FireEye HX (v2.4.10)
FireEye Endpoint Security is an integrated solution that detects and protects endpoints against known and unknown threats. The FireEye HX Cortex XSOAR integration provides access to information about endpoints, acquisitions, alerts, indicators, and containment. Customers can extract critical data and effectively operate the security operations automated playbooks.
- Author
- Cortex XSOAR
- Support
- xsoar
- URL
- https://www.paloaltonetworks.com/cortex
- Default data source
- FireEye HX Event Collector
- Categories
- Endpoint
Incident fields (2)
- FireEye HX Agent Containment State
- FireEye HX Event Info
Integrations (3)
- FireEye HX (Deprecated)
- FireEye HX Event Collector
- FireEye Endpoint Security (HX) v2
Modeling rules (1)
- FireEye HX Modeling Rule
Parsing rules (1)
- FireEye HX Parsing Rule
Playbooks (6)
- FireEye HX - Execution Flow Indicators Hunting
- FireEye HX - File Indicators Hunting
- FireEye HX - Indicators Hunting
- FireEye HX - Isolate Endpoint
- FireEye HX - Traffic Indicators Hunting
- FireEye HX - Unisolate Endpoint
README
<~XSIAM>
FireEye HX
This pack includes Cortex XSIAM content.
Configuration on Server Side
Raw syslog audit messages
In order to configure FireEye HX to send syslog audit logs, refer to FireEye HX Endpoint Security Server System Administration Guide (Configuring a Syslog Server Using the CLI).
Make sure to configure the syslog timestamp format to be RFC-3339 UTC.
CEF format logs
In order to configure FireEye HX to send CEF logs, refer to FireEye HX Endpoint Security Server System Administration Guide.
For further assistant, contact the tech support of FireEye HX.
Collect Events from Vendor
In order to use the collector, use the Broker VM option.
Broker VM
To create or configure the Broker VM, use the information described here.
You can configure the specific vendor and product for this instance.
- Navigate to Settings > Configuration > Data Broker > Broker VMs.
- Go to the apps tab and add the Syslog app. If it already exists, click the Syslog app and then click Configure.
- Click Add New.
- When configuring the Syslog Collector, set the following values:
- vendor as fireeye
- product as hx_audit
- format as Auto-Detect
- protocol as UDP
</~XSIAM>