You can enable or disable the Communications Broker Sender (Comm Broker) by using the Network Security appliance Web UI or CLI:
When Comm Broker is enabled, Comm Broker can receive and send third-party logs to Helix Enterprise for analysis on the Network Security appliance. When Comm Broker is disabled, Comm Broker cannot receive and send third-party logs to Helix Enterprise on the appliance.
Note
Comm Broker is disabled by default.
Prerequisites
Administrator or Operator access to the Network Security appliance
A connection to the Dynamic Threat Intelligence (DTI) Cloud
An active subscription to Helix
Configure a valid hostname for the VPC within an AWS endpoint ( Helix Enterprise URL)
Note
To run the Evidence Collector module for Helix Enterprise, you must configure the Virtual Private Cloud (VPC) within an Amazon Web Services (AWS) endpoint on the Network Security appliance. See Configuring the VPC within an AWS endpoint using the Web UI or Configuring the VPC within an AWS endpoint using the CLI.
You are not required to configure the VPC if you are sending only Layer 7 metadata events to the Splunk Enterprise server.
(Optional) Configure the SSL input module for Comm Broker. For details about how to configure the SSL input module, see Adding or deleting the Communications Broker Sender input module using the Web UI or Adding or deleting the Communications Broker Sender input module using the CLI .
(Optional) Import the public certificate and private key for the SSL server and the root CA certificate. For details about how to configure the SSL certificates and private keys, see Importing the SSL Certificates and the private keys for the Communications Broker Sender using the Web UI or Importing the SSL certificates and the private kKeys for the Communications Broker Sender using the CLI .