Use these instructions to configure a Network Security appliance to send notifications to Helix Enterprise.
The Network Security appliance must have an established connection to the Internet.
You must have admin access to the Network Security appliance.
Use the Rsyslog Settings area on the Network Security Settings page to set up the default configuration for rsyslog notifications.
On the Network Security Web UI, select the Settings tab.
Select Notifications on the side bar.
Click the rsyslog column heading to display the Rsyslog Settings area in the Settings column.
Select CEF (Common Event Format) from the Default format drop-down menu.
Click Apply Settings.
Note
: If you do not click Apply Settings, your changes will be lost.
In the Rsyslog Server Listing area, enter the name or IP address of the Communications Broker or syslog-enabled Cloud Collector in the Name box and click Add Rsyslog Server.
To apply the rsyslog server listing changes, click Update.
In addition to Network Security alert notifications, you can send network event logs to Helix Enterprise from a Trellix NX 2500 appliance.
To configure the Network Security appliance using the CLI:
Configure an AWS endpoint:
> enable# configure terminal# tapsender VPC <hostname>Enable the
tapsenderprocess:# tapsender enable