Pulse Connect Secure
Formerly named Juniper SA, Pulse Connect Secure is an SSL VPN solution that gathers large amounts of event data about your network and users.
Before You Begin
In order to setup this event source in InsightIDR, you must first configure it to send syslog to the InsightIDR collector. You can find instructions here: https://kb.pulsesecure.net/articles/Pulse_Secure_Article/KB22227.
How to Configure This Event Source
- From your dashboard, select Data Collection on the left hand menu.
- When the Data Collection page appears, click the Setup Event Source dropdown and choose Add Event Source.
- From the “Security Data” section, click the VPN icon. The “Add Event Source” panel appears.
- Choose your collector and event source. You can also name your event source if you want.
- Choose the timezone that matches the location of your event source logs.
- Optionally choose to send unfiltered logs.
- Configure your default domain and any Advanced Event Source Settings.
- Select Listen for Syslog. Enter the port you used for your syslog configuration.
- Optionally choose to Encrypt the event source if choosing TCP by downloading the Rapid7 Certificate.
- Click Save.