Infoblox NIOS
Pack Contributors:
- JesĂșs GarcĂa Potes jesusgarciapotes95@gmail.com
Contributions are welcome and appreciated. For more info, visit our Contribution Guide.
Infoblox is a comprehensive solution that consolidates DNS, DHCP, and IP address management into a single platform. It is designed to simplify network management by automating these critical functions and providing a centralized console for managing them.
Contributions are welcome and appreciated. For more info, visit our Contribution Guide.
This pack includes XSIAM content.
The following XQL Queries demonstrate the XDM modeling for the ingested Infoblox syslog messages:
javascript
config timeframe = 1H
| datamodel dataset = infoblox_infoblox_raw
| filter xdm.event.type = "DNS Query"
| fields xdm.source.process.name, xdm.source.process.pid, xdm.alert.severity, xdm.event.log_level, xdm.event.type, xdm.event.description, xdm.source.ipv4, xdm.source.port, xdm.intermediate.ipv4, xdm.network.dns.dns_question.name, xdm.network.dns.dns_question.type, xdm.network.dns.dns_question.class, xdm.event.outcome, xdm.event.outcome_reason, xdm.network.ip_protocol
javascript
config timeframe = 1H
| datamodel dataset = infoblox_infoblox_raw
| filter xdm.event.type = "DNS Response"
| fields xdm.source.process.name, xdm.source.process.pid, xdm.alert.severity, xdm.event.log_level, xdm.event.type, xdm.event.description, xdm.source.ipv4, xdm.source.port, xdm.network.dns.authoritative, xdm.network.dns.dns_question.name, xdm.network.dns.dns_question.class, xdm.network.dns.dns_question.type, xdm.network.dns.is_response,xdm.network.dns.is_truncated, xdm.network.dns.response_code, xdm.network.dns.dns_resource_record.name, xdm.network.dns.dns_resource_record.value, xdm.network.dns.dns_resource_record.type, xdm.network.dns.dns_resource_record.class, xdm.target.host.ipv4_addresses, xdm.target.host.ipv6_addresses, xdm.target.ipv4, xdm.target.ipv6, xdm.network.ip_protocol, xdm.event.outcome, xdm.event.outcome_reason
javascript
config timeframe = 1H
| datamodel dataset = infoblox_infoblox_raw
| filter xdm.event.type = "DHCP" and xdm.network.dhcp.message_type != null
| fields xdm.source.process.name, xdm.source.process.pid, xdm.alert.severity, xdm.event.log_level, xdm.event.type, xdm.event.description, xdm.network.dhcp.message_type, xdm.source.host.mac_addresses, xdm.source.host.device_id, xdm.source.interface, xdm.source.ipv4, xdm.intermediate.ipv4, xdm.network.dhcp.giaddr, xdm.target.ipv4, xdm.network.dhcp.siaddr, xdm.network.dhcp.chaddr, xdm.network.dhcp.ciaddr, xdm.network.dhcp.client_hostname, xdm.network.dhcp.lease, xdm.network.dhcp.requested_address, xdm.network.dhcp.yiaddr, xdm.event.operation_sub_type, xdm.session_context_id, xdm.event.outcome, xdm.event.outcome_reason
This section describes the configuration steps that need to be done on your Infoblox NIOS appliance for sending event logs to Cortex XSIAM Broker VM via syslog.
Login to the Infoblox NIOS appliance.
From the Grid tab, Navigate to Grid Manager → Members, and then click Grid Properties → Edit from the Toolbar.
In the Grid Properties editor, select the Monitoring tab, and then complete the following:
Parameter | Value |
---|---|
Address |
Enter the IP address of the Cortex XSIAM Broker VM Syslog server. |
Transport |
Select whether the appliance should use UDP, TCP, or Secure TCP to connect to the Cortex XSIAM Broker VM. |
Server Certificate |
To transport the logs over Secure TCP, upload a self-signed or a CA-signed server certificate. |
Interface |
Select the interface through which the appliance should send the syslog messages to the Cortex XSIAM Broker VM. |
Source |
Select whether the appliance should send only Internal messages, External messages, or both (Any). |
Node ID |
Specify the host or node identification string that would be used in the syslog message header to identify the appliance from which the syslog messages originated. |
Port |
Enter the port number that the Cortex XSIAM Broker VM is listening on for receiving syslog messages from the Infoblox appliance. |
Severity |
Select the severity level of which messages from this level and above should be sent to Cortex XSIAM. |
Logging Category |
Select Send selected categories and use the arrows to move the requested logging categories from the Available table to the Selected table and vice versa. |
If you want Audit logs to be forwarded to Cortex XSIAM Broker VM as well, select Copy Audit Log Messages to Syslog and select the facility that determines the processes and daemons from which the log messages are generated.
Save the configuration and click Restart if it appears at the top of the screen.
Timestamp Parsing for syslog messages sent from Infoblox to Cortex XSIAM is supported in GMT time zone. The time zone configured on the grid member should be set accordingly. See Using a Syslog Server and Viewing the Syslog Infoblox docs for additional details.
In order to use the collector, use the Broker VM option.
You will need to use the information described here.
You can configure the specific vendor and product for this instance.
Parameter | Value |
---|---|
Protocol |
Select UDP, TCP, or Secure TCP, in accordance with the selected syslog transport method configured on the Infoblox appliance. |
Port |
Enter the syslog service port that Cortex XSIAM Broker VM should listen on for receiving forwarded events from the Infoblox appliance. |
Vendor |
Enter Infoblox. |
Product |
Enter Infoblox. |
Contributions are welcome and appreciated. For more info, visit our Contribution Guide.
Name | Description |
---|---|
Infoblox | Infoblox enables you to receive metadata about IPs in your network and manages the DNS Firewall by configuring RPZs. It defines RPZ rules to block DNS resolution for malicious or unauthorized hostnames, or redirect clients to a walled garden by substituting responses. |
Name | Description |
---|---|
Infoblox | Infoblox enables you to receive metadata about IPs in your network and manages the DNS Firewall by configuring RPZs. It defines RPZ rules to block DNS resolution for malicious or unauthorized hostnames, or redirect clients to a walled garden by substituting responses. |
Name | Description |
---|---|
Infoblox Modeling Rules |
Name | Description |
---|---|
Infoblox Parsing Rule |
Pack Name | Pack By |
---|---|
Base | By: Cortex XSOAR |
Pack Name | Pack By |
---|
Pack Name | Pack By |
---|---|
Base | By: Cortex XSOAR |
Certification | Certified | Read more |
Supported By | Cortex | |
Created | December 13, 2020 | |
Last Release | January 9, 2025 |