ExtraHop configuration

Prev Next

The ExtraHop platform has highly extensible syslog capabilities. Any metrics, whether custom or built in, can be pushed to the Trellix Helix environment using the AI Trigger API.

This section covers how to use the pre-built ExtraHop Trellix Helix Bundle, which includes DNS, HTTP, DB, and network level metrics. For information on extending the information sent to Trellix Helix, refer to this document found on the ExtraHop forum at:

https://forum.extrahop.com/static/ExtraHopTriggersAPI.pdf.

Installing and configuring the ExtraHop Trellix Helix bundle
  1. To download the ExtraHop Trellix Helix Bundle to your workstation, go to:

    http://tme-downloads.extrahop.com/Deployment_Guides/ExtraHop_Helix_Deployment_ Guide/ExtraHopHelixBundle.json

  2. In the ExtraHop Web UI, click Settings in the left navigation.

  3. Click Bundles, and then click Upload.

  4. Select the ExtraHopHelixBundle.json file, and then click Upload.

  5. Select the Apply 3 included assignments checkbox, and then click Apply to load the bundle.

    The Bundle Import Status dialog appears.

  6. Click OK twice to save and close the window.

Triggers are disabled by default. To enable them:

  1. Click Settings in the upper-left navigation path of the System Settings dialog to return to System Settings.

  2. Click Triggers.

  3. Select the trigger (Helix Syslog [DB], Helix Syslog [HTTP], and Helix Syslog [TCP,DNS]), and then click Enable.

ExtraHop data is now flowing to your Trellix Helix environment. Verify this by searching in Trellix Helix for the eh_event tag.

Configuring the alert syslog destination

Note

In an ECM-powered deployment, perform these steps on each node, not on the ECM.

  1. In the ExtraHop Web UI, click Settings in the left navigation, and then click Administration.

  2. Go to the Network Settings section and click Notifications.

  3. Click Syslog.

  4. Make the following selections on the Syslog Notification Settings page:

    1. Enter the host name or IP of the Trellix Helix Comm Broker in the Destination field.

    2. Select UDP on the Protocol drop-down list.

    3. Enter port 514 in the Port field.

  5. Click Save.