Forwarding CEF logs to Helix Enterprise and SIEM solutions

Prev Next

You can forward CEF logs from on-premises or virtual Endpoint Security (HX) servers to Helix Enterprise using a Cloud Collector or Communications Broker (Comm Broker). This allows you to view, but not manage, on-premises and virtual Endpoint Security (HX) log data in Helix Enterprise.

In addition, the Endpoint Security (HX) server can be integrated with a variety of Security Information and Event Management (SIEM) solutions to exchange requests and information automatically, reducing time spent navigating between product interfaces. For example, integrating these products helps you perform the following actions.

  • You can send common event format (CEF) logs from the Endpoint Security (HX) server to one or more remote SIEMs. This includes hits (referred to as alerts), containment state events, and triage status. For more information, see Configuring CEF logging for endpoint events. For information on the data that is logged, see "CEF Logs and Output" in the Endpoint Security (HX) Server User Guide.

  • You can perform two-way communications with SIEM solutions, such as acquiring triage collections.

  • With SIEM solutions, you can execute analyst actions initiated in a URL context. Specifically, you can:

    • Listen for traffic from SIEMs that initiate analyst actions via URL requests.

    • Parse the arguments in these requests.

    • Format and execute commands.

The integration between the Endpoint Security (HX) server and most SIEM solutions can be accomplished using an external integration connector and an API Analyst user account. See "Roles for Local User Accounts" in the System Security Guide. For an example of setting up an integration connector with a SIEM solution, see SIEM example: Setting up an Endpoint Security integration connector with ArcSight.

Note

An integration connector can only be used for communications from the SIEM solution to the Endpoint Security (HX) server, not from the Endpoint Security (HX) server to the SIEM solution.

Similar integration can be accomplished using the Endpoint Security (HX) API.