From 0dbc12681ae180e78595ebcdf707d07490013dec Mon Sep 17 00:00:00 2001 From: rombernier Date: Mon, 8 Apr 2024 11:44:00 +0200 Subject: [PATCH 1/4] add olfeo --- .../network/olfeo_secure_web_gateway.md | 42 +++++++++++++++++++ mkdocs.yml | 1 + 2 files changed, 43 insertions(+) create mode 100644 docs/xdr/features/collect/integrations/network/olfeo_secure_web_gateway.md diff --git a/docs/xdr/features/collect/integrations/network/olfeo_secure_web_gateway.md b/docs/xdr/features/collect/integrations/network/olfeo_secure_web_gateway.md new file mode 100644 index 0000000000..38b96da69b --- /dev/null +++ b/docs/xdr/features/collect/integrations/network/olfeo_secure_web_gateway.md @@ -0,0 +1,42 @@ +uuid: 924470a7-ab0f-49e9-a9c2-d8d15c4fe78f +name: Olfeo Secure Web Gateway +type: intake + +## Overview + +Olfeo Secure Web Gateway is a web gateway offering malware detection, threat prevention and reputation filtering. +This product is supported by Olfeo. + + +{!_shared_content/operations_center/detection/generated/suggested_rules_924470a7-ab0f-49e9-a9c2-d8d15c4fe78f_do_not_edit_manually.md!} + +{!_shared_content/operations_center/integrations/generated/924470a7-ab0f-49e9-a9c2-d8d15c4fe78f.md!} + +## Configure + +This setup guide will show you how to forward your Olfeo Secure Web Gateway logs +to Sekoia.io by means of a syslog transport channel. + +### Prerequisites + +- Have an internal log concentrator + +### Enable Syslog forwarding + +To enable syslog forwarding: + +1. Log in your Olfeo web interface. +2. Go to `Parameters > Monitoring > Syslog.`. +3. Click on `add a syslog` button. +4. Add `label, description and server adress`. +5. Click on `Create`. + +Olfeo forward syslogs in UDP on port 514. You must setup your internal log concentrator to listen on this port and forward logs to Sekoia.io. + +### Create the intake + +Go to the [intake page](https://app.sekoia.io/operations/intakes) and create a new intake from the format `Olfeo Secure Web Gateway`. + +### Forward logs to Sekoia.io + +Please consult the [Syslog Forwarding](../../../ingestion_methods/sekoiaio_forwarder/) documentation to forward these logs to Sekoia.io. \ No newline at end of file diff --git a/mkdocs.yml b/mkdocs.yml index 25e0077568..01f9e63522 100644 --- a/mkdocs.yml +++ b/mkdocs.yml @@ -232,6 +232,7 @@ nav: - Mc Afee/Skyhigh Secure Web Gateway: xdr/features/collect/integrations/network/skyhigh_secure_web_gateway.md - Microsoft Always On VPN: xdr/features/collect/integrations/network/microsoft_always_on_vpn.md - NetFilter: xdr/features/collect/integrations/network/netfilter.md + - Olfeo Secure Web Gateway: xdr/features/collect/integrations/network/olfeo_secure_web_gateway.md - OPNSense: xdr/features/collect/integrations/network/opnsense.md - Palo Alto Next-Generation Firewall: xdr/features/collect/integrations/network/paloalto.md - pfSense: xdr/features/collect/integrations/network/pfsense.md From b1d71a83f69a19b7950ad59f16d04bd020a0f6fd Mon Sep 17 00:00:00 2001 From: rombernier Date: Mon, 15 Apr 2024 15:28:52 +0200 Subject: [PATCH 2/4] add olfeo --- .../network/olfeo_secure_web_gateway.md | 13 ++++++++----- 1 file changed, 8 insertions(+), 5 deletions(-) diff --git a/docs/xdr/features/collect/integrations/network/olfeo_secure_web_gateway.md b/docs/xdr/features/collect/integrations/network/olfeo_secure_web_gateway.md index 38b96da69b..9e50943fbe 100644 --- a/docs/xdr/features/collect/integrations/network/olfeo_secure_web_gateway.md +++ b/docs/xdr/features/collect/integrations/network/olfeo_secure_web_gateway.md @@ -1,16 +1,15 @@ -uuid: 924470a7-ab0f-49e9-a9c2-d8d15c4fe78f +uuid: a2915a14-d1e9-4397-86fc-8f8b2c617466 name: Olfeo Secure Web Gateway type: intake ## Overview -Olfeo Secure Web Gateway is a web gateway offering malware detection, threat prevention and reputation filtering. -This product is supported by Olfeo. +Olfeo Secure Web Gateway is a suite of cybersecurity features for analyzing, filtering and securing your web flows. Combining proxy filtering, flow antivirus and DNS filtering. -{!_shared_content/operations_center/detection/generated/suggested_rules_924470a7-ab0f-49e9-a9c2-d8d15c4fe78f_do_not_edit_manually.md!} +{!_shared_content/operations_center/detection/generated/suggested_rules_a2915a14-d1e9-4397-86fc-8f8b2c617466_do_not_edit_manually.md!} -{!_shared_content/operations_center/integrations/generated/924470a7-ab0f-49e9-a9c2-d8d15c4fe78f.md!} +{!_shared_content/operations_center/integrations/generated/a2915a14-d1e9-4397-86fc-8f8b2c617466.md!} ## Configure @@ -21,6 +20,10 @@ to Sekoia.io by means of a syslog transport channel. - Have an internal log concentrator +### Version supported + +Olfeo Secure Web Gateway On premise v6.8.6 and above + ### Enable Syslog forwarding To enable syslog forwarding: From f21f8807381524e8e6df1ecf2a928fd05b3870d2 Mon Sep 17 00:00:00 2001 From: rombernier Date: Tue, 16 Apr 2024 15:11:24 +0200 Subject: [PATCH 3/4] add olfeo --- .../collect/integrations/network/olfeo_secure_web_gateway.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/xdr/features/collect/integrations/network/olfeo_secure_web_gateway.md b/docs/xdr/features/collect/integrations/network/olfeo_secure_web_gateway.md index 9e50943fbe..fa414567d2 100644 --- a/docs/xdr/features/collect/integrations/network/olfeo_secure_web_gateway.md +++ b/docs/xdr/features/collect/integrations/network/olfeo_secure_web_gateway.md @@ -20,7 +20,7 @@ to Sekoia.io by means of a syslog transport channel. - Have an internal log concentrator -### Version supported +### Versions supported Olfeo Secure Web Gateway On premise v6.8.6 and above From 42757899410edc1771164b1285585f70e1a04978 Mon Sep 17 00:00:00 2001 From: rombernier <136727505+rombernier@users.noreply.github.com> Date: Tue, 16 Apr 2024 15:13:52 +0200 Subject: [PATCH 4/4] Update docs/xdr/features/collect/integrations/network/olfeo_secure_web_gateway.md MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-authored-by: Sébastien Quioc --- .../collect/integrations/network/olfeo_secure_web_gateway.md | 3 +++ 1 file changed, 3 insertions(+) diff --git a/docs/xdr/features/collect/integrations/network/olfeo_secure_web_gateway.md b/docs/xdr/features/collect/integrations/network/olfeo_secure_web_gateway.md index fa414567d2..414c171598 100644 --- a/docs/xdr/features/collect/integrations/network/olfeo_secure_web_gateway.md +++ b/docs/xdr/features/collect/integrations/network/olfeo_secure_web_gateway.md @@ -6,6 +6,9 @@ type: intake Olfeo Secure Web Gateway is a suite of cybersecurity features for analyzing, filtering and securing your web flows. Combining proxy filtering, flow antivirus and DNS filtering. +!!! warning + Important note - This format is currently in beta. We highly value your feedback to improve its performance. + {!_shared_content/operations_center/detection/generated/suggested_rules_a2915a14-d1e9-4397-86fc-8f8b2c617466_do_not_edit_manually.md!}