ESET PROTECT

Our Integration guide was accurate at the time of writing but vendors change things frequently! If you find errors or anything is outdated, let us know by raising a request in the Samurai MDR application and we shall get it updated.

ProductSamurai [Local] CollectorSamurai [Cloud] Collector
ESET PROTECTPicture1.svg

This guide describes the steps required to configure ESET PROTECT On-Prem to send logs to a Samurai Local Collector deployed in your network.

Connectivity Requirements

You must ensure the following connectivity requirements are available:

SourceDestinationPortsDescription
ESET PROTECTSamurai Local CollectorTCP/514 (syslog)For log transmission

Table 1: Connectivity requirements

Syslog Configuration

Follow the steps described in Export logs to Syslog using the following parameters:

ParameterValue
HostIP of the Samurai Local Collector
Port514
FormatSyslog
TransportTCP
Exported logs formatJSON

For integrations that utilize a Local Collector where we ingest syslog only, you do not need to follow specific steps in the Samurai MDR Application as we auto detect the vendor and product. The only reason you need to use the Samurai MDR Application is if you need to determine the Local Collector IP address. Of course you will still need to ensure the integration is functioning! See Integrations for more information on checking status.