Exporting NX/ NDR Sensor alerts to NDR console

Prev Next

You can configure your Network Security/NDR Sensor to export alerts to your NDR appliance.

Perform the following steps on NDR:

  1. Login to NDR CLI.

  2. Create client profile.

    For more information on how to create a client profile see, Creating a client profile using the CLI.

  3. Create client group.

    For more information on how to create a client profile see, Creating a client group using the CLI.

  4. The client group generates a token, use this token to configure alerts export on NX / NDR Sensor.

To enable the export of alerts from your NX Network Security / NDR Sensor to your NDR:

  1. Log in to the Network Security/NDR Sensor Series CLI.

  2. Enter privileged mode:

    hostname (config) # enable

  3. Enter configuration mode:

    hostname # configure terminal

  4. hostname # fenotify http enable

  5. hostname # fenotify http default format json-normal

  6. hostname # fenotify http service service_name auth enable

  7. hostname # fenotify http service service_name auth header scheme IA

  8. hostname # fenotify http service service_name auth header value "token generated by client-group on NDR

  9. hostname # fenotify http service service_name ssl enable

  10. hostname # fenotify http service service_name prefer message delivery per-event

  11. hostname # fenotify http service service_name server-url

    https://NDR_console_IP/services/collector/alert