Skip to content

Commit

Permalink
Update Skyhigh Secure docs
Browse files Browse the repository at this point in the history
  • Loading branch information
lvoloshyn-sekoia committed Feb 20, 2025
1 parent 9cb2931 commit 2ced1ef
Show file tree
Hide file tree
Showing 3 changed files with 70 additions and 3 deletions.
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
uuid: 40bac399-2d8e-40e3-af3b-f73a622c9687
name: McAfee Web Gateway / Skyhigh Secure Web Gateway
name: McAfee Web Gateway / Skyhigh Secure Web Gateway - On Prem
type: intake

## Overview
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,66 @@
uuid: 40bac399-2d8e-40e3-af3b-f73a622c9687
name: McAfee Web Gateway / Skyhigh Secure Web Gateway - SaaS
type: intake

## Overview
Skyhigh Secure Web Gateway (SWG) (previously McAfee Web Gateway (MWG)) is a web gateway offering malware detection, threat prevention and reputation filtering.

- **Vendor**: Skyhigh Security
- **Supported environment**: SaaS
- **Version compatibility**: 12.2.10
- **Detection based on**: Telemetry
- **Supported application or feature**: Anti-virus, Web proxy, Web logs


## Configure

#### Configure a Rule Set

Prior to the configuration, download the “Rule Set” configuration [`SEKOIAIO_SKYHIGH_swg.xml`](/assets/integration/network/skyhigh_secure_web_gateway/SEKOIAIO_SKYHIGH_swg.xml).

In your SWG console:

- Select `Policy` section then the `Rule sets` tab. From the menu, select `Log Handler`.
- Right-click on the `Default` Log Handler in the tree then select `Add > Rule Set from Library...`.
- Once the `Add from Rule Set library` window opened, under the `Rule Set Library` tree, click on the `Import from file...` button and import `SEKOIAIO_mwg.xml` file.
- Select the `Rule Set` `Sekoia.io` and ensure the rule `forward logs` is enabled.


#### Find your Customer ID
1. Go to `Settings > Infrastructure > Client Proxy Management`.
2. Click `Global Configuration > Tenant Authentication`.
3. The Customer ID is displayed under `Global Settings`.

{!_shared_content/integration/intake_configuration.md!}


#### Pull the logs to collect them on Sekoia.io

Go to the Sekoia.io [playbook page](https://app.sekoia.io/operations/playbooks), and follow these steps:

1. Click **+ PLAYBOOK** button to create a new one
2. Select **Create a playbook from scratch**
3. Give it a name in the field **Name**
4. Open the left panel, click **Fastly** then select the trigger `Fetch events from Skyhigh Security Secure Web Gateway (SWG) API`
5. Click **Create**
6. Create a **Module configuration**. Name the module configuration as you wish.
7. Create a **Trigger configuration** using:

- `Intake key` created on the previous step
- `customer Id` (from "Find your Customer ID" step),
- `account name`
- `account password`
- `api domain name` (Europe: eu.msg.mcafeesaas.com, North America: us.msg.mcafeesaas.com)

8. Click the **Save** button
9. **Activate the playbook** with the toggle button

#### Enjoy your events on the [Events page](https://app.sekoia.io/operations/events)

{!_shared_content/operations_center/integrations/generated/40bac399-2d8e-40e3-af3b-f73a622c9687_sample.md!}

{!_shared_content/integration/detection_section.md!}

{!_shared_content/operations_center/detection/generated/suggested_rules_40bac399-2d8e-40e3-af3b-f73a622c9687_do_not_edit_manually.md!}
{!_shared_content/operations_center/integrations/generated/40bac399-2d8e-40e3-af3b-f73a622c9687.md!}

5 changes: 3 additions & 2 deletions mkdocs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -474,7 +474,8 @@ nav:
- Google Cloud Load Balancing: integration/categories/network_security/google_cloud_load_balancing.md
- Imperva Web Application Firewall: integration/categories/network_security/imperva_waf.md
- Lacework Cloud Security: integration/categories/network_security/lacework_cloud_security.md
- McAfee Web Gateway / Skyhigh Secure Web Gateway: integration/categories/network_security/skyhigh_secure_web_gateway.md
- McAfee Web Gateway / Skyhigh Secure Web Gateway - On Prem: integration/categories/network_security/skyhigh_secure_web_gateway_on_prem.md
- McAfee Web Gateway / Skyhigh Secure Web Gateway - SaaS: integration/categories/network_security/skyhigh_secure_web_gateway_saas.md
- Netskope Events: integration/categories/network_security/netskope_events.md
- Netskope Transaction Events: integration/categories/network_security/netskope_transaction.md
- OGO Shield WAF: integration/categories/network_security/ogo_shield.md
Expand Down Expand Up @@ -815,7 +816,7 @@ plugins:
xdr/features/collect/integrations/network/pulse.md: integration/categories/network/pulse.md
xdr/features/collect/integrations/network/rubycat_prove_it.md: integration/categories/iam/rubycat_prove_it.md
xdr/features/collect/integrations/network/sesameit_jizo.md: integration/categories/network/sesameit_jizo.md
xdr/features/collect/integrations/network/skyhigh_secure_web_gateway.md: integration/categories/network_security/skyhigh_secure_web_gateway.md
xdr/features/collect/integrations/network/skyhigh_secure_web_gateway.md: integration/categories/network_security/skyhigh_secure_web_gateway_on_prem.md
xdr/features/collect/integrations/network/sonicwall_fw.md: integration/categories/network_security/sonicwall_fw.md
xdr/features/collect/integrations/network/sonicwall_sma.md: integration/categories/network_security/sonicwall_sma.md
xdr/features/collect/integrations/network/sophos_fw.md: integration/categories/network_security/sophos_fw.md
Expand Down

0 comments on commit 2ced1ef

Please sign in to comment.