Integrate with Papertrail
In this topic, you will learn how to send Portnox™ Cloud alerts to the Papertrail SIEM solution.
Create a log destination in Papertrail
In this section, you will learn how to create a log destination in Papertrail and get information that is necessary to set up the integration with Portnox™ Cloud.
- Open your Papertrail dashboard in the browser.
-
In the top menu, click on the
option.
-
In the Log Destinations pane, section, click on the Create Log
Destination button to create a new log destination or, if Papertrail created a destination for you
automatically upon first login, click on the Settings button in the tile representing that
destination.
-
In the Destination Settings pane:
-
Back in the Log Destinations window, copy the domain name and the port of your Papertrail log
destination and note them down in a temporary file.
-
Use your operating system commands to obtain the IP addresses that the domain name resolves to.
-
Windows PowerShell (recommended):
Resolve-DnsName domain_name
-
Windows Command Prompt:
nslookup domain_name
-
macOS/Linux:
dig +short domain_name
Then, select one of the IP addresses to use in Portnox Cloud and note it down in a temporary text file.
Note: There is no criteria for the selection of the address, you can simply select it at random, or, if the IP addresses are from different geographical regions, select the one that is closest to you by using third party services or commands. -
Configure Portnox Cloud
In this section, you will learn how to configure Portnox™ Cloud to send alert data to the Papertrail collector.
-
In the Cloud portal top menu, click on the Settings option.
-
In the Cloud portal left-hand menu, click on the
option.
-
Create a new SIEM integration with Papertrail.
- Optional:
To configure the types of alerts sent to your SIEM solution, see the following topic: Portnox Cloud alerts.
Note: To learn more about the content and format of alert messages sent to SIEM solutions, see the following topic: Format and content of alert information for SIEM.
You can also send all of the Portnox Cloud activity log (activities performed by administrators in Portnox Cloud) to your SIEM solution. To do this, go to Activity log switch, and click on the Save button.
, activate the
Result: Papertrail is receiving alerts from Portnox Cloud. You can check it using the Papertrail Events pane.