You can configure a Nozomi Guardian using the Network Detection and Response user interface to monitor IoT/ICS.
Note
The configuration of Nozomi Guardian is available only to users with an Enterprise or Core license.
From the main menu, click Integration Hub > Add Integrations and then select Nozomi Guardian.
In the Add New Integration page, specify the following details:
Specify a name for the integration.
Specify the description of the integration.
Specify the url of nozomi guardian server.
Specify the api key name for authenticating with NDR.
Specify api key token for authenticating with NDR.
Select the frequency at which Nozomi Server has to be polled to collect the latest asset data.
Select the Ingestion checkbox to enable the collection of alerts and asset data. By default, the ingestion checkbox is enabled that allows NDR to ingest data from Nozomi Guardian passive sensors, enabling visibility and monitoring for IoT and ICS environments. Disabling will stop the data collection.
Click Add and Verify Integration. Based on the data exported to the Nozomi Guardian server, asset and alerts data starts appearing on the UI.
Edit the Nozomi Guardian Server details
Navigate to Your integrations page.
For the configured Nozomi server you want to edit, click
from the Actions column, select Edit.
On the Edit Integrations page, update the details of the server and then click Save.
Delete the configured Nozomi Guardian Server
Navigate to Your integrations page.
For the configured Nozomi server you want to delete, click
from the Actions column, select Delete.