Data Infrastructure & Analytics
Integrating Network Analytics Logs with your SIEM dashboard

Integrating Network Analytics Logs with your SIEM dashboard

5/17/2022 · Omer Yoachimik, Kyle Bowman

What this post added

Introduces Network Analytics Logs for Magic Transit, Magic Firewall, and Spectrum customers on the Enterprise plan. These logs provide packet samples of traffic dropped and passed by specific mitigation systems, enabling near real-time visibility into network traffic and DDoS attacks. The post details how to set up Logpush jobs to feed these logs into SIEM systems like Splunk, including API token creation, Splunk HEC setup, and the Logpush job configuration. It also highlights the cost-saving benefits of storing logs in R2.

Read the original post ↗