In this article
CyberSight Data Export sends endpoint user activity and analytics data to a supported SIEM (Security Information and Event Management) platform on a recurring schedule. It uses the same Data Export workflow used for DNS query data today. For DNS query export setup, see Data Export configuration.
DNSFilter account users with admin permissions or higher configure CyberSight Data Export.
CyberSight Data Export uses the same HEC-based integration as DNS query export, so it works with most SIEMs, including:
- Microsoft Sentinel
- Crowdstrike
- LogRhythm
- Splunk
- Sumo Logic
- Huntress
CyberSight Data Export can also connect to S3-compatible services such as Wasabi and Backblaze.
What data CyberSight Data Export includes
CyberSight Data Export sends endpoint user activity and analytics data, such as application use, web activity, streaming activity, and user session events. This data differs from DNS query export data, which contains DNS lookups processed through the Roaming Client or network deployments.
An Organization can export DNS query data, CyberSight data, or both. When both are enabled, the SIEM receives two separate payloads per export interval: one for DNS query data and one for CyberSight data.
Prerequisites
The following requirements apply before configuring CyberSight Data Export:
- A DNSFilter Plus plan or higher is required for the Organization. Accounts on legacy Pro plans retain access to features included in their plan, though new features released after the Plus plan launch may be available on the Plus plan only.
- A CyberSight license is required for the Organization.
- The supported destinations are Splunk, Amazon S3, and generic HEC (HTTP Event Collector).
Microsoft Sentinel limitation
Microsoft Sentinel accepts one schema per table mapping. By default, an Organization exporting to Microsoft Sentinel must choose either DNS query data or CyberSight data for that connection. To send both data types to the same Sentinel destination, see Combine CyberSight and DNS query data in Microsoft Sentinel.
Configure CyberSight Data Export
To enable CyberSight Data Export on a new or existing Data Export connection:
- From the DNSFilter dashboard, navigate to Tools and select Data Export.
- Select an existing connection, or select Configure Data Export to create a new one.
- Select Include CyberSight events.
- Re-enter the credentials for the connection when prompted:
- For Splunk or HEC connections, enter the Active Event Collector Token.
- For Amazon S3 connections, enter the Access Key and Secret.
- Select Save.
CyberSight events now export to the configured destination.
If the Include CyberSight events option is unavailable, confirm the Organization has an active CyberSight license and that the connection's destination is one of the supported platforms listed in Prerequisites.
To turn off CyberSight Data Export without affecting DNS query export, clear Include CyberSight events and select Save.
Restart a paused CyberSight Data Export
If a CyberSight Data Export moves to a Paused state, restart it as soon as the SIEM is reachable again. See Restart a paused Data Export in the Data Export configuration article for both dashboard and API restart options.
Comments
0 comments
Please sign in to leave a comment.