# Integrating NetFlow Analyzer with Log360 ManageEngine Log360 is an Security Information and Event Management (SIEM) solution that helps you enhance your network security and comply with government-mandated and organization-level regulations, by collecting and analyzing your network logs. By integrating NetFlow Analyzer with Log360, users can forward their critical logs to Log360, and analyze them to gain deeper insights into user behavior, and identify anomalies and potential threats. > **NOTE**: Log360 version **13000 and above** is compatible with Netflow Analyzer version **\128707 and later.** - [Configuring Log360 details in NetFlow Analyzer](https://www.manageengine.com/products/netflow/help/integrate-log360.html#con) - [How does the NetFlow Analyzer - Log360 integration help network admins?](https://www.manageengine.com/products/netflow/help/integrate-log360.html#how) 1. [Staying compliant with various regulations and frameworks](https://www.manageengine.com/products/netflow/help/integrate-log360.html#comp) 2. [Enhanced security](https://www.manageengine.com/products/netflow/help/integrate-log360.html#sec) - [What are the various reports that network admins can generate using this integration?](https://www.manageengine.com/products/netflow/help/integrate-log360.html#what) 1. [Product Activity Reports](https://www.manageengine.com/products/netflow/help/integrate-log360.html#prod) 2. [Debug Reports](https://www.manageengine.com/products/netflow/help/integrate-log360.html#deb) 3. [Web Access Reports](https://www.manageengine.com/products/netflow/help/integrate-log360.html#web) 4. [User Audit Reports](https://www.manageengine.com/products/netflow/help/integrate-log360.html#user) - [Configuring Notification Templates](https://www.manageengine.com/products/netflow/help/integrate-log360.html#temp) ## Configuring Log360 details in NetFlow Analyzer To integrate NetFlow Analyzer with Log360, kindly follow the below steps: - **Go to Settings -> General Settings -> Third Party Integrations.** - Now, click on the **"Configure"** button found at the bottom-right corner of the Log360 Section. ![Integrating NetFlow Analyzer with Log360](https://cdn.manageengine.com/sites/meweb/images/netflow/help/log360-1.png) - Now, fill in the following details: - Server IP/DNS Name: Enter the IP address or the DNS name of the Log360 -installed server, along with the port and the protocol. - Username: Enter the user name of the Log360 user with the admin privilege. - Password: Enter the password of the Log360 user with the admin privilege. - Select Log File: Select the logs to be forwarded to Log360, from the Select Log File drop down box. - Access logs: Logs that contain requests made to a web server, capturing information like the IP address, timestamp, requested resources, and outcomes of each request - Debug logs: Logs that are generated by NetFlow Analyzer during its operation, containing information used for diagnosing and troubleshooting issues. - Audit Modules: Select the required audit modules to forward their logs to Log360. ![Integrating NetFlow Analyzer with Log360](https://cdn.manageengine.com/sites/meweb/images/netflow/help/log360-2.png) ## How does the NetFlow Analyzer - Log360 integration help network admins? By integrating NetFlow Analyzer with Log360, network admins can leverage the following functionalities. ### Staying compliant with various regulations and frameworks Centralized log management and analysis is a crucial mandate for most of the compliance regulations such as HIPAA, PCI-DSS, and so on. By centralizing and analyzing NetFlow Analyzer's debug and access logs, network admins can comply with the above said regulations. ### Enhanced security Since the debug and access logs are forwarded toLog360 for analysis, network admins can know who accessed what in NetFlow Analyzer. Furthermore, network admins can also correlate access logs with debug logs, helping them troubleshoot network issues, fortify network security against potential unauthorized activities, and conducting extensive root cause analysis. ## What are the various reports that network admins can generate using this integration Once NetFlow Analyzer is integrated with Log360, users' debug and access logs will automatically be forwarded to the Log360 Server via Syslogs. The logs can then be visualized in the form of the following reports: > **NOTE:** Log360 uses both UDP and TCP ports to receive syslogs. The ports used by default are **UDP 514, UDP 513, TCP 514, and TCP 513.** Users can also change these ports. ### Product Activity Report The product activity report category contains the All Activity report, which generates reports for all the logs forwarded from NetFlow Analyzer server. ### Debug Reports The following debug reports can be generated from the serverout & stdout(debug) logs of the NetFlow Analyzer. - Instance Created: Obtain a detailed report that outlines the product's startup instance with the necessary configurations, within the chosen time period. - Services Created: Generate a comprehensive report listing the services that were created during NetFlow Analyzer startup within the specified time frame. For example, services like StartupControllerService, PatchUpdaterService, CacheService, and others, were initiated during this process. - Server Started: Obtain a comprehensive report detailing when the NetFlow Analyzer server was started within the selected time period. - Successful Logins: Access a detailed report showcasing successful NetFlow Analyzer logins, including the respective login times, all within the chosen time frame. - Failed Logins: Receive a comprehensive report detailing unsuccessful NetFlow Analyzer login attempts, complete with the corresponding login times that occurred within the selected time interval. ### Web Access Reports Web access reports generated from NetFlow Analyzer's access logs encompasses a range of HTTP status codes, such as Status Success, Internal Server Error, Gateway Timeout, etc., each reflecting distinct outcomes of client-server interactions. ### User Audit Reports The User Audit reports offers comprehensive visibility into user activities and administrative actions within Netflow Analyzer. It tracks key events such as user authentication (logins and logouts), user account creation and deletion, and changes to roles and permissions. It also records critical system updates, including device additions and configuration changes. This enables administrators to effectively monitor access, ensure compliance, and identify any unauthorized activities. This is how users can successfully integrate NetFlow Analyzer with Log360, and enhance their network security by analyzing their logs. > **Note**: Support for forwarding alarms to Log360 is available from NetFlow Analyzer version **\129102**. ## Configuring Notification Templates Notification templates in NetFlow Analyzer allows you to customize alert delivery for triggered alarms. They can also be associated with alarm correlation rules to generate notifications when predefined event patterns are detected. - Go to **Settings -> Notifications -> Notification templates** - Click on **Add** navigate to **SIEM** and select **Log360** to add a notification template. ![Log360-OpManager](https://cdn.manageengine.com/sites/meweb/images/network-monitoring/images/log360-2.png) - Enter the required parameters, including **Template Name, Format, Severity, Facility, Description,** and **relevant variables**. - If you enable the **Structured Message** option, make sure to provide the required key-value pair inputs. - To verify the template created, click on **Test Action**. - Click **Save**. > **Note:** Please refer to the [dynamic variables](https://www.manageengine.com/network-monitoring/help/workflow-variables.html?nfa-help-log360) page for more information on the replaceable tags used in alarm details.