Configuring Nozomi Networks SCADAguardian
To receive the alert information, Ivanti Policy Secure details are added in SCADAguardian admin interface.
-
Select Administration > Data Integration.
-
Click +Add to add new Endpoint.
-
Under Endpoint Configured as, select Common Event Format (CEF).
-
Under To URL, enter the Protocol (TCP or UDP), IP address of Ivanti Policy Secure, and port number.
-
Select the checkbox Enable sending Alerts.
-
Enter the filter query if only specific alert information should be sent to Ivanti Policy Secure.
For example, if administrator wants to send information to Ivanti Policy Secure for alerts with risk score of more than 6, specify “where risk > 6" in query filter.