Background
This article provides a walkthrough on enabling the SIEM and Log Forwarding integration between Huntress and CyberQP by creating a Generic HEC log source in Huntress and connecting it in the CyberQP admin dashboard.
Pre-requisites
- Administrative access to the Huntress management console with permission to manage SIEM log sources
- Administrative access to the CyberQP admin dashboard
Table of Contents
Create the Log Source in Huntress
- Sign in to the Huntress management console.
- In the left navigation bar, click SIEM, then click Source Management.
- In the Log Sources window, click Add Source.
- Click Generic HEC.
- Click the add (plus) icon.
- Select the organization.
- Enter a name for the source.
- Add a description (optional.
- Click Save.
- Copy the Event Collector URL and the Event Collector Token.
Configure the Integration in CyberQP
- Sign in to the CyberQP admin dashboard.
- In the left navigation, click Integrations.
- Open the SIEM and Log Forwarding Huntress integration.
- Paste the Event Collector URL into the collector URL field.
- Paste the Event Collector Token into the HEC Token field.
- Click Submit.
- Confirm the SIEM and Log Forwarding integration displays a green status indicator inside the Huntress integration.
end of article
Comments
0 comments
Article is closed for comments.