Proteggiamo il tuo ambiente digitale da qualsiasi attacco informatico. Sfrutta tutte le potenzialità della piattaforma SGBox!

Gallery

Contatti

Via Melchiorre Gioia, 168 - 20125 Milano

info@sgbox.it

+39 02 60830172

Linux

Rsyslog strict connection

Install the rsyslog-gnutls packge. In Ubuntu/Debian: apt install rsyslog-gnutls Add the following lines in the rsyslog file. In Ubuntu/Debian: /etc/rsyslog.d/50-default.conf or /etc/rsyslog.conf $DefaultNetStreamDriverCAFile /root/certs/chain_bundle.crt $DefaultNetStreamDriver gtls $ActionSendStreamDriverMode 1 # run driver in TLS-only mode $ActionSendStreamDriverAuthMode anon *.* @@sgbox192.sgbox.it:6514 Restart the rsyslog service: service rsyslog restart

Actions

Upload SGBox custom certificate

SGBox custom certificate Starting from version 5.3.0 it’s possible to substitute the self-signed and upload a custom certificate. Requirements: SGBox version 5.3.0 From the web interface go to: SCM > Action > Upload custom certificate Select the Certificate, private key and the chain certificate if present. You can also specify the name of your web […]

1 - Playbooks Base

Playbooks – Base settings

PLAYBOOKS A playbook is used to perform a series of actions among the available ones, preserving the state and processing the result on each subsequent action. Starting from version 5.4.1, playbooks can be used in combination with list feeds and to retrieve logs from any external API. To associate a playbook with a list feed, […]

Network Appliance

Syslog configuration on Cisco devices

Syslog configuration on Cisco devices This article explain how to configure Cisco devices to send log to SGBox using syslog protocol. All the following command has been taken from this website: https://www.ciscopress.com/articles/article.asp?p=426638&seqNum=3 Log in to your device using a terminal link program (eg. Putty) and run the following command: Cisco Switches Console> (enable) set logging […]

Dashboards

Manage Dashboards

Create a Dashboard Dashboards are used to display important items to the administrator as soon as you have logged in to SGBox. They can be configured differently so that each user puts information on his dashboard that is relevant to him/her. To create a new dashboard, connect to the web interface of SGBox. SGBox > […]

Threat Intelligence Queries

Threat Intelligence Queries

Configure Threat Intelligence Queries This article explain how to create a Threat Intelligence Query, that allows you to obtain simply the process of an Events Query to search a value in the list and take an action. In this way, queries can be used like LCE rules or sensors. Can be scheduled to run every minute […]

Sensors

Replace a Sensor with Events Queries

Events Queries as a Sensor In version 5.3.0 we introduce the Events Queries, the new mechanism to search events and produce alerts. (see this section).In this article we explain how to replace a sensor with an events query, in order to have more flexibility and use less SGBox resources. Requirements: SGBox version 5.3.0 Pattern must […]

Network Appliance

Syslog Configuration on Kaspersky

Syslog configuration on Kaspersky This article explain how to configure Kaspersky to send log to SGBox using CEF protocol. Requirements SGBox 5.2.2 Valid Kaspersky license for export CEF/LEEF logs Click here. Log in to your Kaspersky Security Center console, from Administration Server select Events. Select Configure notification and event export and select the Siem configuration […]

Multi Tenant

Access to remote SGBox

Access to remote SGBox This feature is used when a customer has his own SGBox on premise and a service provider wants monitor customer’s events and incidents in order to alert him.This feature is used when a customer doesn’t want send logs out of his company. Requirements SGBox 5.0.3 or higher. First of all you […]