CloudPassage Halo
Integration points
Protocol | Information collected | Used for |
---|---|---|
CloudPassage REST API | Halo events – over 110 event types including User login and account activity, server compliance and vulnerability status, server FIM and firewall policy modification etc. | Security and Compliance |
FortiSIEM can pull logs from CloudPassage Halo via CloudPassage REST API. Currently, over 110 CloudPassage event types are parsed.
To see the event types:
- Login to FortiSIEM.
- Go to ADMIN > Resources > Event Types.
- Search for 'CloudPassage-Halo'.
Use cases covered via API:
- User login to Halo and user account creation/deletion/modification activity
- Vulnerable software package found and Compromised host detection
- Server FIM, Firewall policy modification
- Server account creation
- Server login via ghostport
Configuring CloudPassage Portal
Create an API Key to be used for FortiSIEM communication.
- Log in to your CloudPassage Halo portal.
- Create an API Key and API Secret for use in FortiSIEM.
Configuring FortiSIEM
Use the API Key and Secret in previous step to enable FortiSIEM access.
- Login to FortiSIEM.
- Go to ADMIN > Setup > Credential.
- Click New to create a CloudPassage Halo credential.
- Choose Device Type = CloudPassage Halo (Vendor = CloudPassage, Model = Halo).
- Choose Access Protocol = Halo REST API.
- Choose Pull Interval = 5 minutes.
- Password Configuration: for CyberArk and RAX_CustomerService, see Password Configuration. For Manual, see the following:
- Set API Key ID to API Key obtained from CloudPassage portal in Configuring CloudPassage Portal.
- Set API Key Secret to API Secret obtained from from CloudPassage portal in Configuring CloudPassage Portal.
- Choose the Organization if it is an MSP deployment and the same credential is to be used for multiple customers.
- Click Save.
- Enter an IP range to Credential Association.
- Set Hostname = api.cloudpassage.com
- Select the credential created in step 3.
- Click Save.
- Select the entry in step 4 and click Test Connectivity. Once successful, an entry will be created in ADMIN > Setup > Pull Events. FortiSIEM will start to pull events from CloudPassage portal using the API.
To test for received CloudPassage Halo events:
- Go to ADMIN > Setup > Pull Events.
- Select the CloudPassage entry and click Report.
The system will take you to the Analytics tab and run a query to display the events received from CloudPassage in the last 15 minutes. You can modify the time interval to get more events.