Huawei workbook template for MS Sentinel

%3CLINGO-SUB%20id%3D%22lingo-sub-3531837%22%20slang%3D%22en-US%22%3EHuawei%20workbook%20template%20for%20MS%20Sentinel%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3531837%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20all%2C%3C%2FP%3E%3CP%3Edoes%20anyone%20know%20if%20there%20is%20a%20template%20to%20connect%20and%20manage%20Huawei%20routers%20logs%20into%20MS%20Sentinel%3F%3C%2FP%3E%3CP%3EI%20don't%20find%20anything%20in%20the%20official%20templates%20and%20in%20github.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMany%20thanks.%3C%2FP%3E%3CP%3ERaffaele%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-3531837%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EData%20Collection%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ELog%20Data%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESIEM%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWorkbooks%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3532519%22%20slang%3D%22en-US%22%3ERe%3A%20Huawei%20workbook%20template%20for%20MS%20Sentinel%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3532519%22%20slang%3D%22en-US%22%3EIt%20maybe%20device%20specific%2C%20but%20most%20routers%20will%20support%20syslog%2C%20enable%20sending%20of%20the%20logs%20to%20a%20syslog%20server%20and%20collect%20it%20into%20Sentinel%20using%20the%20built-in%20Syslog%20connector.%20You%20maybe%20able%20to%20use%20an%20api%20as%20well%2C%20but%20again%20that%20will%20depend%20on%20the%20device%2Fmodel%20etc...%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fsupport.huawei.com%2Fenterprise%2Fen%2Fdoc%2FEDOC1000174065%2F755f5e2%2Fdoes-the-device-support-log-dumping-to-a-third-party-gateway%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsupport.huawei.com%2Fenterprise%2Fen%2Fdoc%2FEDOC1000174065%2F755f5e2%2Fdoes-the-device-support-log-dumping-to-a-third-party-gateway%3C%2FA%3E%3C%2FLINGO-BODY%3E
New Contributor

Hi all,

does anyone know if there is a template to connect and manage Huawei routers logs into MS Sentinel?

I don't find anything in the official templates and in github.

 

Many thanks.

Raffaele

1 Reply
It maybe device specific, but most routers will support syslog, enable sending of the logs to a syslog server and collect it into Sentinel using the built-in Syslog connector. You maybe able to use an api as well, but again that will depend on the device/model etc...

https://support.huawei.com/enterprise/en/doc/EDOC1000174065/755f5e2/does-the-device-support-log-dump...