Document toolboxDocument toolbox

edr.fireeye.alerts

The tag edr.fireeye.alerts identifies log events generated by FireEye Security Solutions.

Sending methods

This technology uses a single tag to support all of the log events generated by FireEye Security Solutions. The tag is simply edr.fireeye.alerts and the associated events are saved in Devo in a table of the same name. For more information, read more about Devo tags.

To set up the sending of FireEye events to your Devo domain:

  1. Set up the Devo relay rule that applies the tag to the FireEye events.

  2. Configure event sending from FireEye to the Devo relay.

Other sending methods

Instead of the Devo relay, you may opt to use tools like NXlogFluentd, or Logstash to collect the alert events, apply the Devo tag, and forward them securely to your Devo cloud. Learn more in Other data collection methods

Here we explain how to send events using the Devo relay.

Step 1: Set up the Devo relay rule

You'll set up a rule on the relay that will apply the correct tag before forwarding the events to Devo in syslog format.

For complete instructions, see the vendor documentation online.

Create a simple rule on your Devo Relay that applies the edr.fireeye.alerts tag to all events arriving on a specified port. In the example below, we use port 13007 but you should use any port that you can dedicate to these events.

  • Source Port → 13007

  • Target Tag → edr.fireeye.alerts

  • Check the Stop processing and Sent without syslog tag checkboxes.

Step 2: Configure event sending in FireEye

In FireEye, set up a notification rsyslog event type that sends the event data in JSON - Concise format. Then add your Devo Relay as a Rsyslog Server indicating the relay's IP address and the port on which you set up the relay rule in Step 1.

At this point, the events should be getting sent to the Devo relay where the correct tag is applied before being securely forwarded to your Devo domain.