SV-271070r1107133_rule
V-271070
SRG-APP-000471
DRAG-OT-002120
CAT II
10
1. Configure Servers.
If using Syslog Server:
Create a Syslog server on a third-party device.
The steps may vary depending on the chosen Syslog server software. Refer to 2.3.x Dragos Platform Syslog Integration Guide in the Customer Portal for additional help.
Create a syslog server output in the Dragos UI.
Navigate to Admin >> Integrations.
Click "LAUNCH" in the Syslog section.
Click "ADD NEW SERVER".
Enter third-party server information and click "NEXT".
Input Message Template.
Click "SAVE".
2. Creating System Rules:
Navigate to Notification >> RULES Tab.
Click "NEW RULE".
Fill in Name and Processing Order.
Create two Attributes.
Click "ADD ATTRIBUTE" in the "If ANY of the following" block:
Type = "Notification Type"
Select Operation = "Equals"
Select Value = "System"
Click "ADD ATTRIBUTE" in the "If ANY of the following" block:
Type = "Notification Type"
Select Operation = "Equals"
Select Value = "System failure"
In the "THEN perform the following actions block:
Click "ADD ACTION".
Action = "Send (<your syslog server>)"
Click "SAVE".
1. Check Server Configuration.
If using Syslog Server:
Verify third-party server is used to receive communication-related notifications.
Check for a configured Syslog Server.
In the UI, navigate to Admin >> Integrations.
Click "LAUNCH" in the Syslog section.
If no server is configured or the status is not "Connected", this is a finding.
If no recipient is configured, this is a finding.
2. Check Rules:
Navigate to Notification >> RULES Tab.
Verify a rule exists and has the following:
Action = "Send (<your syslog server>)"
Criteria = "Notification Type Equals System"
"Notification Type Equals System Failure"
If a rule does not exist with the correct Action and Criteria, this is a finding.
V-271070
False
DRAG-OT-002120
1. Check Server Configuration.
If using Syslog Server:
Verify third-party server is used to receive communication-related notifications.
Check for a configured Syslog Server.
In the UI, navigate to Admin >> Integrations.
Click "LAUNCH" in the Syslog section.
If no server is configured or the status is not "Connected", this is a finding.
If no recipient is configured, this is a finding.
2. Check Rules:
Navigate to Notification >> RULES Tab.
Verify a rule exists and has the following:
Action = "Send (<your syslog server>)"
Criteria = "Notification Type Equals System"
"Notification Type Equals System Failure"
If a rule does not exist with the correct Action and Criteria, this is a finding.
M
5675