Add a third-party integration, such as ServiceNow or Splunk, for Secure Access push security events.
You can add a Third-party Integration in Secure Access to enable Push Security Events for a third-party product or service.
Push Security Events are logged by Secure Access when end users request destinations that are associated with Security categories or other security criteria. Security categories that trigger security events are Command and Control, Malware, and Phishing.
A Secure Access Third-party Integration for Push Security Events requires a Secure Access Webhook configured with the URL of the third-party HTTP listener and authentication credentials.
To get started, set up your Third-party Integration for Push Security Events with a Secure Access Webhook. Configure the Secure Access Webhook to send the security events to a destination URL for an HTTP target service. Select the type of security events that the Webhook will send to the HTTP listener.
Administrators of the third-party product or service are responsible for deploying the HTTP listener in the organization's on-premises or cloud environment.
Push Security Events are available for various types of network and security activities:
-
DNS activity
-
HTTP activity
-
Other types of activity:
-
Firewall
-
Intrusion Prevention System (IPS)
-
Data Loss Prevention (DLP)
-
Zero Trust Network Access (ZTNA) with a blocked reason
-
Remote Access Virtual Private Network (RAVPN) with a failed reason
-
Benefits of Integrating Secure Access Push Security Events with Third-Party Security and Information Systems
-
Administrators can configure Secure Access to send Push Security Events to an XDR or Security Information and Event Management (SIEM) system.
-
Third-party integrations enable an organization's Security Operations Centers (SOCs) to have visibility into risky activity.
-
Third-party integrations provide administrators with the capability to trigger automation and incident response and correlation workflows.
-
Assist organizations to identify potential security threats.
Guidelines and Limitations
-
Secure Access supports three (3) third-party integrations of Push Security Events in an organization.
-
Secure Access sends all Push Security Events in batches formatted with the Cloud events schema or Splunk schema.
-
Secure Access sends up to ten security events in each Webhook message.
-
Secure Access does not convert numeric or UUID values in the events into names or labels. You can use the Secure Access API to resolve these identifiers.
How to Set Up a Third-Party Integration for Push Security Events
-
Deploy an HTTP listener in your on-premises or cloud environment. Ensure that the target system can receive HTTP POST messages from Secure Access. The target system must support Basic authentication with a username and password.
-
Add a Webhook in Secure Access as a Third-party integration. Configure the Webhook with the URL and Basic authentication credentials of the HTTP listener.
-
Add a Third-party integration for Push Security Events in Secure Access.
-
Validate that your target system receives Secure Access Push Security Events.