Skip to main content

How to Integrate Forcepoint

In this guide, we'll walk you through the process of integrating Forcepoint with the Defense.com SIEM platform.

Kara Crimson avatar
Written by Kara Crimson
Updated over a week ago

This integration is available on our Advanced and Enterprise packages.

Before you get started

Before beginning the integration, you will need to deploy a log collector within the same network as your firewall.

To initiate the collector deployment process, please reach out to our Technical Support team, who'll provide you with a deployment pack that includes all the software and scripts needed to configure this.

If you already have a log collector deployed, please follow the steps outlined below

Configuring syslog

  1. Login to the Web Security module of the Forcepoint Security Manager.

  2. Go to Settings > General > SIEM Integration.

  3. Under Internet Activity Log Data:

    1. Select Add, which will open a new window to configure the SIEM integration.

    2. Or select Enable SIEM integration for Internet activity log data for this Policy Server if there is no Add option.

  4. Configure the SIEM integration in the new window:

    1. Under IP Address or Hostname add the IP address of your log collector.

    2. Under Port enter 5514.

    3. Under Transport Protocol, select UDP.

    4. Under SIEM format, select Syslog.

    5. Click OK.

    6. Click Save and Deploy to save your changes.

Confirming log flow

Once the above steps are complete, your device will now ship logs to our SIEM platform via your collector. You can confirm logs are successfully reaching our SIEM by either.

  1. Navigating to the Log Search feature in Defense.com by browsing to SIEM > Log Search and then filtering the logs by type:"syslog".

  2. Reaching out to our Technical Support team, who'll be able to check and confirm this for you.

And that's it! You've successfully integrated Forcepoint🎉


Did this answer your question?