You can configure your Malware Analysis series appliance to export alerts to your NDRConsole appliance. Perform the following steps on NDR Console:
Login to NDR Console CLI.
Create client profile.
For more information on how to create a client profile see, Creating a client profile using the CLI.
Create client group.
For more information on how to create a client group see, Creating a client group using the CLI.
The client group generates a token, use this token to configure alerts export on Malware Analysis.
To enable the export of alerts from your Malware Analysis to your NDR Console:
Log in to the Malware Analysis Series CLI.
Enter privileged mode:
hostname (config) # enableEnter configuration mode:
hostname # configure terminalhostname # fenotify http enablehostname # fenotify http default format json-normalhostname # fenotify http service service_name auth enablehostname # fenotify http service service_name auth header scheme IAhostname # fenotify http service service_name auth header value "token generated by client-group on NDR consolehostname # fenotify http service service_name ssl enablehostname # fenotify http service service_name prefer message delivery per-eventhostname # fenotify http service service_name server-url https://NDR_console_IP/services/collector/alert