Collect FireEye NX logs
This document describes how you can collect the FireEye Network Security and Forensics (NX) logs by using a Google Security Operations forwarder.
For more information, see Data ingestion to Google SecOps overview .
An ingestion label identifies the parser that normalizes raw log data to structured
UDM format. The information in this document applies to the parser with the FIREEYE_NX
ingestion label.
Configure FireEye NX
- Sign in to the FireEye NX interface.
- Go to Settings > Notifications.
- To enable a syslog notification configuration, select the rsyslogcheckbox.
- Click Add rsyslog server.
- In the Namefield, enter a name to label your FireEye connection to the Google SecOps instances.
- In the IP addressfield, enter the Google SecOps forwarder IP address.
- Select the Enabledcheckbox.
- In the Deliverylist, select Per event.
- In the Notificationslist, select All events.
- In the Formatlist, select CEF.
- In the Accountfield, don't enter any information.
- In the Protocollist, select the protocol.
-
Click Add new rsyslog server.
Configure the Google SecOps forwarder to ingest FireEye NX logs
- In the Google SecOps menu, select Settings > Forwarders > Add new forwarder.
- In the Forwarder namefield, enter a unique name for the forwarder.
- Click Submit. The forwarder is added and the Add collector configurationwindow appears.
- In the Collector namefield, enter a unique name for the collector.
- In the Log typefield, specify
FireEye NX. - Select Syslogas the Collector type.
- Configure the following input parameters:
- Protocol: specify the connection protocol that the collector uses to listen to syslog data.
- Address: specify the target IP address or hostname where the collector resides and listens to syslog data.
- Port: specify the target port where the collector resides and listens to syslog data.
- Click Submit.
For more information about the Google SecOps forwarders, see Manage forwarder configurations through the Google SecOps UI .
If you encounter issues when you create forwarders, contact Google SecOps support .

