You can configure the input module for the Communications Broker Sender (Comm Broker) by using the Network Security appliance Web UI or CLI:
The Communication Broker Sender (Comm Broker) module can send and receive third-party syslog and JSON formatted logs to Helix Enterprise for analysis.
For Helix Enterprise to analyze both syslog and JSON data at the same time, you must configure the Comm Broker to send and receive third-party logs using a different port, interface or protocol.
Note
The Comm Broker syslog and JSON input types cannot match. For example, the following are valid input modules for the Comm Broker:
commbroker input syslog interface ether1 proto tcp port 514
commbroker input json interface ether1 proto tcp port 516
commbroker input syslog interface ether1 proto tcp port 514
commbroker input json interface ether2 proto tcp port 514When Comm Broker is already enabled and the appliance is upgraded, the nxlog process is restarted. Comm Broker will automatically restart using the syslog configuration input type.
Prerequisites
Administrator or Operator access to the Network Security appliance
A connection to the Dynamic Threat Intelligence (DTI) Cloud
An active subscription to Helix
Configure a valid hostname for the VPC within an AWS endpoint ( Helix Enterprise URL)
Note
To run the Evidence Collector module for Helix Enterprise, you must configure the Virtual Private Cloud (VPC) within an Amazon Web Services (AWS) endpoint on the Network Security appliance, see Configuring the VPC within an AWS endpoint using the Web UI or Configuring the VPC within an AWS endpoint using the CLI.
You are not required to configure the VPC if you are sending only Layer 7 metadata events to the Splunk Enterprise server.