Configuring Symantec Cloud Security

Configuring a Repo for Symantec Cloud Security

  1. Go to Settings >> Configuration from the navigation bar and click Repos.

  2. Click Add.

  3. Enter a Repo Name.

  4. Select a Repo Path to store incoming logs.

  5. Set a Retention Day to keep logs in a repository before they are automatically deleted.

Note

You can add and remove multiple Repo Path and Retention Day.

  1. Select a Remote LogPoint and set a Available for (day).

  2. Click Submit.

_images/Symantecrepo.png

Adding a Repo

Adding a Normalization Policy

  1. Go to Settings >> Configuration from the navigation bar and click Normalization Policies.

  2. Click Add.

  3. Enter a Policy Name.

  4. Select SymantecCloudSecurityCompiledNormalizer.

  5. Click Submit.

_images/symanteccloud_addNormalizationPolicy.png

Adding a Normalization Policy

Configuring a Processing Policy for Symantec Cloud Security

  1. Go to Settings >> Configuration from the navigation bar and click Processing Policies.

  2. Click Add.

  3. Enter a Policy Name.

  4. Select the previously created Normalization Policy.

  5. Select the Enrichment Policy.

  6. Select the Routing Policy.

_images/processingpolicy.png

Adding a Processing Policy

Configuring Symantec Cloud Security Fetcher

  1. Go to Settings >> Configuration from the navigation bar and click Devices.

  2. Click Add collectors/fetchers (add) from Actions of the localhost device.

  3. Click SymantecCloud Fetcher.

  4. Click Add.

_images/symantec-fetcheradd.png

SymantecCloudSecurity Fetcher

  1. Enter your API credentials of Symantec Web Security Service in Username and Password.

  2. Select the Fetch Interval in minutes.

  3. Select the Start Date. Symantec Cloud Security fetches logs from the specified date.

  4. Select the End Date. Symantec Cloud Security fetches logs until the specified date.

  5. Select the previously created Processing Policy.

  6. Select the Charset.

  7. Select Enable Proxy to use a proxy server.

  8. In Proxy Configuration:

    12.1 Enter the IP address and the Port number of the proxy server.

    12.2 Select HTTP or HTTPS protocol as required.

  9. Click Submit.

_images/symanteccloud-fetcher.png

Adding a New Configuration for SymantecCloud Fetcher


Helpful?

We are glad this guide helped.


Please don't include any personal information in your comment

Contact Support