Creating an alarm profile for LogRhythm
In an alarm profile that you create and name, you specify which alarms you want to pull from the LogRhythm Client Console. You also define how they are mapped to fields on a ServiceNow AI Platform security incident.
Before you begin
Role required: sn_si.admin
About this task
Based on the Alarm Profile configured, one alarm profile can ingest all types of alarms out of the box, but you can use filter criteria to ingest specific types of alarms. Using this ServiceNow AI Platform integration, all configured alarm rules or specific ones based on the profile created are ingested. Alarm rules such as only high-risk level alarms can then be filtered to specify which alarms should create security incidents. Before security incidents are created, individual field values on the filtered alarms are mapped to corresponding fields on the ServiceNow AI Platform security incident. This configuration is done via an alarm profile within your ServiceNow AI Platform instance.
Procedure
Navigate to All > LogRhythm Integration.
Select the LogRhythm Alarm Profiles module to display the Alarm Profiles list.
Create an alarm profile
To create a new alarm profile, click New.
A new alarm profile form is displayed. At the top of the page in the progress bar, Name is selected. This bar tracks your progress during the configuration.
On the form, fill the fields.
| Field | Description |
|---|---|
| Name | Name for the alarm profile. This name helps you identify the alarm types such as Unauthorized access \(VPN\), malware, or phishing. |
| Short description | Short text for additional information about the alarm profile, which may include the type of alarms, or an alarm category. An example description: All alarms associated with unauthorized Powershell and Sudo access attempts. |
| Source | Source server from the choice list. The list consists of LogRhythm configurations you have already set up, for example, `logrhythm-server-a`. See Install the plugin and configure LogRhythm. |
| Order | Alarm profile priority. This field indicates the order in which the alarm profiles are executed when two or more alarm profiles share the triggering conditions. |
| Active | By default this option is not selected. After you complete all alarm profile setup steps and click Finish, you are prompted to select this check box to activate the alarm profile. When the alarm profile is active, it pulls alarms from the LogRhythm Client Console automatically. |
Click Continue to save your data and proceed to the Mapping form.
If the validation is successful, the page reloads and the Mapping form is displayed. You cannot proceed with the configuration until you have successfully validated your connection and credentials.
Mapping
After selecting the LogRhythm source that you want to ingest, you need to map individual LogRhythm alarm fields to the ServiceNow AI Platform security incident fields.- Filter alarms for LogRhythm
Setting filtering criteria for alarms after you have mapped fields helps you determine which alarms should be ingested into the SIR application. Filtering alarms helps you significantly reduce the number of alarms you ingest when the alarm profile is activated. - Previewing the security incident with mapped LogRhythm alarm values
After you have completed the mapping step, preview the values that you mapped to the fields on the security incident. This preview step permits you to verify that you have mapped all the critical LogRhythm alarm fields you want displayed on the security incident. - Schedule and retrieve LogRhythm alarms
After you preview the security incident with the LogRhythm alarms that you have selected and mapped, you are ready to schedule alarm retrieval. After you complete this step, the alarm profile is ready to be activated. - Additional options for LogRhythm alarms
The LogRhythm Enterprise integration provides you the ability to automatically update or close the LogRhythm alarms based on the security incidents.
Parent Topic:LogRhythm Overview
Previous topic:Install the plugin and configure LogRhythm
Next topic:Mapping
Related topics