Forcepoint NGFW
Connect Forcepoint NGFW to Radiant Security to forward firewall logs for AI triage.
Forcepoint NGFW is a next-generation firewall that protects networks against intrusions, malware, evasions, and unauthorized application use. Connecting Forcepoint NGFW forwards firewall logs and SMC audit log entries to Radiant Security through the Radiant Agent. Radiant uses this telemetry to enrich alerts with network context, giving analysts visibility into traffic activity and administrative actions during triage.
Prerequisites
Add the data connector in Radiant Security
Log in to Radiant Security.
From the navigation menu, click Settings > Data Connectors, then click + Add Connector.
Search for and select Radiant Agent, then click Data Feeds.
Under Select your data feeds, select Forcepoint NGFW, then click Credentials.
Under Credential Name, enter an identifiable name for the Radiant Agent integration (e.g.,
Radiant Agent integration). To reuse an existing Radiant Agent credential, select it from the drop-down menu.Click Add Connector.
Configure Forcepoint SMC to forward logs
Before starting, confirm the IP address of the Radiant Agent and the port configured to receive Forcepoint NGFW data. If you do not know the port, contact your Customer Success representative.
One Log Server element is automatically created during SMC installation. Repeat these steps for every Log Server you want to forward from.
Sign in to Forcepoint SMC.
Click Home, then click Others > Log Server.
Right-click the log server you want to forward logs from, then select Properties.
Click the Log Forwarding tab.
Click Add and enter the following values:
Service:
UDPPort: the port configured on the Radiant Agent to receive Forcepoint NGFW data
Format:
JSONData Type:
All Log Data
Double-click the Target Host cell to open the Select Host dialog box.
Click the Settings icon, then select New > Host.
In the Name field, enter
Radiant-Security-Syslog.In the IP field, enter the IP address of the Radiant Agent.
Click OK, then select the new host and click Select.
In the Log Server TLS Certificate dialog, select No client Authentication.
Click OK to save the log forwarding rule.
Verify ingestion
After Forcepoint NGFW begins forwarding, confirm alerts and events are reaching Radiant.
In Radiant, navigate to Log Management.
Filter by
rs_connectorType:"forcepoint_ngfw".Confirm recent alerts and events appear.
Allow several minutes for alerts and events to be parsed, indexed, and available for search.
Last updated
Was this helpful?