Data sources for Helix Enterprise

Prev Next

Helix Enterprise effectiveness depends on the data sources available for analysis. The log data that you send determines Helix Enterprise's detection capability (such as use cases available). From the perspective of effective use of Helix Enterprise, there are varying types of log data.

The Helix Enterprise Communications Broker Sender has specifications for log data accepted and log data from specific sources that are currently supported. Helix Enterprise generally accepts logs from log aggregation systems and other sources such as network devices, security systems, and operating systems.

The following table shows information about the data sources.

Data Source

What is Collected

How Logs are Used in Helix Enterprise

Connection Logging

Logs connection information and duration between two hosts.

Identify APT activity from known bad IP addresses. Track movement of malicious hosts around the network.

DNS Logging

All DNS requests are logged.

Identify malware or APT activity.

Files Logging

Names/hashes of files are logged.

Identify malicious files used by attackers, or invalid versions of files.

SMTP Logging

Logs all SMTP headers.

Identify internal spam abuse or augment SMTP logs.

HTTP Logging

Similar to proxy/Web server logs, but does not include user names.

See attacks on internal Web servers or malware leaving an egress.

SSL Certificate Logging

Logs certificate information such as CA.

Identify known bad certificates or invalid certificate chains.

Tunnel Logging

Identify and report on tunneled traffic, such as teredo, IPv6 over IPv4, or GRE.

Identify possible data exfiltration or command and control.

Software Logging

Detect versions of applications in use. For example, old Java versions, Web browser versions, and so on.

Identify abnormal or vulnerable software in use.