Forcepoint SWG collector
Overview
Forcepoint secure web gateway services are part of Forcepoint ONE, an all-in-one, cloud-native security platform. Forcepoint ONE SWG enables users to securely access any website or download any document while still enjoying the speed and performance required to stay competitive.
Devo collector features
Feature | Details |
---|---|
Allow parallel downloading ( |
|
Running environments |
|
Populated Devo events |
|
Flattening preprocessing |
|
Data sources
Data source | Description | API endpoint | Collector service name | Devo table | Available from release |
| Logs generated from general web traffic from users using the SmartEdge agent, pulls logs from the Analyze > Logs > Web dashboard page. |
|
|
| v1.0.0 |
| Logs generated by application activity as seen on the Analyze > Logs > Proxy dashboard page. |
|
|
| v1.0.0 |
| All admin events within the admin portal as seen on the Analyze > Logs > Admin dashboard page. |
|
|
| v1.0.0 |
| The Health dashboard allows admins to identify if issues that users encounter are brought on by Forcepoint ONE SSE or the backend server |
|
|
| v1.0.0 |
Learn more about these parsers in this article.
Flattening preprocessing
Data source | Collector service | Optional | Flattening details |
swgweb logs |
| yes | not required |
access logs |
| yes | not required |
admin logs |
| yes | not required |
healthproxy logs |
| yes | not required |
Minimum configuration required for basic pulling
Although this collector supports advanced configuration, the fields required to retrieve data with basic configuration are defined below.
This minimum configuration refers exclusively to those specific parameters of this integration. There are more required parameters related to the generic behavior of the collector. Check setting sections for details.
Setting | Details |
---|---|
| The username for authentication. |
| The password for authentication. |
See the Accepted authentication methods section to verify what settings are required based on the desired authentication method.
Accepted authentication methods
Authentication method | username | password |
---|---|---|
Basic auth | REQUIRED | REQUIRED |
API limits, delays, & known Issues
The API has a limit of 300 requests per day per endpoint.
Run the collector
Once the data source is configured, you can either send us the required information if you want us to host and manage the collector for you (Cloud collector), or deploy and host the collector in your own machine using a Docker image (On-premise collector).
Collector services detail
This section is intended to explain how to proceed with specific actions for services.
dpim incident
Collector operations
To check the memory usage of this collector, look for the following log records in the collector which are displayed every 5 minutes by default, always after running the memory-free process.
The used memory is displayed by running processes and the sum of both values will give the total used memory for the collector.
The global pressure of the available memory is displayed in the
global
value.All metrics (Global, RSS, VMS) include the value before freeing and after
previous -> after freeing memory
Change log
Release | Released on | Release type | Details | Recommendations |
---|---|---|---|---|
| Aug 12, 2024 | NEW FEATURE | - | - |