Skip to main content

How to Integrate ESET Protect

This guide will walk you through how to get ESET Protect logging to Defense.com's SIEM via your on premises collector

Written by Kara Crimson

The ESET Protect integration is available on our Enterprise and Advanced packages.

Before you get started

This integration requires us to configure a collector on the edge of our network to receive log data directly from ESET Protect via Syslog. Before you get started, please reach out to our Technical Support team and make them aware that you're planning on setting up this integration.

They will then deploy the collector required for this and provide you with the host address, port, and TLS certificates mentioned later in this guide. The certificates will come as an attachment on the support ticket.

Configuring ESET Protect

  1. Log in to the ESET Protect console.

  2. In the left-hand menu, click More > Settings > Syslog.

  3. Click the toggle next to Enable Syslog sending to turn it on.

  4. Configure the following settings:

    1. Format of payload — Select JSON.

    2. Format of envelope — Select Syslog.

    3. Minimal log level — Select Information.

    4. Event types to log — Select the event types you'd like to send. We recommend enabling at minimum: Antivirus, Firewall, HIPS, Web protection, and Audit Log.

    5. Destination IP or FQDN — Enter the host address provided by the Defense.com Technical Support team.

    6. Port — Enter the port number provided by the Defense.com Technical Support team.

  5. Enable Validate CA Root certificates of TLS connections by clicking the toggle.

  6. In the certificate field that appears, paste the full certificate chain from the ca.crt file provided via the support ticket.

  7. Click Apply settings.

Once you have completed the configuration steps, please let us know via the ticket so we can confirm that ESET Protect is logging.

And that's it! You've successfully integrated ESET Protect🎉

Did this answer your question?