CSP Configuration
Follow the steps below in the Infoblox Cloud Services Portal (CSP) to configure the Infoblox Cloud Data Connector (CDC) to send BloxOne data to QRadar. See more information on the CDC here.
The CDC is a major feature of BloxOne Threat Defense and as such requires appropriate licensing and deployment. This integration will NOT deploy a CDC.
Navigate to Manage > Data Connector.
Click the Destination Configuration tab at the top.
Click Create > Syslog.
Name: Give the new Destination a meaningful name, such as QRadar-Destination.
Description: Optionally give it a meaningful description.
State: Set the state to Enabled.
Format: Set the format to CEF.
FQDN/IP: Enter the IP address of the QRadar appliance. If using a proxy or other syslog forwarder, enter that IP instead.
Port: Leave the port number at 514.
Protocol: Select desired protocol and CA certificate if applicable.
Click Save & Close.
Click the Traffic Flow Configuration tab at the top.
Click Create.
Name: Give the new Traffic Flow a meaningful name, such as QRadar-Flow.
Description: Optionally give it a meaningful description.
State: Set the state to Enabled.
Expand the Service Instance section.
Service Instance: Select your desired service instance host for which the Data Connector service is enabled.
Expand the Source Configuration section.
Source: Select BloxOne Cloud Source.
Select all desired log types you wish to collect. Currently supported log types are:
Threat Defense Query/Response Log
Threat Defense Threat Feeds Hits Log
DDI Query/Response Log
DDI DHCP Lease Log
Audit Log
Service Log
Expand the Destination Configuration section.
Select the Destination you just created.
Click Save & Close.
Allow the configuration some time to activate.