Learn more about collecting Forcepoint DLP logs using a Syslog Collector applet and content pack integration in Cortex Cloud.
You can configure collecting Corelight Zeek logs using a Broker VM Syslog Collector applet or with a content pack integration:
Forcepoint DLP vendor | Description |
|---|---|
Syslog Collector applet overview | If you use Forcepoint DLP to prevent data loss over endpoint channels, you can forward logs to Cortex Cloud using the Broker VM Syslog Collector applet in a CEF or LEEF format. |
Link to Syslog Collector applet instructions | |
Link to content pack/integration details | The Forcepoint DLP content pack fetches security incidents from Forcepoint DLP and ingests them as events into Cortex Cloud for processing and analysis. contains the
|