SIEM tool plugin | RS
Configure and administer the BeyondTrust SIEM tool plugin
Important informationYou must purchase this integration separately for both your Remote Support software and your SIEM Tool solution. For more information, contact BeyondTrust's Sales team.
The Security Information and Event Management (SIEM) tool plugin for BeyondTrust Remote Support enables the processing and transmission of session event data to your preferred SIEM tool. This complements tools that gather syslog data, which includes only appliance events. The plugin can customize the output message format for special needs and/or use cases.
Prerequisites
Before using this plugin, you must:
- Install and configure the BeyondTrust Middleware Engine, which supports this and other plugins.
- Install this plugin following the instructions in the Middleware Guide.
- Review the network considerations for your preferred SIEM tool.
For more information about installing and configuring the BeyondTrust Middleware Engine and installing plugins, see the Middleware Engine Guide.
Configure Remote Support
All of the steps in this section take place in the BeyondTrust /login administrative interface. Access your Remote Support interface by going to the hostname of your B Series Appliance followed by /login (e.g., https://support.example.com/login).
SIEM plugin configuration is required for each B Series Appliance configured in the application's configuration file.
Verify the API Is enabled
This integration requires the BeyondTrust XML API to be enabled. This feature is used by the BeyondTrust Middleware Engine to communicate with the BeyondTrust APIs.
Go to /login > Management > API Configuration and verify that Enable XML API is checked.
Create an OAuth API account
The SIEM Tool API account is used from within SIEM Tool to make Remote Support Command API calls to Remote Support.
- In /login, navigate to Management > API Configuration.
- Click Add.
- Check Enabled.
- Enter a name for the account.
- OAuth Client ID and OAuth Client Secret is used during the OAuth configuration step in SIEM Tool.
- Under Permissions, check the following:
- Command API: Full Access.
- Reporting API: Allow Access to Support Session Reports and Recordings, and Allow Access to Presentation Session Reports and Recordings.
- Click Save at the top of the page to create the account.
Cloud sites: the reverse proxy is required, not optionalIf your BeyondTrust site is cloud-hosted, you cannot use the default http://middleware-host:8180/PAMPost URL. Your appliance sends outbound events from the internet, so the middleware engine must be reachable at a public hostname over HTTPS on port 443. A URL that points to a private address (10.x, 172.16-31.x, 192.168.x, 100.64.x) is rejected when you save it, and blocked again at delivery if it later resolves to a private address.
Before continuing, complete Set up reverse proxy in the Middleware engine guide, then enter your public HTTPS URL in the step below.
Cannot expose the middleware engine publicly? Use polling instead (see Configure the plugin). Polling requires no inbound access, but supports only the Support Session End event type
How outbound events work
The SIEM plugin does not read session data out of the appliance on a schedule. Instead, the appliance pushes a notification the moment something happens. This is what BeyondTrust calls an outbound event.
When a configured event occurs - a support session ends, a file is transferred, a chat message is sent - the appliance makes an HTTP POST to a URL you supply, carrying the event's details. The BeyondTrust Middleware Engine is the listener for that POST. It receives the event, calls back to the appliance's API to retrieve the full session report, hands the result to the SIEM plugin, and the plugin writes it to your SIEM tool as syslog.
Two consequences follow, and they are what the port table is really describing:
- The appliance is the client and the middleware engine is the server. The connection is established by the appliance, to your middleware host - never the other way round. Your network must therefore accept an inbound connection on the port in the outbound event URL (8180 by default).
- Because the middleware engine then calls the appliance's API to fetch session details, a second connection in the opposite direction is also needed: middleware engine out to the appliance on 443.
If an event cannot be delivered, the appliance retries, and the current state of each destination is shown in the Status column at /login > Management > Outbound Events. A destination that is unreachable, unresolvable, or not permitted reports the reason there. Check this column first when events are not arriving in your SIEM tool.
If your BeyondTrust site is in the cloud, the direction of that first connection is the whole problem. Your appliance is hosted by BeyondTrust, so its POST comes from the internet, not from inside your network. A middleware host on a private address is unreachable from there, and the appliance will refuse a private-address URL outright. Cloud deployments must therefore publish the middleware engine on a public hostname over HTTPS on port 443, which is what the reverse proxy in the Middleware engine guide is for.
Add an outbound event URL
- Go to /login > Management > Outbound Events.
- In the HTTP Recipients section, click Add and name it Integration or something similar.
- Enter the URL to use:
- If using the default appliance ID:
- http://<middleware-host>:<port>/PAMPost.
- The default port is 8180.
- If using an appliance ID other than the default:
- http://<middleware-host>:<port>/PAMPost?appliance=
where <\middleware-host> is the hostname where the BeyondTrust Middleware Engine is installed. - The default port is 8180.
- The
is an arbitrary name, but note the value used, as it is required later in the plugin configuration. This name accepts only alphanumeric values, periods, and underscores.
- http://<middleware-host>:<port>/PAMPost?appliance=
- If using the default appliance ID:
- Scroll to Events to Send and check the following event: Support Session End
- Click Save.
The list of outbound events contains the event just added. The Status column displays a value of OK if communication is working. If communication is not working, the Status column displays an error which you can use to repair communication.
Configure the SIEM tool plugin
All of the steps in this section take place in the BeyondTrust Middleware Administration Tool. Access this tool by going to a browser on the server where the Middleware Engine is installed, and entering the address http://127.0.0.1:53231/.
To begin configuration, click the clipboard icon next to the plugin name.
Configure communication between the SIEM plugin and the BeyondTrust Appliance B Series
Enter the settings for communication between the plugin and the appliance. Configuration sections include:
- Plugin Configuration Name: Any desired value. Because multiple configurations can be created for a single plugin, allowing different environments to be targeted, provide a descriptive name to indicate how this plugin is to be used.
- Appliance Id: This can be left as default or can be given a custom name. This value must match the value configured on the outbound event URL in the BeyondTrust Appliance B Series. If outbound events are not being used, this value is still required, but any value may be used.
- B Series Appliance Host Name: The hostname of the B Series Appliance. Do not include https:// or other URL protocol elements. For example, enter www.example.com.
- BeyondTrust Integration API OAuth Client ID: This field must contain the Client ID of the OAuth account.
- BeyondTrust Integration API OAuth Client Secret: This field must contain the client secret of the OAuth account
- BeyondTrust Integration API User Name: Deprecated - no longer used.
- BeyondTrust Integration API Password: Deprecated - no longer used.
- Locale Used for BeyondTrust API Calls: This value directs the B Series Appliance to return session data in the specified language.
- Disabled: Enable or disable this plugin configuration. It must be enabled to function.
- Allow Invalid Certificates: Leave unchecked unless there is a specific need to allow. If enabled, invalid SSL certificates are allowed in calls performed by the plugin. This would allow, for example, self-signed certificates. This is not recommended in production environments.
- Use Non-TLS Connections: Leave unchecked unless it is the specific goal to use non-secure connections to the B Series Appliance. If checked, TLS communication is disabled altogether. If non-TLS connections are allowed, HTTP access must be enabled on the BeyondTrust /login > Management > API Configuration page. Using non-secure connections is discouraged.
When you use OAuth authentication, TLS cannot be disabled.
- Outbound Events Types: Check which types of events the plugin processes when received by the middleware engine. Event types selected here must also be configured to be sent in BeyondTrust. The middleware engine receives any events configured to be sent in BeyondTrust but passes them off to the plugin only if the corresponding event type is selected in this section.
- Polling Event Types: If network constraints limit connectivity between the B Series Appliance and the middleware engine such that outbound events cannot be used, an alternative is to use polling. The middleware engine regularly polls the B Series Appliance for any sessions that have ended since the last session was processed, however only the Support Session End event type is supported.
- Polling Interval: Enter only if polling is used. This determines how often the middleware engine polls the B Series Appliance for sessions that have ended. Too frequent polling may cause performance issues.
- Retry Attempt Limit: Enter the number of retries that can be attempted if the plugin fails to process an event. Too many retries may cause performance issues.
- Retry Outbound Event Types: Specify which outbound events the plugin retries if it fails to process the event.
- Retry Polling Event Types: Specify which polling events the plugin retries if it fails to process the event.
SIEM tool instance
These are the fields and selections needed to configure the plugin for integration with your SIEM tool. See your SIEM installation guide for the values to provide.
- Target SIEM System: Select the target SIEM tool from the list.
- SIEM Syslog Host: Enter the hostname or IP address of the SIEM instance that should receive the messages.
- SIEM Syslog Port: Enter the port used by the SIEM instance to receive syslog messages.
- SIEM Syslog Protocol: Select the appropriate protocol from the list.
- Events to Process: BeyondTrust session data can contain many different event types. All types are available; however, a subset may be desired in the SIEM tool. Select only the events you would like sent to the tool. Events matching unchecked event types are ignored.
For a complete list of available events, see BeyondTrust SIEM Tool Message Reference List.
Report templates
On the BeyondTrust Middleware Engine server, in the
If you are editing a template, we recommend copying and saving the original in case the changes need to be reverted.
For more information on Handlebars templates, see the Handlebars website.
SIEM tool message reference
| Event Name | Event ID |
|---|---|
| Callback Button Deployed | 10 |
| Callback Button Removed | 20 |
| Chat Message | 30 |
| Command Shell Session Started | 40 |
| Conference Member Added | 50 |
| Conference Member Departed | 60 |
| Conference Member State Changed | 70 |
| Conference Owner Changed | 80 |
| Credential Injection Attempt Failed | 90 |
| Credential Injection Attempt | 100 |
| Customer Exit Survey | 110 |
| Directory Created | 120 |
| External Key | 130 |
| File Deleted | 140 |
| File Download Failed | 150 |
| File Download | 160 |
Updated 24 days ago