The Evidence Collector module on the Network Security appliance is a log aggregator that collects logs generated by the appliance. The network event logs allow you to identify activity in your network before the Network Security-specific alert is triggered on the appliance.
When you enable the integration between Helix Enterprise and the Network Security appliance, the Evidence Collector module on the Network Security appliance sends network event logs to Helix Enterprise for further analysis.
The Communications Broker Sender (Comm Broker) can send and receive third-party syslog and JSON formatted logs to Helix Enterprise for analysis. Comm Broker functionality requires that Evidence Collector be enabled. When you enable Helix Enterprise mode on a Network Security appliance, the HelixConnect Client is also enabled. This allows the following to happen:
Evidence Collector is automatically configured with the Helix Enterprise URL.
The bootstrap certificate that Evidence Collector and Comm Broker require is automatically downloaded and deployed.
Perform the integration steps in the following order:
Enable Helix Enterprise mode.
Enable Evidence Collector.
Start Comm Broker.
If you do not enable Helix Enterprise mode first, you must manually download and deploy the bootstrap certificate. See the Network Security User Guide for information about enabling Evidence Collector, starting Comm Broker, and filtering out types of events you do not want to send to Helix Enterprise. The Network Security User Guide also describes how Evidence Collector and Comm Broker interact.