You can configure your Network Security/NDR Sensor to export alerts to your NDR appliance.
Perform the following steps on NDR:
Login to NDR CLI.
Create client profile.
For more information on how to create a client profile see, Creating a client profile using the CLI.
Create client group.
For more information on how to create a client profile see, Creating a client group using the CLI.
The client group generates a token, use this token to configure alerts export on NX / NDR Sensor.
To enable the export of alerts from your NX Network Security / NDR Sensor to your NDR:
Log in to the Network Security/NDR Sensor Series CLI.
Enter privileged mode:
hostname (config) # enableEnter configuration mode:
hostname # configure terminalhostname # fenotify http enablehostname # fenotify http default format json-normalhostname # fenotify http service service_name auth enablehostname # fenotify http service service_name auth header scheme IAhostname # fenotify http service service_name auth header value "token generated by client-group on NDRhostname # fenotify http service service_name ssl enablehostname # fenotify http service service_name prefer message delivery per-eventhostname # fenotify http service service_name server-url