<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FireEye HX integration in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/FireEye-HX-integration/m-p/572153#M101267</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cool. We have UDP opened on all the syslog forwarders.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 24 Oct 2021 13:11:56 GMT</pubDate>
    <dc:creator>kiranpanchavat1</dc:creator>
    <dc:date>2021-10-24T13:11:56Z</dc:date>
    <item>
      <title>FireEye HX integration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/FireEye-HX-integration/m-p/572142#M101263</link>
      <description>&lt;P&gt;Dears,&lt;/P&gt;&lt;P&gt;Can we integrate the Fireeye HX with Splunk using GUI or not ? If not let me know the process for CLI.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Oct 2021 10:54:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/FireEye-HX-integration/m-p/572142#M101263</guid>
      <dc:creator>kiranpanchavat1</dc:creator>
      <dc:date>2021-10-24T10:54:14Z</dc:date>
    </item>
    <item>
      <title>Re: FireEye HX integration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/FireEye-HX-integration/m-p/572147#M101264</link>
      <description>&lt;P&gt;What kind of integration you want? FireEye HX can export alerts in CEF format which can be quite easily parsed by splunk. I don't remember if it can send alerts directly to HEC.&lt;/P&gt;&lt;P&gt;Also if I remember correctly, the HX has REST API so you could define workflow actions on splunk side but I don't recall seeing a ready-made app with this.&lt;/P&gt;</description>
      <pubDate>Sun, 24 Oct 2021 12:28:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/FireEye-HX-integration/m-p/572147#M101264</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-10-24T12:28:39Z</dc:date>
    </item>
    <item>
      <title>Re: FireEye HX integration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/FireEye-HX-integration/m-p/572149#M101265</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the reply.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have followed the below steps to integrate fireeye hx.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The HX appliance logging cannot be set from the GUI as of right now, please use the CLI:&lt;BR /&gt;hostname # logging 173.1.227.134 trap none&lt;BR /&gt;hostname # logging 173.1.227.134 &amp;nbsp;trap override class cef priority info&lt;BR /&gt;hostname # logging 173.2.227.134 trap none&lt;BR /&gt;hostname # logging 173.2.227.134 &amp;nbsp;trap override class cef priority info&lt;BR /&gt;hostname # write mem&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/1845/#/details" target="_blank"&gt;FireEye App for Splunk Enterprise v3 | Splunkbase&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But not working.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Oct 2021 12:34:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/FireEye-HX-integration/m-p/572149#M101265</guid>
      <dc:creator>kiranpanchavat1</dc:creator>
      <dc:date>2021-10-24T12:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: FireEye HX integration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/FireEye-HX-integration/m-p/572152#M101266</link>
      <description>&lt;P&gt;I haven't touched HX for few years so I don't remember exactly but I suppose this way you set up forwarding log on default syslog port. Do you have a listener on your splunk server on udp:514?&lt;/P&gt;</description>
      <pubDate>Sun, 24 Oct 2021 13:09:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/FireEye-HX-integration/m-p/572152#M101266</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-10-24T13:09:54Z</dc:date>
    </item>
    <item>
      <title>Re: FireEye HX integration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/FireEye-HX-integration/m-p/572153#M101267</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cool. We have UDP opened on all the syslog forwarders.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Oct 2021 13:11:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/FireEye-HX-integration/m-p/572153#M101267</guid>
      <dc:creator>kiranpanchavat1</dc:creator>
      <dc:date>2021-10-24T13:11:56Z</dc:date>
    </item>
    <item>
      <title>Re: FireEye HX integration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/FireEye-HX-integration/m-p/572154#M101268</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;UDP ports has been opened already . We are receiving the fireeye NX, EX and CMS logs not HX logs. Not sure is there any configuration we need to change on fireeye side .&amp;nbsp;&lt;/P&gt;&lt;P&gt;can you please post this comment on any splunk slack channels and get the update ASAP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help in advance.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Oct 2021 13:39:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/FireEye-HX-integration/m-p/572154#M101268</guid>
      <dc:creator>kiranpanchavat1</dc:creator>
      <dc:date>2021-10-24T13:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: FireEye HX integration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/FireEye-HX-integration/m-p/572155#M101269</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are receiving syslog logs not HX application logs . We tried both GUI and CLI options but no luck .&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Oct 2021 13:45:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/FireEye-HX-integration/m-p/572155#M101269</guid>
      <dc:creator>kiranpanchavat1</dc:creator>
      <dc:date>2021-10-24T13:45:10Z</dc:date>
    </item>
  </channel>
</rss>

