FireEye HX
This pack includes Cortex XSIAM content.
Configuration on Server Side
Raw syslog audit messages
In order to configure FireEye HX to send syslog audit logs, refer to FireEye HX Endpoint Security Server System Administration Guide (Configuring a Syslog Server Using the CLI).
Make sure to configure the syslog timestamp format to be RFC-3339 UTC.
CEF format logs
In order to configure FireEye HX to send CEF logs, refer to FireEye HX Endpoint Security Server System Administration Guide.
For further assistant, contact the tech support of FireEye HX.
Collect Events from Vendor
In order to use the collector, use the Broker VM option.
Broker VM
To create or configure the Broker VM, use the information described here.
You can configure the specific vendor and product for this instance.
- Navigate to Settings > Configuration > Data Broker > Broker VMs.
- Go to the apps tab and add the Syslog app. If it already exists, click the Syslog app and then click Configure.
- Click Add New.
- When configuring the Syslog Collector, set the following values:
- vendor as fireeye
- product as hx_audit
- format as Auto-Detect
- protocol as UDP