Configure the Trellix ePO platform to send logs to Arctic Wolf

You can configure the Trellix ePolicy Orchestrator (Trellix ePO)® platform to send the necessary logs to Arctic Wolf®.

Note:

This is an optional configuration. Discuss this log forwarding option with your Concierge Security® Team (CST).

These resources are required:

  • An activated Capteur Arctic Wolf or Collecteur de journaux virtuel (vLC)
  • Access to Trellix ePO platform with administrator permissions

Configure a new server

  1. Sign in to the Trellix ePO platform with administrator permissions.
  2. Click Menu, and then click Configuration > Registered Servers.
  3. Click New Server.
  4. On the Description page, configure these settings:
    • Server type — Select Syslog Server.
    • Name — Enter a unique name for your Capteur Arctic Wolf.
  5. Click Next.
  6. On the next Registered Server Builder page, configure these settings:
    • Server name — Enter your Capteur Arctic Wolf IP address o.
    • TCP port number — Enter 6514.
    • Enable event forwarding — Select the checkbox.
  7. Click Test connection.
  8. Click Save.
  9. Click Menu, and then click Configuration > Server Settings.
  10. In the Setting Categories list, select Event Filtering.
  11. Click Edit.
  12. On the Server Settings page, configure these settings:
    • The agent forwards — Select Only selected events to the server, and then select any events you want to send.
    • Where to store events — Select Store selected in both.
    • Event source — Select Events from any source.
  13. Click Save.

Provide configuration information to Arctic Wolf

  1. Sign in to the Portail unifié Arctic Wolf.
  2. Dans le menu de navigation, cliquez sur Ticket et alertes > Tous les tickets.
  3. Perform the appropriate action, depending on if you are:
    • A new customer — In the Ticket Type list, select Onboarding. Then, click the existing [Deploy] Site Config: <ticket_subject> ticket.
    • An existing customer — Click Open a New Ticket.
  4. On the Open a New Ticket page, configure these settings:
    • What is this ticket related to? — Select General request.
    • Subject — Enter Syslog changes.
    • Related ticket (optional) — Keep empty.
    • Message — Enter this information for your Concierge Security® Team (CST):
      • Confirmation that you completed the steps in this configuration guide.
      • The IP address or hostname of the Capteur Arctic Wolf that you used during the configuration.
      • The IP address, timezone, and device type for all sources that you are forwarding.
      • Questions or comments that you have.
  5. Click Send Message.

    Your CST reviews the details to make sure that Arctic Wolf is successfully processing the logs.