The ExtraHop platform has highly extensible syslog capabilities. Any metrics, whether custom or built in, can be pushed to the Helix Enterprise environment using the AI Trigger API.
This section covers how to use the pre-built ExtraHop Helix Enterprise Bundle, which includes DNS, HTTP, DB, and network level metrics. For information on extending the information sent to Helix Enterprise, refer to this document found on the ExtraHop forum at:
https://forum.extrahop.com/static/ExtraHopTriggersAPI.pdf.
To download the ExtraHop Helix Enterprise Bundle to your workstation, go to:
In the ExtraHop Web UI, click Settings in the left navigation.
Click Bundles, and then click Upload.
Select the
ExtraHopHelixBundle.jsonfile, and then click Upload.Select the Apply 3 included assignments checkbox, and then click Apply to load the bundle.
The Bundle Import Status dialog appears.
Click OK twice to save and close the window.
Triggers are disabled by default. To enable them:
Click Settings in the upper-left navigation path of the System Settings dialog to return to System Settings.
Click Triggers.
Select the trigger (Helix Syslog [DB], Helix Syslog [HTTP], and Helix Syslog [TCP,DNS]), and then click Enable.
ExtraHop data is now flowing to your Helix Enterprise environment. Verify this by searching in Helix Enterprise for the eh_event tag.
Note
In an ECM-powered deployment, perform these steps on each node, not on the ECM.
In the ExtraHop Web UI, click Settings in the left navigation, and then click Administration.
Go to the Network Settings section and click Notifications.
Click Syslog.
Make the following selections on the Syslog Notification Settings page:
Enter the host name or IP of the Helix Enterprise Comm Broker in the Destination field.
Select UDP on the Protocol drop-down list.
Enter port 514 in the Port field.
Click Save.