Datacollector

Management

This topic provides information on how to add a data source to the Logger software.

Sources ℹ️

Sources are fundamental components that define the data collection points of the SIEM system and are essential resources that must be added for the dataview page to function properly. A source can be any device you want to integrate into your SIEM product, including network devices such as firewalls and switches, or client machines with installed agents. Various methods can be used to send logs from these devices to the SIEM software: the most common Syslog protocol can be used over 514/UDP or 514/TCP ports, API-based integrations can be implemented, or data transfer can be provided through the agent's own dedicated port and protocol. To add a Data Source, see How to Use.

Internal Logs 👨‍⚕️

Unlike traffic logs, internal logs provide detailed information about the state of the container system on which the logger software is running. They also provide visibility into event logs generated by the logger software itself. As with all log types, features such as date-based filtering and column customization are available here. Filtering and column customization is described in detail in the Data View manual. To access Internal Logs, go to DataView > Administration > Internal Logs

Audit Logs 🕵️‍♀️

Audit logs display user activity on the logger software. They provide detailed records of events such as login and logout actions, as well as object modifications, deletions, and additions within the system. As with all log types, features like date filtering and column customization are available. Filtering and column customization is described in detail in the Data View manual. To access audit logs, DataView > Management > Audit Logs

How To Use ? 🤔

Send Log Data

Log sending procedures may differ depending on the device brand. Below you can find log submission guides for common security devices. If it is not available on our blog page, you can go to the official website of the device brand and browse the support documents.

In the section below, you can access the blog posts of log submission processes of some brands;
Fortigate: blog/how-to-config-fortigate...
Sophos: blog/how-to-config-sophos...
Palo Alto: blog/how-to-config-paloalto...

Create New Source

Navigate to Datacollector > Management > Sources

  • Click the Create New button
  • Select your Vendor
  • Select your Data Source then click Add button.
  • You can edit and delete data sources with the buttons in the upper left corner.
  • In the Action section on the right side of the data sources, you can perform user authorization, editing, license activation and deletion.

Verify Live Data Flow

Go to Data View > Default View page.

  • Click on Data View Sources under the Data View Filters menu and select your registered source.
  • If you can see the live log stream after this process, the process has been completed successfully.