@@ -124,31 +124,31 @@ Follow the steps below to configure the Infoblox CDC to send BloxOne data to Mic
124
124
1 . Navigate to ** Manage > Data Connector** .
125
125
1 . Click the ** Destination Configuration** tab at the top.
126
126
1 . Click ** Create > Syslog** .
127
- - ** Name** : Give the new Destination a meaningful ** name** , such as ** Microsoft-Sentinel-Destination** .
128
- - ** Description** : Optionally give it a meaningful ** description** .
129
- - ** State** : Set the state to ** Enabled** .
130
- - ** Format** : Set the format to ** CEF** .
131
- - ** FQDN/IP** : Enter the IP address of the Linux device on which the Linux agent is installed.
132
- - ** Port** : Leave the port number at ** 514** .
133
- - ** Protocol** : Select desired protocol and CA certificate if applicable.
134
- - Click ** Save & Close** .
127
+ - ** Name** : Give the new Destination a meaningful ** name** , such as ** Microsoft-Sentinel-Destination** .
128
+ - ** Description** : Optionally give it a meaningful ** description** .
129
+ - ** State** : Set the state to ** Enabled** .
130
+ - ** Format** : Set the format to ** CEF** .
131
+ - ** FQDN/IP** : Enter the IP address of the Linux device on which the Linux agent is installed.
132
+ - ** Port** : Leave the port number at ** 514** .
133
+ - ** Protocol** : Select desired protocol and CA certificate if applicable.
134
+ - Click ** Save & Close** .
135
135
1 . Click the ** Traffic Flow Configuration** tab at the top.
136
136
1 . Click ** Create** .
137
- - ** Name** : Give the new Traffic Flow a meaningful ** name** , such as ** Microsoft-Sentinel-Flow** .
138
- - ** Description** : Optionally give it a meaningful ** description** .
139
- - ** State** : Set the state to ** Enabled** .
140
- - Expand the ** CDC Enabled Host** section.
137
+ - ** Name** : Give the new Traffic Flow a meaningful ** name** , such as ** Microsoft-Sentinel-Flow** .
138
+ - ** Description** : Optionally give it a meaningful ** description** .
139
+ - ** State** : Set the state to ** Enabled** .
140
+ - Expand the ** CDC Enabled Host** section.
141
141
- ** On-Prem Host** : Select your desired on-premises host for which the Data Connector service is enabled.
142
- - Expand the ** Source Configuration** section.
142
+ - Expand the ** Source Configuration** section.
143
143
- ** Source** : Select ** BloxOne Cloud Source** .
144
144
- Select all desired ** log types** you wish to collect. Currently supported log types are:
145
145
- Threat Defense Query/Response Log
146
146
- Threat Defense Threat Feeds Hits Log
147
147
- DDI Query/Response Log
148
148
- DDI DHCP Lease Log
149
- - Expand the ** Destination Configuration** section.
149
+ - Expand the ** Destination Configuration** section.
150
150
- Select the ** Destination** you just created.
151
- - Click ** Save & Close** .
151
+ - Click ** Save & Close** .
152
152
1 . Allow the configuration some time to activate.
153
153
154
154
3 . Validate connection
0 commit comments