Websense configuration

Prev Next

You can configure Websense software to send log data from the Filtering Service to Helix Enterprise.

Prerequisite
  • Make sure an instance of Websense Multiplexer is installed for each Helix Enterprise instance.

Configuring Websense Integration
  1. Open the Settings > General > SIEM Integration page.

  2. Select Enable SIEM integration for this Policy Server.

  3. Provide the IP address or hostname of the Helix Enterprise instance, as well as the communication Port to use for sending SIEM data.

  4. Specify the Transport protocol (UDP or TCP) to use when sending data to Helix Enterprise.

  5. Select the SIEM format to use. This determines the syntax of the string used to pass log data to the integration.

    • The available formats are syslog/CEF (Arcsight), syslog/key-value pairs (Splunk and others), syslog/LEEF (QRadar), and Custom.

      Note

      LEEF is preferred.

    • If you select Custom, a text box is displayed. Enter or paste the string that you want to use. Click View SIEM format strings for a set of sample strings to use as a reference or template.

    • If you select a non-custom option, a sample Format string showing fields and value keys is displayed.

  6. Click OK to cache your changes.

  7. Click Save and Deploy to implement your cached changes.

When you save your changes, Websense Multiplexer connects to Filtering Service and takes over the job of distributing log data to both Log Server and Trellix Helix Enterprise.

Note

Although the same data is passed from Filtering Service to both Log Server and Helix Enterprise, Log Server may be configured to perform data reduction processing tasks (like recording visits instead of hits, or consolidating log records). Because Helix Enterprise does not perform these data reduction tasks, there may be more SIEM entries than records in the Log Database.