The Communications Broker Sender (Comm Broker) can send and receive third-party syslog and JSON formatted logs to Helix Enterprise for analysis.
Comm Broker functionality requires that Evidence Collector be enabled, so you must configure Evidence Collector with the Helix URL and certificate before starting Comm Broker. For details about how to enable Evidence Collector, see Enabling or disabling the Evidence Collector module using the Web UI on page 1 or Enabling or disabling the Evidence Collector module using the CLI.
Comm Broker can be configured with a transport protocol (UDP, TCP, or SSL) and a port (range 514 - 65355). You must configure the protocol and port before Comm Broker is enabled. Note that you should configure TCP as the protocol for better performance. For Helix Enterprise to analyze JSON data, you must configure the Comm Broker to send and receive third-party syslog and JSON formatted logs from different ports. For example, port 514 for syslog events and port 516 for JSON events.
Comm Broker can listen on the specified port and can directly access the IP address of the dedicated Helix Virtual Private Cloud (VPC) on a specific port.
Either Comm Broker or Evidence Collector can be disabled, but not both. The interactions of the possible Evidence Collector and Comm Broker configurations are listed below.
Configuration | Interaction |
|---|---|
Default configuration | Both Evidence Collector and Comm Broker are disabled. |
Only Evidence Collector is enabled | Evidence Collector is functional. |
Only Comm Broker is enabled | Comm Broker is functional |
Evidence Collector is already enabled when Comm Broker is enabled | The nxlog process is restarted and both Evidence Collector and Comm Broker are functional |
Evidence Collector and Comm Broker are both enabled, and then Comm Broker is disabled | Comm Broker functionality stops and the nxlog process is restarted. Evidence Collector remains functional. |
Evidence Collector and Comm Broker are both enabled, and then Evidence Collector is disabled | The nxlog process is stopped and the Comm Broker context remains enabled, but Evidence Collector functionality stops and Comm Broker remains functional. |
Evidence Collector only is running and is then disabled | Evidence Collector functionality stops. |
Prerequisites
Administrator or Operator access to the Network Security appliance
A connection to the Dynamic Threat Intelligence (DTI) Cloud
An active subscription to Helix
Configure a valid hostname for the VPC within an AWS endpoint (Helix Enterprise URL)
Note
To run the Evidence Collector module for Helix Enterprise, you must configure the Virtual Private Cloud (VPC) within an Amazon Web Services (AWS) endpoint on the Network Security appliance, see Configuring the VPC Within an AWS endpoint using the Web UI on page 1 or Configuring the VPC within an AWS endpoint using the CLI.
You are not required to configure the VPC if you are sending only Layer 7 metadata events to the Splunk Enterprise server.