Use https://seceonhelp.freshdesk.com/support/login to access updated Knowledge Base Articles, Submit Technical Support Tickets and Review Status of submitted support tickets.
Device Configuration: PIM Arcon
Overview
We are providing you with the steps to integrate your PIM Arcon with Seceon SIEM so One can have Comprehensive visibility and Proactive Threat Detection in your Environment. There will be a log transfer between your firewall to APE(Analytics and Policy Engine) via CCE (Collection and Control Engine ).
Steps Of Configuration
Step 1. Navigate to Provisioning by clicking on the Provisioning tab located in the top menu bar of the application.
Step 2. Drop down Add on devices by clicking on the downward-facing arrow next to the 'Add on devices' option in the menu.
To add support for PIM Arcon, please follow the steps below:
Device: Select 'PIM Arcon' as the device name.
Name: Choose any name you like.
CCE Host: Enter the IP address of the CCE.
If via API -
Access ID/username: Enter the username for the Arcon.
Password/Secret Key: Enter the password for the Arcon.
Enter the following JSON format in the last field the Arcon Host (without https://):
{"host": "arcon_host"}
Via SQL Database
Access ID/username: Enter the username for the Database User.
Password/Secret Key: Enter the password for the Database Pass.
Enter the following JSON format in the last field the Arcon Database Details:
{"pimarcon_host": "database_host", "pimarcon_port": "database_port", "pimarcon_databasename": "database_name", "pimarcon_tablename": "database_table_name"}
Click the Save button."
Verification
STEP 1:Log in to UI >> SYSTEM
STEP 2: >> Logs and flows collection status
STEP 3: >>To verify the source device IP from the UI:
Log in to the user interface
Navigate to the "SYSTEM" section
Look for the "SOURCE DEVICE IP"
Check the IP address that is displayed
Compare the IP address displayed against the expected source device IP
This will allow you to ensure that the system is properly identifying the source device IP and that it matches the expected IP address..
Seceon Inc. All rights reserved. https://www.seceon.com