TEAM: Huntress Managed Security Information and Event Management (SIEM)
PRODUCT: HTTP Event Collector (HEC) Syslog
ENVIRONMENT: DNSFilter
SUMMARY: Configuration Guide for DNSFilter
Vendor Information
Vendor |
DNSFilter |
---|---|
Supported Model Name/Number |
N/A |
Supported Software Version(s) |
N/A |
Collection Method |
HTTP Event Collector |
Provider Name |
DNSFilter |
Additional Information |
https://help.dnsfilter.com/hc/en-us/articles/6266552356499-Data-Export-configuration |
You must be an Account Administrator in Huntress in order to follow the steps below.
If the options don't appear available to you, please confirm you have the appropriate DNSFilter licensing.
Configuration Checklist
-
Create Token
-
Open Huntress Portal
- Click SIEM on the left navigation menu
- Click Source Management
- Click Add Source
- Click DNSFilter
- Click Add
- Provide a name for the Integration and an optional description.
- Click Save
- Copy the HTTP Event Collector Token value
-
- Configure Integration in DNSFilter
-
-
- Log into DNSFilter Admin Console
- If you have multiple organizations, select the Organization you want to configure for logging to Huntress SIEM.
- Click Integrations
- Click HTTP Event Collector
- If you have no existing integrations, you will want to click Getting Started, then choose HTTP Event Collector
- In the HTTP Event Collector URL field, enter https://hec.huntress.io/services/collector
- In the Active Event Collector Token, paste the value from step 9 in the previous step.
- Click "Verify & Test Account"
- Once successful, click "Finalize"
- Log into DNSFilter Admin Console
-
-