ERPM configuration

Prev Next

To configure ERPM to send logs to the Comm Broker Sender:

  1. From the ERPM console, select Settings > Extension Components > Configure Event Sinks…

    ERPM_console.png
  2. Click New:

    ERPM_event_sink_defs.png
  3. Enter a name for your new Event Sink:

    ERPM_event_sink_conf.png
  4. Click the Add Event button in the Event Sink Configuration window.

  5. Select the events you want ERPM to forward to the Comm Broker and click OK:

    ERPM_select_events.png
  6. In the Event Sink Configuration window, select Syslog from the Event sync output type dropdown menu:

    ERPM_event_sink_output.png
  7. Click the Settings… button.

    In the Event Output Syslog Settings window, enter the Comm Broker's IP Address and the port. Use the default port 514 unless you previously configured a different port.

    ERPM_event_sink_syslog.png
  8. Click the Output Format… button in the Event Sink Configuration window.

  9. Change the Output Data Format to "JSON for FireEye Helix".

    ERPM_output_format.png
  10. Click OK to save the format settings.

  11. Click OK in the Event Sink Configuration window to save your configuration.

  12. For validation purposes, you can re-enter the Event Sink configuration at any time and test the output by clicking the Test Output button:

    ERPM_test_output.png