IoT Security
Send Security Alerts to SIEM
Table of Contents
Expand All
|
Collapse All
IoT Security Docs
-
-
- Firewall Deployment Options for IoT Security
- Use a Tap Interface for DHCP Visibility
- Use a Virtual Wire Interface for DHCP Visibility
- Use SNMP Network Discovery to Learn about Devices from Switches
- Use Network Discovery Polling to Discover Devices
- Use ERSPAN to Send Mirrored Traffic through GRE Tunnels
- Use DHCP Server Logs to Increase Device Visibility
- Control Allowed Traffic for Onboarding Devices
- Support Isolated Network Segments
-
Send Security Alerts to SIEM
Manually send security alerts from IoT Security through Cortex XSOAR to
SIEM.
Where Can I Use This? | What Do I Need? |
---|---|
|
One of the following Cortex XSOAR setups:
|
From the IoT Security portal, send a security alert to SIEM from the
AlertsSecurity Alerts page. You can also do this in the Actions menu in the Alert section
on the Device Details page.
By integrating IoT Security through Cortex XSOAR with a third-party SIEM server,
XSOAR automatically exports data about devices, security alerts, and device
vulnerability in periodic incremental updates from IoT Security to SIEM. Therefore,
it might be unnecessary to send a security alert to SIEM manually. However, if you
haven’t performed a bulk export to SIEM and you want to send a security alert that
wasn’t exported through the automatic incremental update process, then you can use
this option to send it manually.
- Log in to the IoT Security portal and select an alert on AlertsSecurity AlertsAll Alerts.
- Click MoreSend toSIEM.IoT Security sends the security alert in Common Event Format (CEF) through Cortex XSOAR to the SIEM server.