Forcepoint NGFW (syslog)
Configure Forcepoint NGFW Security Management Center (SMC) for syslog forwarding to Radiant Security.
In this guide, you'll set up a trusted relationship between Forcepoint NGFW and Radiant. Once complete, Radiant will collect and analyze alerts and events from your Forcepoint NGFW environment.
Log entries are traffic-based events that are logged according to policy rules. An audit log entry is a special type of log entry that is not traffic-based, but instead provides a record of SMC administrative actions and some internal events like element updates and scheduled task executions.
Prerequisites
Add the data connector in Radiant Security
Log in to Radiant Security.
From the navigation menu, click Settings > Data Connectors and click + Add Connector.
Search for and select the Forcepoint NGFW (syslog) option from the list and then click Data Feeds.
Under Select your data feeds, select Forcepoint NGFW and click Credentials.
Under Credential Name, give the credential an identifiable name (e.g.
Forcepoint NGFW Credentials
).Under Required Credentials, in the Connector tag field enter a value. This value will act as the salt to randomize the unique Token you’ll download in the next step.
Click Add Connector.
Copy and save the connector Token value using the clipboard option or download the Token file. You will need this token to complete the configuration.
Click Done to save your changes.
Configure a Radiant Agent for Log Collection
Refer to the Install the Radiant Security Agent guide to set up a local agent to collect the logs.
Configure log forwarding in Forcepoint SMC
Sign in to your Forcepoint SMC.
Click Home.
Click Others > Log Server.
Right-click the log server that you want to forward logs from, and then select Properties.
Click the Log Forwarding tab.
Click Add and enter the following:
Service:
UDP
Port:
514
Format: select JSON
Data Type: select All Log Data
Double-click the Target Host cell to open the Select Host dialog box.
Click the Settings icon > New > Host.
b. Enter
Radiant-Security-Syslog
c. Select the IP field and enter
<Radiant Agent's local IP>
Click OK.
Select the new host and click Select.
On the Log Server TLS Certificate box, select No client Authentication.
Click OK.
Last updated