To collect events, you must configure syslog forwarding for Forcepoint
TRITON.
Procedure
-
Log in to your Forcepoint TRITON Web Security Console.
- On the Settings tab, select .
- Select the Enable SIEM integration for this
Policy Server check box.
- In the IP address or hostname field,
type the IP address of your QRadar.
- In the Port field, type 514.
- From the Transport protocol list,
select either the TCP or UDP protocol
option.
QRadar supports
syslog events for TCP and UDP protocols on port 514.
- From the SIEM format list, select syslog/LEEF
(QRadar)
- Click OK to cache any changes.
-
Click Deploy to update your Forcepoint TRITON security components or
V-Series appliances.
The Forcepoint Multiplexer connects to Forcepoint Filtering Service and ensures that event log
information is provided to QRadar.