term archivesIRA
Destroy configuration dataIRA

Go further

Artigos relacionados