Claroty Continuous Threat Detection (CTD)
Cortex XSIAM SIEM Content
This pack includes Cortex XSIAM SIEM content, which is supported directly by Palo Alto Networks.
The SIEM content contains parsing and modeling rules for ingesting and mapping events and alerts that are sent from Claroty CTD to Cortex XSIAM.
This section describes the configurations required on Claroty CTD for forwarding events and alerts to Cortex XSIAM and the configurations required on Cortex XSIAM for ingesting and mapping them.
Configuration on Claroty CTD
Follow these steps to configure Claroty CTD to forward Syslog messages to Cortex XSIAM.
- Login to your account on the Claroty CTD web management console.
- Go to Configuration and navigate to Log Settings → Syslog.
- Click + Add to add a new syslog configuration.
- Clear the Local checkbox and fill in the following settings:
Parameter |
Value
|
Message Contents |
Select the log type to forward to Cortex XSIAM.
|
Message Format |
Select CEF.
|
Server |
Enter the IP address of the target Cortex XSIAM Broker VM syslog server.
|
Port |
Enter the port number which the target Cortex XSIAM Broker VM syslog server would be listening on for receiving syslog messages from Claroty CTD.
|
Protocol |
Select the requested forwarding transport protocol (UDP, TCP or TLS). |
- Click Save.
|
|
|
|
|
|
Since the syslog forwarding configuration is set for each log type individually,
repeat the steps above for each log type (Alerts, Events, etc.) to monitor on Cortex XSIAM.
Configuration on Cortex XSIAM
In order to use the collector for Claroty CTD, use the Broker VM option.
Broker VM
To create or configure the Broker VM, use the information described here.
You can configure the specific vendor and product for this instance.
- Navigate to Settings → Configuration → Data Broker → Broker VMs.
- Go to the apps tab and add the Syslog app for the relevant broker instance. If the Syslog app already exists, hover over it and click Configure.
- Click Add New.
- When configuring the Syslog Collector, set the following parameters:
| Parameter | Value
| :--- | :---
| Protocol
| Select the forwarding transport protocol in correspondence to the protocol defined on Claroty CTD (UDP, TCP or Secure TCP for TLS).
| Format
| Select CEF.
| Port
| Enter the syslog service port number that this Cortex XSIAM Broker VM should listen on for receiving forwarded events from Claroty CTD.
| Vendor
| Enter Claroty.
| Product
| Enter CTD.