Proteggiamo il tuo ambiente digitale da qualsiasi attacco informatico. Sfrutta tutte le potenzialità della piattaforma SGBox!

Gallery

Contatti

Via Melchiorre Gioia, 168 - 20125 Milano

info@sgbox.it

+39 02 60830172

LM - Log Management

Custom Report

Custom reports are used to filter search results and extract information from different classes.To create a Custom report go to LM > Custom Report, this page open the list of existing reports but you can also create a new one. Requirements: SGBox version 6.0.0 Main Page The main page displays information about the Custom Reports, […]

Rules

LCE Rules

LCE → Rules 📝 Add and modify new rule This page allows you to create and edit a rule. A correlation rule is used to alert the admin when an event, or a series of events, occur in a specified time range. ✔️ Requirements: A mail server must be configured. Check the Configure a Mail […]

6.0

6.0.7

6.0.7 A new version of SGBox that improve features and performance has been released New LCE module interface 6.0.7 version of the collector Correction and improvement of various modules SGBOX > SCM > Applications > SGBox Updates

Client Configuration

Cato Network – SGBox SIEM Integration Guide

Cato Network – SGBox SIEM Integration Guide This Guide explains how to configure SGBox to make API calls to Cato Network with the purpose of collecting events in SGBox SIEM related to Network and IDS/IPS activities managed by CATO. To complete the tasks outlined in this guide, you’ll need the following: Create an API key […]

Collector

The SGBox Collector (v6)

  The collector is a virtual appliance based on the Linux operating system, and is responsible for performing certain tasks of SGBox, such as collecting logs from local data sources and sending them to SGBox, via HTTPS (port 443) by establishing an encrypted channel. In addition the collector offers caching capabilities if the communication between […]

Report Catalog

Custom Report – Detailed

Custom Report – Detailed In this section you can create report in PDF starting from Custom Report previously configured.From RS > Report Catalog, select  Custom Report – Detailed.  Click on printer icon select timerange and custom report you want use.The generated report will be shown and stored in RS > Report archive. You can personalize […]

Analysis

Historical Search

Historical Search This section is used to analyze logs coming from each data source. You can see them in:  LM > Analysis > Historical Search.  Logs are stored in a database, when you need to search logs  and you can use operator like “AND”, “OR” and “NOT” to filter the search results. You can choose […]

Network Appliance

SIEM solutions integration with Apex Central

Syslog Configuration on Apex Configure Syslog Settings For Apex Central On-premise Configure Syslog Settings Apex SaaS Configure Syslog Settings For Apex Central On-premise In order to send logs to SGBox you need to modify first you syslog settings: Go to Detections > Notifications > Notification Method Settings. The Notification Method Settings screen will appear. In […]

Network Appliance

Syslog configuration on Sangfor

Syslog configuration on Sangfor Cyber Command Endpoint Secure Cyber Command In order configure Cyber Command to send logs to SGBox you need to: Login to your Cyber Command console.Go to System > Third-Party Platforms section, click on “add” and complete the fields. Choose Platform name (eg. SGBox) Enter SGBox IP address Enter Reported asset (suggested […]

6.0

6.0.6

6.0.6 A new version of SGBox that improve features and performance has been released Internal report added Collector v6 updates Lista Elementi SGBOX > SCM > Applications > SGBox Updates