Ingest Logs from Avanan
C
Carles Javierre
CheckPoint Harmony Email & Collaboration partner, user and fan here. That would be greatly appreciated if it added context and maybe could help your detections/incident reports.
M
Marcus D
Jerry Meyer We have this working already with Avanan via the Generic HEC source in Huntress SIEM. only added function that would be great to have is predefined queries and triggers in Huntress for escalations (but can be done in Huntress with custom queries if searching for something specific)
Avanan -> Security Settings -> Security Engines -> SIEM Integration -> Configure
Transport -> Splunk HTTPS Event Collector (HEC)
HTTP Event Collector Host / URI -> https://hec.huntress.io/services/collector
HTTP Event Collector Token -> Token from Huntress
Format -> JSON (Spunk HEC/CIM compatible)
Collect System logs -> Checked
J
Joel DeTeves
Marcus D thanks for sharing - i was struggling to get this working turns out i chose JSON insted of the JSON Splunk option.
M
Matt Payze
Great request. Not just Avanan but also Check Point Harmony Email & Collaboration (the new and improved version of Avanan) :)
M
Mick Alford
Yes very much yes
Dino Chirico
we really need this
B
Ben Smith
Yes please!
D
David Ridenhour
One hundred percent agree with this.