Log Forwarding - Discovery Logs¶
Overview¶
Discovery logs may be forwarded to Security Information Event Management (SIEM) systems to aggregate into a single management platform.
Valtix supports viewing security event information directly within the UI. These events are available under the Investigate -> Traffic section. The events are categorized and viewable as follows:
Category | Type | Description |
---|---|---|
DNS Logs | DNS_LOG | Correlation of Threat Intelligence with DNS Log information gathered from cloud provider |
VPC Logs | VPC_LOG | Correlation of Threat Intelligence with VPC/VNet Flow Log information gathered from cloud provider |
Each of the categories can be sent to a SIEM using a Log Forwarding Profile and attaching the Profile to the onboarded Cloud Account. The Log Forwarding destinations currently supported by Valtix are:
To forward Discovery Logs, use the steps below:
Standalone Profile¶
Create a Profile¶
- Navigate to Manage -> Profiles -> Log Forwarding
- Click Create
- Specify a Profile Name and Description
- Specify Type as Standalone
- Fill in the appropriate parameters (refer to the SIEM-specific documentation)
- Click Save
- Associate the Log Profile to the desired Cloud Accounts (refer to Add a Cloud Account Association)
Edit a Profile¶
- Navigate to Manage -> Profiles -> Log Forwarding
- Check the box next to the Profile you want to Edit
- Click Edit
- Modify the parameters as desired (refer to the SIEM-specific documentation)
- Click Save
Group Profile¶
Create a Profile¶
- Navigate to Manage -> Profiles -> Log Forwarding
- Click Create
- Specify a Profile Name and Description
- Specify Type as Group
- Add a row for to associate a Standalone Profile
- Click Save
- Add the desired Gateway Associations (refer to Add a Gateway Association)
Edit a Profile¶
- Navigate to Manage -> Profiles -> Log Forwarding
- Check the box next to the Profile you want to Edit
- Click Edit
- Modify, Add or Remove Standalone Profiles
- Click Save
Delete a Profile¶
- Navigate to Manage -> Profiles -> Log Forwarding
- View the Profile Details to view the Associated CSP Accounts
- Remove all Cloud Account Associations (refer to Remove a Cloud Account Association)
- Navigate to Manage -> Profiles -> Log Forwarding
- Check the box next to the Profile you want to Delete
- Click Delete
- Confirm the Delete operation by clicking Yes or No
View a Profile Details¶
- Navigate to Manage -> Profiles -> Log Forwarding
- Select the Profile link you want to view the Details
- View the Details information
Add a Cloud Account Association¶
- Navigate to Manage -> Cloud Accounts -> Accounts
- Check the box next the Cloud Account you want to associate the Profile
- Click Actions -> Update Log Profile
- Select the Log Profile object for Cloud Logs Forwarding Profile
- Click Save & Continue
Remove a Cloud Account Association¶
- Navigate to Manage -> Cloud Accounts -> Accounts
- Check the box next the Cloud Account you want to de-associate the Profile
- Click Actions -> Update Log Profile
- For the Cloud Logs Forwarding Profile parameter, click the 'X' next to the Profile to remove it
- Click Save & Continue