Infoblox DNS¶
Infoblox delivers essential technology to enable customers to manage, control and optimize DNS, DHCP, and IPAM. Chronicle has the ability to ingest Infoblox log information and stitch together data for assets based on hostname and/or IP address. This section will cover how to configure syslog settings on Infoblox to point to an external syslog server. These instructions will push the syslog configuration for the Grid Wide level.
Chronicle Data Types¶
- INFOBLOX
- INFOBLOX_DNS
- INFOBLOX_DHCP
Configuration¶
- From the Grid tab, Grid > Grid Manager > Members
- Click Grid Properties > Edit in the right hand Toolbar
- Select the Monitoring tab
- Check the Log to External Syslog Servers box
- Click the + icon of the External Syslog Servers table
-
Enter the following information for the external syslog server:
Setting Value Address IP address of CYCLOPS appliance Transport TCP Interface Any Node ID IP and Host Name Source Any Severity info Port Port provided by Cyderes Logging Category Send all Copy Audit Log Messages to Syslog Select this option Syslog Facility Take default value provided -
Select Save & Close to save the configuration
- Click Restart if it appears at the top of the screen