Configuration

Configuring the RecordedFuture Application in LogPoint

  1. Go to Settings >> Configuration >> Recorded Future.

  2. Select Settings.

  3. Select the Enable Source option to activate the Recorded Future threat intelligence source.

  4. Enter the API Key provided by Recorded Future.

  5. Select the required Entities. The application fetches and stores data of the selected entities only.

  6. Select the Enable Proxy option to connect to Recorded Future via a proxy server.

  7. In the Proxy Configuration section:

    7.1 Enter the IP address and the Port number of the proxy server.

    7.2 Select the HTTP or HTTPS protocol as required.

  8. Click Submit.

_images/RF_enabling_proxy.png

Configuring Recorded Future

Note

The data fetched from Recorded Future is stored in the Threat Intelligence database. Therefore, you must use the Threat Intelligence enrichment source while creating an enrichment policy for the RecordedFuture application.

Configuring Drill Forward

The RecordedFuture application enriches the incoming logs with the threat information fetched from Recorded Future. You can find the enriched logs using the Search tab in LogPoint and can further drill forward on the enriched fields to access the Intelligence Card. To use the drill forward feature, you must enable the drill forward option and map the LogPoint fields with the Recorded Future entity type. You can only drill forward from the mapped fields.

The application maps the following fields by default:

LogPoint Taxonomy Field

Recorded Future Entity Type

source_address

IP Address

destination_address

IP Address

ip_address

IP Address

device_ip

IP Address

host_address

IP Address

hash

Hash

hash_sha256

Hash

hash_sha1

Hash

domain

Domain

url

URL

threat

Vulnerability

Follow these steps to use the drill forward feature:

  1. Go to Settings >> Configuration >> Recorded Future.

  2. Select Drill Forward Settings.

  3. Select the Enable Drill Forward option.

  4. Select the Type of entity from the drop-down menu.

  5. Enter the LogPoint Taxonomy Field to map it with the Recorded Future entity type.

  6. Click Add.

  7. Click Submit.

_images/RF_drill_forward_mapping.png

Enabling Drill Forward


Helpful?

We are glad this guide helped.


Please don't include any personal information in your comment

Contact Support