Accenture MDR Quick Start Guide for DARKTRACE

This quick start guide will help Accenture MDR customers configure DARKTRACE to send logs to the Log collection Platform (LCP).

This document includes the following topics:

Supported Versions

A list of supported versions is available in the Accenture MDR Supported Products List document (Accenture_MDR_Supported_Products_List.xlsx) which can be found in Accenture MDR Portal.

Port Requirements

Table 1-1: Port requirements for LCP communication.

Source

Destination

Port

Description

DARKTRACE

LCP

601 (TCP)

Default port

Configuring DARKTRACE

To configure the Darktrace, select any one of the below based on the version.

Configuring steps for version 5.2 and below

  1. Log in to DARKTRACE console.

  2. Navigate to System config > Alerting.

3. Configure the JSON Syslog Alerts as follows.

  • Select the JSON Syslog Alerts as true

  • Enter the LCP IP address on the JSON Syslog Server textbox

  • Enter the Port number in JSON Syslog Server Port textbox.

  • Select the JSON Syslog TCP Alerts as true.

 Note:

  • MDR recommends using the port TCP/601 for forwarding the DARKTRACE logs to the LCP.

  • MDR recommends forwarding all types of logs to the LCP for log monitoring and analysis

Configuration steps for version 5.2 and above

  1. Log in to DarkTrace Threat Visualizer and navigate to the System Config page (Main menu › Admin).

image2024-2-16_11-1-42.png
  1. From the left-side menu, select Modules, then navigate to the Workflow Integrations section and choose Syslog.

  1. A window with four tabs will open, a Status tab that lists existing configurations per-Syslog server and an individual tab for each Syslog format. The Status tab may not be present if there are no existing configurations.

  1. Select the Syslog JSON tab, existing configurations using that format will be listed by destination server.

5.Scroll past any existing configurations and click New to set up forwarding Darktrace alerts to a new server via syslog.

6.Enter LCP IP Address in the Server field, enter the Port Number in Server Port. Enable Show Advanced Options and then enable Send Alerts Using TCP.

7.Turn on Send Alerts and click Add to save the configuration and observe a confirmation message.

Note:

  • MDR recommends using the port TCP/601 for forwarding the DARKTRACE logs to the LCP.

  • Minimum Alert Priority, Minimum Alert Score, and Model Expression can be configured to set the type of alerts that will be sent to syslog server when Show Advanced Options is enabled. Our recommendation is to forward all types of logs to the LCP for log monitoring and analysis

LCP Configuration Parameters

Table 1-2: The DARKTRACE event collector (Syslog -3875) properties to be configured by MDR are shown in the table.

Property

Default Value

Description 

Protocol

TCP

The default protocol for syslog.

Host Names/IP Address

DARKTRACE Interface IP address

Logging device IP address mentioned in the Pre-Installation Questionnaire (PIQ).

Signatures

darktrace-dt ,darktrace

MDR recommended signatures processed by the DARKTRACE event collector.

Port Number

601

The default port for TCP.

 

 

Legal Notice

Copyright © 2021 Accenture. All rights reserved.

Accenture, the Accenture Logo, and DeepSight Intelligence are trademarks or registered trademarks of Accenture in the U.S. and other countries. Other names may be trademarks of their respective owners.

The product described in this document is distributed under licenses restricting its use, copying, distribution, and decompilation/reverse engineering. No part of this document may be reproduced in any form by any means without prior written authorization of Accenture and its licensors, if any.

THE DOCUMENTATION IS PROVIDED "AS IS" AND ALL EXPRESS OR IMPLIED CONDITIONS, REPRESENTATIONS AND WARRANTIES, INCLUDING ANY IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE OR NON-INFRINGEMENT, ARE DISCLAIMED, EXCEPT TO THE EXTENT THAT SUCH DISCLAIMERS ARE HELD TO BE LEGALLY INVALID. ACCENTURE SHALL NOT BE LIABLE FOR INCIDENTAL OR CONSEQUENTIAL DAMAGES IN CONNECTION WITH THE FURNISHING, PERFORMANCE, OR USE OF THIS DOCUMENTATION. THE INFORMATION CONTAINED IN THIS DOCUMENTATION IS SUBJECT TO CHANGE WITHOUT NOTICE.

The Licensed Software and Documentation are deemed to be commercial computer software as defined in FAR 12.212 and subject to restricted rights as defined in FAR Section 52.227-19 "Commercial Computer Software - Restricted Rights" and DFARS 227.7202, et seq. "Commercial Computer Software and Commercial Computer Software Documentation," as applicable, and any successor regulations, whether delivered by Accenture as on premises or hosted services. Any use, modification, reproduction release, performance, display or disclosure of the Licensed Software and Documentation by the U.S. Government shall be solely in accordance with the terms of this Agreement.