Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Forcepoint CSG data connectors won't open for configuration #11749

Open
HeatonJL opened this issue Jan 31, 2025 · 10 comments
Open

Forcepoint CSG data connectors won't open for configuration #11749

HeatonJL opened this issue Jan 31, 2025 · 10 comments
Assignees
Labels
Connector Connector specialty review needed

Comments

@HeatonJL
Copy link

A few months ago, I was able to get into the configuration section for the Forcepoint CSG via AMA. Today, If I check the box, and click Open connector page, nothing happens, it just sits there.

@v-sudkharat v-sudkharat added the Connector Connector specialty review needed label Feb 3, 2025
@v-mabrindha
Copy link

@HeatonJL, Thanks for reporting this issue, we are checking on it with team and get back to you with some update. Thanks!

@v-mabrindha
Copy link

v-mabrindha commented Feb 12, 2025

@HeatonJL ,
Could you please share your current version of Force Point CSG.
we have version update of force point from 3.0.0 to 3.0.3
version 3.0.2 - Deprecating data connectors
version 3.0.3 - Removed Deprecated Data Connectors

pls update with latest version 3.0.3 of Force Point CSG.

Thanks.

@HeatonJL
Copy link
Author

HeatonJL commented Feb 12, 2025 via email

@v-mabrindha
Copy link

@HeatonJL , Please check details mentioned below

Forcepoint Cloud Security Gateway (CSG) Solution for Microsoft Sentinel exports web and/or email logs so that custom dashboards can be created using Workbooks to visualize events and insights on activities of Forcepoint Cloud Security Gateway.

For more details about this solution refer to integration documentation.

This solution is dependent on the Common Event Format solution containing the CEF via AMA connector to collect the logs. The CEF solution will be installed as part of this solution installation.

NOTE: Microsoft recommends installation of CEF via AMA Connector. The existing connectors were deprecated on Aug 31, 2024.

@HeatonJL
Copy link
Author

HeatonJL commented Feb 14, 2025 via email

@v-sudkharat
Copy link
Contributor

@HeatonJL, The Forcepoint CSG solution version 3.0.3 required the CEF Data connector, as the existing "[Deprecated] Forcepoint CSG via AMA", has been removed from the solution.
Image

  1. You can use the same CEF solution by running the below script into your environment to configure the CEF logs, which will contains the DeviceVendor == Forcepont CSG
    Image

Once the configuration has been completed, you can filter out the logs by executing the below query :

CommonSecurityLog
|where DeviceVendor =~ 'Forcepoint CSG'

Thanks!

@v-mabrindha
Copy link

@HeatonJL, Waiting for your response on above comment. Thanks!

@HeatonJL
Copy link
Author

HeatonJL commented Feb 20, 2025 via email

@v-mabrindha
Copy link

Hi @HeatonJL ,
Yes, first you need to execute the AMA connector script on a Linux box, so the AMA can forward the Forcepoint logs to Sentinel.
Once that is done, you can check the Forcepoint logs using the query below in the Sentinel workspace. This query will help you filter out the Forcepoint logs, as you have already configured CEF for a different source vendor.
CommonSecurityLog
|where DeviceVendor =~ 'Forcepoint CSG'

@v-mabrindha
Copy link

@HeatonJL, Waiting for your response on above comment. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Connector Connector specialty review needed
Projects
None yet
Development

No branches or pull requests

4 participants