Setting up this integration requires you to create one security device in Workbench for the SIEM (you will find a link to those instructions in this guide), and a separate security device for the Forcepoint Web Filter integration (that device will reference the SIEM's device).

Scope and Limitations

When choosing to set up this integration, remember the following:

  1. You must use a supported SIEM to set up this type of connection. This integration's supported SIEMs include:
    • Exabeam Fusion New-Scale SIEM
  2. Custom detection rules cannot be used for a via SIEM connection.

Quick Links

  1. Set Up Logging
  2. Set Up the SIEM
  3. Add Forcepoint Web Filter (via SIEM) as a Security Device in Workbench

Step 1: Set Up Logging

You must first confirm that your SIEM's data sources are logging properly, and then specify which logs the SIEM should ingest, where they should be stored, and any other data quality information that should be included.

You should work with your SIEM representative or refer to your SIEM's documentation if you need help with this step. The following web resources are also available:

Step 2: Set Up the SIEM

You must set up the SIEM as its own security device before you can configure this integration's security device, since you are using it as a connection. Select the link below to go to your SIEM's setup guide, then return to this page when you have completed it:

Important

Be sure to confirm the SIEM's security device in Workbench is connected and logs are flowing before continuing to Step 3 in this guide.

Step 3: Add Forcepoint Web Filter (via SIEM) as a Security Device in Workbench