Overview
TXOne StellarOne is a centralized management console for TXOne's OT (Operational Technology) endpoint security agents (StellarProtect and StellarProtect Legacy Mode). It provides threat detection, application lockdown, and device control for industrial environments, and forwards audit, system, console, and agent security events in Syslog CEF format.
This pack includes
Data normalization capabilities:
- Rules for parsing and modeling TXOne StellarOne audit, system, console, and agent (StellarProtect) logs that are ingested via the Broker VM into Cortex XSIAM.
- The ingested TXOne StellarOne logs can be queried in XQL Search using the
txone_stellarone_rawdataset.
- The ingested TXOne StellarOne logs can be queried in XQL Search using the
Supported log categories
| Category | Category Display Name |
|---|---|
| Agent Event | Agent Event |
| Console Log | Console Log |
| AUDIT_EVENT | Audit Event |
| SYSTEM_EVENT | System Event |
Supported timestamp formats
- Epoch milliseconds (13-digit), e.g.
1765893322000. %b %d %Y %H:%M:%S GMT%Ez, e.g.Jan 01 2026 20:00:28 GMT+00:00.
Data Collection
TXOne StellarOne side
Configure StellarOne to forward events to a Syslog server (the Cortex XSIAM Broker VM):
- Log in to the StellarOne management console.
- Navigate to Administration → Configuration → Syslog.
- Enable Send logs to a syslog server.
- Set the Server address to the Broker VM IP address, the Port, and the Protocol (UDP/TCP/TLS).
- Set the format to CEF.
- Select the event types to forward (audit, system, console, and agent events).
- Save the configuration.
For more information, contact TXOne StellarOne customer support for proper guidance on configuring Syslog forwarding.
Cortex XSIAM side - Broker VM
For instructions on how to create or configure the Broker VM, see Set up and configure Broker VM.
Follow the instructions below to configure the Broker VM to receive TXOne StellarOne logs:
Navigate to Settings → Configuration → Data Broker → Broker VMs.
Go to the APPS column under the Brokers tab and add the Syslog app for the relevant broker instance. If the Syslog app already exists, hover over it and click Configure.
Click Add New.
When configuring the Syslog Collector, set the following parameters:
Parameter Value ProtocolSelect UDP for the default forwarding, or, if you configured TXOne StellarOne to use TCP or Secure TCP, select one of those instead. PortEnter the syslog port where the Cortex XSIAM Broker VM will receive forwarded events from TXOne StellarOne. FormatEnter CEF. VendorSelect Auto-Detect. ProductSelect Auto-Detect.
