Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
| Attribute | Value |
|---|---|
| Publisher | Community |
| Support Tier | Community |
| Support Link | https://github.com/Azure/Azure-Sentinel/issues |
| Categories | domains |
| Version | 3.0.2 |
| Author | Forcepoint |
| First Published | 2022-05-25 |
| Solution Folder | Forcepoint NGFW |
| Marketplace | Azure Marketplace · Popularity: ⚪ Very Low (8%) |
| Pre-requisites | Common Event Format |
The Forcepoint NGFW (Next Generation Firewall) Solution for Microsoft Sentinel allows you to automatically export user defined Forcepoint NGFW logs into Microsoft Sentinel in real-time. This enriches visibility into user activities recorded by NGFW, enables further correlation with data from Azure workloads and other feeds, and improves monitoring capability with Workbooks inside Microsoft Sentinel.
For more details about this solution refer to integration documentation
This solution is dependent on the Common Event Format solution containing the CEF via AMA connector to collect the logs. The CEF solution will be installed as part of this solution installation.
NOTE: Microsoft recommends installation of CEF via AMA Connector. The existing connectors were deprecated on Aug 31, 2024.
This solution depends on 1 other solution(s):
| Solution |
|---|
| Common Event Format |
This solution has 2 discovered data connector(s)⚠️ (not in Solution definition):
Connectors from dependency solutions:
🔍 Discovered: This item was discovered by scanning the solution folder but is not listed in the Solution JSON file.
This solution uses 4 table(s):
| Table | Used By Connectors | Used By Content |
|---|---|---|
CommonSecurityLog |
Common Event Format (CEF) (dependency), Common Event Format (CEF) via AMA (dependency), [Deprecated] Forcepoint NGFW via AMA, [Deprecated] Forcepoint NGFW via Legacy Agent | Workbooks |
Heartbeat |
- | Workbooks |
Perf |
- | Workbooks |
ThreatIntelligenceIndicator |
- | Workbooks |
This solution includes 2 content item(s):
| Content Type | Count |
|---|---|
| Workbooks | 2 |
| Name | Tables Used |
|---|---|
| ForcepointNGFW | CommonSecurityLog |
| ForcepointNGFWAdvanced | CommonSecurityLogHeartbeatPerfThreatIntelligenceIndicator |
| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.0.2 | 19-11-2024 | Removed Deprecated Data Connectors |
| 3.0.1 | 15-07-2024 | Deprecating data connectors |
| 3.0.0 | 29-08-2023 | Addition of new Forcepoint NGFW AMA Data Connector |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊