Adding a New Profile

Create a new profile to connect Forcepoint RBI to a SIEM tool.

Steps

  1. Sign in to Forcepoint ONE Platform.
  2. Click the settings icon on the top . Next, navigate to Integration > SIEM.
  3. Click the +Add New Profile button. Following dialog is displayed:
    Table 1. +Add New Profile Fields
    S.No. Field Name Description
    1 Profile Details The fields in this section, allow for setting the name and description that will be used to store the profile on the system.
    2 Server Connection Details The fields in this section, allow for setting the server connection details for connecting to a SIEM server.
    3 Log Details The fields in this section, allow for setting the log format and selecting the events that will be included.
  4. Under Profile Details section, enter the Name and Description.
    Note: The Name is required. The profile cannot be saved without a name.
  5. Under Server Connection Details
    1. For Export Destination, Syslog is the only option and is selected by default.
    2. In the Syslog Server field, enter the host name or the IP address of the Syslog server. This field is required.
    3. In the Server Port field, enter the port number of the server. This field is required
    4. Select the Transport Protocol. UDP is selected by default. If TCP is selected, you can also enable or disable TLS. If you enable TLS, select the certificates to be used.
    5. Click Check Connection to verify that Forcepoint RBI can connect to the Syslog server.
  6. Under Log Details:
    1. For Log Format, JSON is the only option and is selected by default.
    2. Select the Events that need to be logged. You can select one or more types of events and add or remove them from this field.
  7. Click Save.