TEAM: Huntress Managed Security Information and Event Management (SIEM)
PRODUCT: HTTP Event Collector (HEC)
ENVIRONMENT: ScoutDNS
SUMMARY: Configuration Guide for ScoutDNS. With this guide you can use Huntress to ingest SIEM data directly from Scout DNS, bypassing the need to use Splunk or another 3rd party tool.
Vendor Information
| Vendor | ScoutDNS |
| Support Model Name/Number | N/A |
| Supported Software Version(s) | N/A |
| Collection Method | HTTP Event Collector |
| Provider Name | ScoutDNS |
| Additional Information | ScoutDNS SIEM data export |
Configuration Checklist
Prerequisites:
- You must have a ScoutDNS license type for SIEM Export.
- Admin or Super Admin role in ScoutDNS is required.
- You must have Account Admin access in your Huntress portal.
- You must have an active SIEM subscription or trial.
Getting Started:
Read the notes below and then refer the great guide ScoutDNS created for integrating with Huntress SIEM.
- When selecting the destination stream endpoint Type in ScoutDNS, select the "Huntress" option.
- For step 1 under "Configure Huntress SIEM export" select "ScoutDNS" as the source instead of "Generic HEC".