Skip to content

Commit

Permalink
Merge pull request #1887 from SEKOIA-IO/feat/SesameitJizoNDR
Browse files Browse the repository at this point in the history
SesameIT: add Jizo NDR documentation
  • Loading branch information
squioc authored Jul 11, 2024
2 parents dba1e3b + 723eba9 commit ee996c1
Show file tree
Hide file tree
Showing 2 changed files with 45 additions and 0 deletions.
44 changes: 44 additions & 0 deletions docs/xdr/features/collect/integrations/network/sesameit_jizo.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,44 @@
uuid: 46e14ac3-0b79-42d6-8630-da4fcdb8d5f1
name: Sesame it Jizo NDR
type: intake

## Overview
Sesame it Jizo NDR is a network observability platform that enables decision-makers to anticipate, identify and block cyber-attacks.

!!! warning
Important note - This format is currently in beta. We highly value your feedback to improve its performance.


{!_shared_content/operations_center/detection/generated/suggested_rules_46e14ac3-0b79-42d6-8630-da4fcdb8d5f1_do_not_edit_manually.md!}

{!_shared_content/operations_center/integrations/generated/46e14ac3-0b79-42d6-8630-da4fcdb8d5f1.md!}


## Configure

In this guide, you will configure the Jizo NDR to forward events to syslog.

### Prerequisites

An internal syslog concentrator is required to collect and forward events to Sekoia.io.

### Configure log settings

1. Log into jizo console
2. Configure Syslog Primary to receive alerts Logs

```shell
syslog_conf set <log concentrator server ip> <PROTOCOL> <log concentrator port> 2
```

with <Protocol> for protocol (tcp or udp) used to send Logs and 2 to indicate first IdsLog (syslog primary)


## Create the intake

Go to the [intake page](https://app.sekoia.io/operations/intakes) and create a new intake from the format `Sesame it Jizo NDR`.


## Forward logs to Sekoia.io

Please consult the [Syslog Forwarding](../../../ingestion_methods/sekoiaio_forwarder/) documentation to forward these logs to Sekoia.io.
1 change: 1 addition & 0 deletions mkdocs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -255,6 +255,7 @@ nav:
- pfSense: xdr/features/collect/integrations/network/pfsense.md
- Pulse / Ivanti Secure Connect: xdr/features/collect/integrations/network/pulse.md
- Rubycat PROVE IT: xdr/features/collect/integrations/network/rubycat_prove_it.md
- Sesame it Jizo: xdr/features/collect/integrations/network/sesameit_jizo.md
- SonicWall Firewall: xdr/features/collect/integrations/network/sonicwall_fw.md
- SonicWall SMA: xdr/features/collect/integrations/network/sonicwall_sma.md
- Squid: xdr/features/collect/integrations/network/squid.md
Expand Down

0 comments on commit ee996c1

Please sign in to comment.