Collect FireEye NX logs
This document describes how you can collect the FireEye Network Security and Forensics (NX) logs by using a Google Security Operations forwarder.
For more information, see Data ingestion to Google SecOps overview.
An ingestion label identifies the parser that normalizes raw log data to structured
UDM format. The information in this document applies to the parser with the
FIREEYE_NX
ingestion label.
Configure FireEye NX
- Sign in to the FireEye NX interface.
- Go to Settings > Notifications.
- To enable a syslog notification configuration, select the rsyslog checkbox.
- Click Add rsyslog server.
- In the Name field, enter a name to label your FireEye connection to the Google SecOps instances.
- In the IP address field, enter the Google SecOps forwarder IP address.
- Select the Enabled checkbox.
- In the Delivery list, select Per event.
- In the Notifications list, select All events.
- In the Format list, select CEF.
- In the Account field, don't enter any information.
- In the Protocol list, select the protocol.
Click Add new rsyslog server.
Configure the Google SecOps forwarder to ingest FireEye NX logs
- In the Google SecOps menu, select Settings > Forwarders > Add new forwarder.
- In the Forwarder name field, enter a unique name for the forwarder.
- Click Submit. The forwarder is added and the Add collector configuration window appears.
- In the Collector name field, enter a unique name for the collector.
- In the Log type field, specify
FireEye NX
. - Select Syslog as the Collector type.
- Configure the following input parameters:
- Protocol: specify the connection protocol that the collector uses to listen to syslog data.
- Address: specify the target IP address or hostname where the collector resides and listens to syslog data.
- Port: specify the target port where the collector resides and listens to syslog data.
- Click Submit.
For more information about the Google SecOps forwarders, see Manage forwarder configurations through the Google SecOps UI.
If you encounter issues when you create forwarders, contact Google SecOps support.