Configuring Lastline Enterprise to Communicate with JSA
On the Lastline Enterprise system, use the SIEM settings in the notification interface to specify a SIEM appliance where Lastline can send events.
- Log in to your Lastline Enterprise system.
- On the sidebar, click Admin.
- Click >Reporting > Notifications.
- To add a notification, click the Add a notification (+) icon.
- From the Notification Type list, select SIEM.
- In the SIEM Server Settings pane, configure the parameters for your JSA Console or Event Collector. Ensure that you select LEEF from the SIEM Log Format list.
- Configure the triggers for the notification:
To edit existing triggers in the list, click the Edit trigger icon, edit the parameters, and click Update Trigger.
To add a trigger to the list, click the Add Trigger (+) icon, configure the parameters, and click Add Trigger.
- Click Save.