FireEye HX
Connect FireEye HX (now Trellix Endpoint Security HX) to Radiant Security to forward alerts and host data through Cribl Stream for AI triage.
FireEye HX (now Trellix Endpoint Security HX) is an endpoint detection and response product that detects intrusions, malware, lateral movement, and credential theft on managed hosts. Connecting through Cribl Stream forwards FireEye HX alerts and host data to Radiant Security over a webhook. Radiant uses these alerts for AI triage, classifying and enriching each before it reaches an analyst.
Prerequisites
Add the data connector in Radiant Security
Sign in to Radiant Security.
From the navigation menu, select Settings > Data Connectors, then click + Add Connector.
Search for and select FireEye HX, then click Data Feeds.
Under Select your data feeds, select FireEye HX, then click Credentials.
Under Credential Name, enter an identifiable name for this credential.
Under Required Credentials, enter a Webhook Auth Token. Use a long, randomly generated value, and rotate it periodically.
Click Add Connector.
Open the newly created connector. Under Vendor Configuration, copy and save the Webhook URL. You will need it in the Create a webhook destination in Cribl Stream section.
Create a webhook destination in Cribl Stream
Sign in to Cribl.
Navigate to Stream.
Use the top navigation to open Manage > Groups.
From the list of groups, click the group that has the FireEye HX data as a Source.
Use the top navigation to open Data > Destinations.
Filter the Destinations and click Webhook.
Click Add Destination.
Under General Settings, configure the following:
Output ID:
rs-cribl-fireeye-hxURL: the Webhook URL copied from Radiant Security.

Click Authentication and configure the following:
Authentication type:
Auth TokenToken: the Webhook Auth Token configured in Radiant Security.

Click Save.
Use the top navigation to open Routing > Data Routes.
Click Add Route.
Configure the route to send FireEye HX data (Hosts and Alerts) to a Pipeline that outputs to the
rs-cribl-fireeye-hxDestination. For details on configuring Routes and Pipelines, see the Cribl Stream Routing documentation.
Verify ingestion
After Cribl Stream begins forwarding, confirm events are reaching Radiant.
In Radiant, navigate to Log Management.
Filter by
rs_connectorType:"cribl_webhook_hx".Confirm recent events appear.
Allow several minutes for events to be parsed, indexed, and available for search.
Last updated
Was this helpful?