This pack includes:
Log Normalization - XDM mapping for key event types.
Data Collection
To configure Dragos Platform to send logs to Cortex XSIAM, follow the below steps.
Dragos Platform side
Log in to Dragos as an administrator.
Navigate to Admin → Syslog or browse to "https://<your-site-store\>/syslog/".
Go to the SERVERS tab and click + ADD SERVER.
Fill the below data:
Parameter Value Name Cortex XSIAM Broker VM. Hostname/IP Enter the Broker VM IP address. Port Enter the syslog service port that you want to use for sending logs to the Broker VM. Protocol TCP/TLS. Source Hostname Leave the default value / set a value of your choice. Source Process Leave the default value / set a value of your choice. TLS Protocol Configuration (optional) If protocol is set to TLS, set all the relevant values. Check the RFC 5424 Modern Syslog checkbox under Message Format.
Check the Use newline delimiter for TCP and TLS streams checkbox under Message Delimiter.
Click Next: SET TEMPLATE.
From the Output Message Format dropdown, select CEF.
Use the recommended CEF template suggested by Dragos documentation, under Message.
Leave all other fields set to their default state.
Click Save.
For more information contact Dragos support.
Cortex XSIAM side
To create or configure the Broker VM, use the information described here.
Broker VM
Follow the below steps to configure the Broker VM to receive Dragos Platform logs.
Navigate to Settings → Configuration → Data Broker → Broker VMs.
Go to the APPS column under the Brokers tab and add the Syslog app for the relevant broker instance. If the Syslog app already exists, hover over it and click Configure.
Click Add New.
When configuring the Syslog Collector, set the following parameters:
Parameter Value Protocol
Select UDP for the default forwarding, TCP or Secure TCP (depends on the protocol you configured in the Dragos Platform configuration). Port
Enter the syslog service port that Cortex XSIAM Broker VM should listen on for receiving forwarded events from the Dragos Platform. Vendor
Enter dragos. Product
Enter platform.