Collect data from the Falcon LogScale Collector

Falcon LogScale Collector to Onum

See the changelog of the Falcon LogScale Collector Listener here.

Overview

The following article outlines a basic data flow from Falcon LogScale Collector to the Onum Falcon LogScale Collector Listener.

Prerequisites

You need to generate your TLS certificates for use in securing the sending of data to Onum. These will be required during the Falcon LogScale Collector Listener configuration and in the Falcon LogScale Collector setup.

Learn how to generate these self-signed certificates in this article.

Falcon LogScale Collector setup

Access your Falcon NG-SIEM instance and follow these steps:

1

In Falcon NG-SIEM, click Data connectors > Data connections from the left menu, then select the Fleet management tab.

2

Choose the required VM in this area and access its configuration.

3

Add the following information:

  • The required token value.

  • The Onum URL, with the following format: distributorURL:port

  • In the TLS section at the end, add the path to the required CA certificate file. Add the file in a directory that the Falcon LogScale Collector can read.

Onum setup

1

In Onum, go to the Listeners area and click New listener. Select the Falcon LogScale Collector Listener from the list.

2

Enter a Name for the Listener. Optionally, add a Description and some Tags to identify the Listener.

3

Then, enter the Port we're going to listen to.

4

In the Authentication section, click the Select an API Key field and select New secret. In the window that appears, give your secret a Name and turn off the Expiration date option. Then, click Add new value and paste the required value from your Falcon LogScale Collector. Click Save when you're done.

5

Now, select the token used to receive in the Token field.

6

In the TLS configuration section, you must enter the required Certificate, Private key and CA Chain. See above how to create them. Once you have them, click New secret in each field and add the corresponding values.

7

Finally, click Create labels. Create any required labels if you need to break down your data and then click Create listener.

Last updated

Was this helpful?