When you configure Thycotic Software Secret Server to send log data to USM Appliance, you can use the Thycotic Software Secret Server plugin to translate raw log data into normalized events for analysis. The table below provides some basic information for the plugin.
Device | Details |
---|---|
Vendor | Thycotic Software |
Device Type | Data Protection |
Connection Type | Syslog |
Data Source Name | Secret-server |
Data Source ID | 1909 |
Integrating Thycotic Software Secret Server
Before you configure the Thycotic Software Secret Server integration, you must have the IP Address of the USM Appliance Sensor.
To configure Thycotic Software Secret Server to send Syslog messages to USM Appliance
- From the Thycotic Secret Server web UI, select Administration > Configurationand then click the Edit button.
- Select or check the Enable Syslog/CEF Logging check box.
- Enter the following values for the three additional settings that appear:
- Syslog/CEF Server: The IP Address of the USM Appliance Sensor.
- Syslog/CEF Port: 514.
- Syslog/CEF Protocol: UDP.
- After entering the values, click Save.
Plugin Enablement
For plugin enablement information, see Enable Plugins.
Additional Resources and Troubleshooting
https://thycotic.force.com/support/s/secretserver
https://thycotic.force.com/support/s/article/Secret-Server-End-User-Guide
For troubleshooting, see the vendor documentation.