lhs-panel Click here to expand

Configuration steps for Syslog forwarding from Trend Micro - Deep Security devices to EventLog Analyzer

  1. To forward system events to ELA server:
    • Go to Administration → System Settings → Event Forwarding.
    • Select Forward System Events to a remote computer (via Syslog) in the SIEM section.
    • Specify the following information and then click Save:
      1. Hostname <EventLog Analyzer IP>
      2. UDP port <default 514>
      3. Syslog Format <CEF>
      4. Syslog Facility
  2. To forward security events to ELA server:
    • Go to Policies.
    • Double-click the policy you want to use for computers to forward security events via the Deep Security Manager.
    • Go to Settings > SIEM and select Forward Events To > Relay via the Manager for each applicable protection module.
    • Specify the following information that is required for relaying events via the Deep Security Manager and then click Save:
      1. Hostname <EventLog Analyzer IP>
      2. UDP port <default 514>
      3. Syslog Format <CEF>
      4. Syslog Facility
Malwarebytes Reports

Once the threat source is added, EventLog Analyzer will start parsing the fields in the logs. This log data can now be viewed in the form of reports.

  1. In the EventLog Analyzer console, navigate to Settings > Log Source Configurations > Applications > Security Applications > Add Security Applications
  2. Select Add-on type as Trend Micro
  3. Expand the list by clicking the "+" icon to add a new device.
  4. Choose from the drop-down menu to add Configured devices, Workgroup devices, domain devices, etc.
  5. To add new devices manually, click on Configure Manually and enter Log Source >Select and click on Add.
  6. FireEye Threat Solutions

Copyright © 2020, ZOHO Corp. All Rights Reserved.

Get download link