Step 7: Install Log Server and (optionally) Sync Service

Before you begin

Log Server enables most reporting components, and must reside on a Windows machine.

If you have purchased the Forcepoint Web Security Hybrid Module, Sync Service is responsible for sending policy information to the hybrid service, and passing reporting information from the hybrid service to Log Server. In most cases, it is best to install Sync Service on the same machine as Log Server.

Before installing Log Server on a supported Windows server, make sure you have prepared the machine (including downloading the installer file) as described in Prepare your Windows servers.

Important: During the installation process, if you encounter the error “Installation failed with error code 3004”, refer to Potential issue when installing v8.5.4 and v8.5.5 for instructions.

To install Log Server and (optionally) Sync Service:

Steps

  1. Log on to the machine.

    If you plan to have Log Server connect to the Log Database using a trusted account, log on to the machine using that account.

  2. Use the Run as administrator option to launch the Forcepoint85xSetup.exe installer. After a few seconds, a progress dialog box appears, as files are extracted.
  3. On the Welcome screen, click Start.
  4. On the Subscription Agreement screen, select I accept this agreement, then click Next.
  5. On the Installation Type screen, select Custom and then click Next.
  6. On the Summary screen, click Next.
  7. On the Custom Installation screen, click the Install link next to Forcepoint Web Security or URL Filtering.
  8. On the Welcome screen for the Web Protection Solutions setup program, click Next.
  9. Accept the subscription agreement, then click Next.
  10. If the machine has multiple NICs, on the Multiple Network Interfaces screen, select the IP address of the NIC that software components should use for communication, and then click Next.
  11. Select the Custom installation type, then click Next.
  12. On the Select Components screen:
    1. Select Log Server.
    2. If you have purchased the Forcepoint Web Security Hybrid Module, optionally select Sync Service.
    3. Click Next.
  13. On the Policy Server Connection screen, enter the IP address of the Policy Server for this Log Server, and the Policy Server communication port (55806, by default), and then click Next.
  14. On the Policy Broker Connection screen, enter the IP address of the primary (or standalone) Policy Broker, and the Policy Broker communication port (55880, by default), and then click Next.
  15. If the Log Server server machine does not include a supported version of the Microsoft SQL Server Native Client and related tools, you are prompted to install the required components.

    Depending on your current configuration, the Native Client installer may run silently in the background, or prompt you for input.

    • When the Native Client installer runs in the background, you will know the process is complete when the Forcepoint installer continues to the next screen. This may take a few minutes.
    • When the Native Client installer runs in the foreground, follow the prompts to complete the installation. Note that if you are prompted to reboot the machine, do not reboot at this point. Instead, complete the Forcepoint software installation first, then reboot.
  16. On the Database Information screen, enter the hostname or IP address of the machine on which a supported database engine is running. If you are using SQL Server clustering, enter the virtual IP address of the cluster. Also indicate how to connect to the database engine:
    • Select Trusted connection to use a Windows account to connect to the database. Enter the user name and password of a trusted account with local administrator privileges on the database machine. (As noted in step 1, this should be the same account that you used to perform the installation.)

      If you use a trusted account, an additional configuration step is required after installation to ensure that reporting data can be displayed in the Forcepoint Security Manager. See the Reporting FAQ.

    • Select SQL Server authentication to use a SQL Server account to connect to the database. Enter the user name and password for a SQL Server account that has administrative access to the database. The SQL Server password cannot be blank, or begin or end with a hyphen (-).
  17. On the Log Database Location screen, either accept the default location for the Log Database files or select a different location, then click Next.
    • The default location is C:\Program Files\Microsoft SQL Server on the SQL Server machine.
    • If you specify a custom directory, that directory must already exist. The installer cannot create a new directory on the SQL Server machine.
  18. On the Optimize Log Database Size screen, select either or both of the following options, and then click Next.
    • (Recommended) Log Web page visits: Enable this option to log fewer records that combine hits and bandwidth data for a requested website, rather than a logging a separate record for each file included in the request. This results in fewer records and therefore smaller databases, allowing for potentially faster report generation and longer storage capacities.
    • Consolidate requests: Enable this option to combine Internet requests that share the same value for all of the following elements, within a certain interval of time (1 minute, by default):
      • Domain name (for example: www.forcepoint.com)
      • Category
      • Keyword
      • Action (for example: Category Blocked)
      • User/device
  19. On the Installation Directory screen, accept the default installation path, or click or select Choose to specify another path, and then click Next.
    • The installation path must be absolute (not relative). The default installation path is C:\Program Files\Websense\Web Security\.
    • The installer creates this directory if it does not exist.
      Important: The full installation path must use only ASCII characters. Do not use extended ASCII or double-byte characters.
  20. On the Pre-Installation Summary screen, verify the installation path, components selected, and other information shown, then click Next.

    A progress screen is displayed while components are installed.

  21. When the installation process finishes, the Installation Complete screen is displayed. Click Next to exit the installer.
  22. Restart the following services on the management server machine:
    • Websense TRITON - Web Security
    • Websense Web Reporting Tools

    This step is required to ensure that reporting tools operate properly, and that any scheduled reports that you create are saved properly.

Next steps

If you have purchased Forcepoint DLP or the Forcepoint Web Security DLP Module, continue with Step 8: (Forcepoint Web Security DLP Module only) Install Linking Service on the management server.

Otherwise, go to Step 9: Install additional web protection components.