Configuring the ForeScout CounterACT Plug-in
Before you configure JSA, you must install a plug-in for your ForeScout CounterACT appliance and configure ForeScout CounterACT to forward syslog events to JSA.
To integrate JSA with ForeScout CounterACT, you must download, install, and configure a plug-in for CounterACT. The plug-in extends ForeScout CounterACT and provides the framework for forwarding LEEF events to JSA.
- From the ForeScout website, download the plug-in for ForeScout CounterACT.
- Log in to your ForeScout CounterACT appliance.
- From the CounterACT Console toolbar, select Options
>Plugins >Install. Select the location of the plug-in file.
The plug-in is installed and displayed in the Plug-ins pane.
- From the Plug-ins pane, select the JSA plug-in and click Configure.
The AddJSA wizard is displayed.
- In the Server Address field, type the IP address of JSA.
- From the Port list, select 514.
- Click Next.
- From the Assigned CounterACT devices pane,
choose one of the following options:
Default Server— Select this option to make all devices on this ForeScout CounterACT, forward events to JSA.
Assign CounterACT devices— Select this option to assign which individual devices that are running on ForeScout CounterACT forward events to JSA. The Assign CounterACT devices option is only available if you have one or more ForeScout CounterACT servers.
- Click Finish.
The plug-in configuration is complete. You are now ready to define the events that are forwarded to JSA by ForeScout CounterACT policies.