Configure a ThreatSync+ NDR SIEM Integration

Applies To: ThreatSync+ NDR, Total NDR

This feature is only available with a ThreatSync+ NDR or Total NDR license. For more information, go to About ThreatSync+ NDR Licenses and About Total NDR Licenses.

Configuration of a Security Information and Event Management (SIEM) integration is a three-step process:

  • Add and configure a SIEM integration.
  • Configure alerts.
  • Configure notification rules.

Before You Begin

To configure SIEM integration with ThreatSync+ NDR, make sure:

  • You have a ThreatSync+ NDR or Total NDR license.
  • You have a ThreatSync+ NDR Collection Agent that has network connectivity to the SIEM server.

For more information, go to:

Add a SIEM Integration

To add a SIEM integration, you must have the SIEM server IP address, port, and a connected ThreatSync+ NDR Collection Agent.

To add a SIEM integration, from WatchGuard Cloud:

  1. Log in to your WatchGuard Cloud Subscriber account.
  2. Select Administration > System > Integrations.
    The Integrations page opens.

Screenshot of the SIEM Integration page

  1. Click Add SIEM Integration.
    The Add SIEM Integration page opens.

Screenshot of the Add SIEM Integration page

  1. In the Integration Name text box, enter a name for the SIEM integration.
  2. (Optional) In the Description text box, add a description to describe the SIEM integration.
  3. In the SIEM Server section, in the SIEM Server IP Address text box, enter the IP address of the SIEM server.

To send notifications from the ThreatSync+ NDR Collection Agent to the SIEM server, the SIEM server must have network connectivity from the ThreatSync+ NDR Collection Agent.

  1. In the Port text box, enter the port number the SIEM server listens on for incoming syslog events. For example, 514.
  2. From the Protocol drop-down list, select UDP.
  3. From the Collection Agent drop-down list, select the connected ThreatSync+ NDR Collection Agent that will forward syslog data to the SIEM server.
    1. If you want to assign syslog forwarding to a new or different collection agent, click Add New Collection Agent to go to the Collection Agents page in the ThreatSync+ Integrations UI.
  4. Click Add.
    The SIEM Integration page opens with the new integration added to the table.
  5. After the status changes to Connected, the SIEM integration configuration is complete. It might take a few minutes for the status to change to Connected. ClickThe Refresh icon to refresh the page.

Edit a SIEM Integration

You can edit a SIEM integration to change the description or update SIEM server details.

To edit an SIEM integration:

  1. Select Administration > System > Integrations.
    The Integrations page opens.
  2. Click the name of the SIEM integration you want to edit.
    The SIEM Integration Details page opens.
  3. (Optional) In the SIEM Server IP Address text box, edit the SIEM server IP address.
  4. (Optional) In the Port text box, update the port number.
  5. (Optional) From the Collection Agent drop-down list, select a different ThreatSync+ NDR Collection Agent.
  6. Click Save.

Delete a SIEM Integration

You can delete a SIEM integration from the SIEM Integration page.

To delete a SIEM integration:

  1. Select Administration > System > Integrations.
    The Integrations page opens.
  2. Click The Options icon, blue next to the name of the SIEM integration you want to delete.
    The Delete SIEM Integration dialog box opens.

Screenshot of the Delete SIEM Integration dialog box

When you delete a SIEM integration, you also delete notification rules that use the SIEM integration.

  1. Click Delete.

Configure SIEM Alerts and Notification Rules

To configure SIEM alerts and notification rules, you specify which alerts generate a notification when they are created or updated.

From the SIEM Alerts tab on the Configure > ThreatSync+ > Alerts page, select which alerts you want included in your notifications.

Screenshot of the SIEM Alerts tab on the Alerts page in Configure > ThreatSync+ > SIEM Alerts

To configure SIEM notifications, enable SIEM on the Administration > Notifications page and select which SIEM configuration to use for the notifications.

Because Total NDR includes ThreatSync+ SaaS, the SIEM delivery method is available for ThreatSync+ SaaS notifications in accounts with a Total NDR license.

Screenshot of the Delivery Method section on the Notifications page in WatchGuard Cloud, SIEM toggle enabled

For more information, go to Configure ThreatSync+ Alerts and Notification Rules.

Related Topics

About ThreatSync+ NDR SIEM Integration

Configure ThreatSync+

Monitor ThreatSync+