Syslog Forwarding from FireEye

Welcome Forums Integrations Syslog Forwarding from FireEye

Viewing 1 post (of 1 total)
  • Author
    Posts
  • #1642
    Mike RiforgiateMike Riforgiate
    Keymaster

    Complete the following steps to send data to WitFoo using CEF over SYSLOG:
    ■ Log into the FireEye appliance with an administrator account
    ■ Click Settings
    ■ Click Notifications
    ■ Click rsyslog
    ■ Check the “Event type” check box
    ■ Next to the “Add Rsyslog Server” button, type “CEF”.
    ■ Then click the “Add Rsyslog Server” button.
    ■ Enter the IP address of the WitFoo Precinct server in the “IP Address” field.
    Make sure rsyslog settings are:
    ■ Format: CEF
    ■ Delivery: Per event
    ■ Send as: Alert

    Now you can test the sending and receiving of notifications on the same FireEye Notifications page by clicking the “Test-Fire” button at the bottom. Flip back over to the WitFoo “Search” interface and search for the IP address of the FireEye Managment Console.

Viewing 1 post (of 1 total)
  • You must be logged in to reply to this topic.