Skip to main content
Skip table of contents

Configure CB Response LEEF

Prerequisites

  • Follow the manufacturer’s instructions for installing CB Response and the CB Event Forwarder.
  • Set the output format for the CB Event Forwarder to LEEF.
  • Have an Agent with syslog Enabled available to collect the CB Response logs.
  • Record the IP address of the LogRhythm Agent.

Configure CB Response for Data Collection

  1. Go to etc/cb/integrations/event-forwarder.
  2. Open cb-event-forwarder.conf.
  3. Update the values for the following settings so that they match the ones shown in the table.

    SettingValue
    tcpout=<IP address of LogRhythm Agent>:514
    udpout=<IP address of LogRhythm Agent>:514
    output_type=tcporudp
    output_format=leef
  4. Restart the event forwarder service by executing service cb-event-forwarder restart.

After you configure the device, you must also configure LogRhythm according to the instructions provided on the overview page of this guide. Only Global Admins or Restricted Admins with elevated View and Manage privileges can take this action.

The name of the log message source is Syslog - CB Response LEEF. In addition, when configuring this log source:

  • For Log Message Processing Mode, select MPE Processing Enabled, Event Forwarding Enabled.
  • For Log Message Processing Engine (MPE) Policy, select LogRhythm Default.
  • On the Flat File Settings tab, enter the following:
    • File Path. <path to log file, including the file name and extension>


JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.