Sending Logs to Logpoint SaaS

You need to deploy Logpoint Cloud Connector Appliance in your network to send log information to Logpoint SaaS. Logpoint Cloud Connector Appliance allows collection of logs from a large variety of on-premise and cloud-based data sources.

To deploy and configure log collection with Logpoint Cloud Connector Appliances:

  1. Provision a virtual machine or device that meets hardware requirements. Use the Cloud Connector Appliance Sizing Helper to estimate your hardware requirements.

  2. Install Logpoint SIEM+SOAR from an ISO, VHD, or AMI depending on your infrastructure.

  3. Upload your Logpoint license.

  4. Install Logpoint Cloud Connector Plugin.

  5. Upload the Cloud Connector license.

  6. Disable Local Log Storage in the Cloud Connector Plugin.

  7. Configure Repositories.

  8. Configure devices, normalization, and enrichment policies.

  9. Configure enrichment subscriber.

Configure Repositories

You will need to configure repositories with the same names in both Cloud Connector Appliance and SaaS Web UI to successfully send the log information to SaaS service.

Repositories in the Cloud Connector Appliance may use the default storage path, and the Local Log Storage in Cloud Connector Plugin must be disabled. The repository names will be used in the routing policy configurations to route the log data to correct repositories in SaaS Web UI. For more details, go to the Repos section in the Data Integration guide.

Refer to Configure SaaS Instance section on how to configure repositories in SaaS Web UI.


Helpful?

We are glad this guide helped.


Please don't include any personal information in your comment

Contact Support