Knowledge Base – SGBox Next Generation SIEM & SOAR https://www.sgbox.eu Next Generation SIEM & SOAR Wed, 28 Jan 2026 16:34:25 +0000 en-US hourly 1 https://wordpress.org/?v=6.8.2 https://www.sgbox.eu/wp-content/uploads/2025/02/cropped-SGBox-symbol-png-32x32.webp Knowledge Base – SGBox Next Generation SIEM & SOAR https://www.sgbox.eu 32 32 Syslog configuration on Cynet https://www.sgbox.eu/en/knowledge-base/syslog-configuration-on-cynet/ Wed, 28 Jan 2026 08:40:50 +0000 https://www.sgbox.eu/?post_type=epkb_post_type_1&p=34860

Cynet – SGBox SIEM Integration Guide

Configure Cynet to send syslog notifications to a remote Syslog.

  1. On your Cynet web interface, go to Setting > Advanced.
    Knowledge Base
  2. Select the box beside Send Audit Records to SIEM.
  3. Go to Configuration > SIEM settings and enable the following configuration:
    Knowledge Base
    – TCP
    – IP – public IP address of your syslog server
    – Port – port that is configured on your syslog server. We use 6514 tcp.
  4. Press Add. The added IP and port will appear on the screen.
    Knowledge Base

NOTE: These instructions are based on official guide provided by the vendor. but for let work the integration with SGBox ensure that the configuration matches what is specified below

– Communication protocols is TCP
– Port is 6514
– Public IP address of your syslog server is correct one.

For further SGBox support requests, please open a ticket on the ticket portal.  
 
]]>
Troubleshooting on Collector 6 https://www.sgbox.eu/en/knowledge-base/troubleshooting-on-collector-6/ Mon, 26 Jan 2026 11:43:50 +0000 https://www.sgbox.eu/?post_type=epkb_post_type_1&p=35763

Troubleshooting on Collector 6

In this guide, we show you how to perform debugging: to quickly check if the collector has all the main processes active for correct communication with the Host or SGBox appliance.

Docker and containers

Collector 6 introduces the use of docker and containers, to activate them correctly, it is necessary do port forwarding on the firewall. For more details, see: SGBox and Collector network requirements

after opening the Internet connection to our public registry address. You can debug using the CLI tool: to verify that the collector has correctly activated all key containers.

Connect to the Collector appliance via SSH (using Putty,Terminal or console), specifying the user CLI and the password you saved for it.
Go under System > Process Handling > Services status > SGBox Containers
Check if there are 4 active containers. See the image below for an example showing active containers.Knowledge Base

Containers are Active: this means that your Collector is ready to be used.
Containers are not Active: this means that something went wrong during network configuration or port opening. We suggest following the Network debugging guide.

Network debugging

You can perform network debugging using the CLI tool.
Connect to the Collector appliance via SSH (using Putty,Terminal or console), specifying the user CLI and the password you saved for it.
Go under Network Configuration > Connect to port
Knowledge Base 

For example, let’s check if Collector reaches our registry. You can specify IPv4 or FQDN and Port.Knowledge Base

The result may be Server is Responding or Cannot connect to the server.

If the result is Cannot connect to the server, we recommend checking that the firewall managing the network is not blocking communication. For more details, see: SGBox and Collector network requirements or provide the results obtained from debugging to SGBox Support for further assistance.

Dump network traffic

You can use the CLI tool to check if there are any problems with receiving data from the Hosts.
Connect to the Collector appliance via SSH (using Putty,Terminal or console), specifying the user CLI and the password you saved for it.
Go under Stats > Dump network traffic
Knowledge Base

  1. Filter by IP: simple filter on data source IP all ports and protocols
  2. Filter SGBox ports: simple filter on ports 514 and 443 from all the data source
  3. Expert: you can enter all the tcpdump parameters.

For example, let’s use the Filter by IP option to check if the collector receives the log from the Host.
Knowledge Base

Knowledge Base
If the host sends logs to the collector, then you should see traffic passing through, as in the example above.
If you do not see any traffic passing through, double-check that you have correctly configured the source to send logs, or check that there are no firewall blocks between the source and the collector.

]]>
6.2.5 https://www.sgbox.eu/en/knowledge-base/6-2-5/ Wed, 21 Jan 2026 15:45:33 +0000 https://www.sgbox.eu/?post_type=epkb_post_type_1&p=35652

6.2.5

A new version of SGBox that improve a lot of backend features and performance has been released


SGBOX > SCM > Applications > SGBox Updates
Knowledge Base
]]>
6.2.3 https://www.sgbox.eu/en/knowledge-base/6-2-3/ Wed, 21 Jan 2026 15:37:32 +0000 https://www.sgbox.eu/?post_type=epkb_post_type_1&p=35650

6.2.3

A new version of SGBox that improve a lot of backend features and performance has been released


SGBOX > SCM > Applications > SGBox Updates
Knowledge Base
]]>
6.2.4 https://www.sgbox.eu/en/knowledge-base/6-2-4/ Wed, 21 Jan 2026 14:50:24 +0000 https://www.sgbox.eu/?post_type=epkb_post_type_1&p=35651

6.2.4

A new version of SGBox that improve a lot of backend features and performance has been released


SGBOX > SCM > Applications > SGBox Updates
Knowledge Base
]]>
Network debugging https://www.sgbox.eu/en/knowledge-base/network-debugging/ Thu, 15 Jan 2026 13:33:24 +0000 https://www.sgbox.eu/?post_type=epkb_post_type_1&p=35627

In this guide, we show you how to perform network debugging: to quickly check that a port on a server is reachable from SGBox.

You can perform network debugging using the SGBox CLI tool.
Connect via SSH (using a programme such as Putty or a virtualisation console) to SGBox, specifying the user CLI and the password you saved for it.

Go under Network Configuration > Connect to port
Knowledge Base

For example, let’s check if SGBox reaches Active Directory server on port 389 (LDAP) or 636 (LDAPS).

You can specify IPv4 or Hostname and port.
Knowledge Base

The result may be Server is Responding or Cannot connect to the server.

If the result is Cannot connect to the server, we recommend checking that the firewall managing the network is not blocking communication or checking that the Host port is actually open.

For more details on which ports are used by SGBox, please read the Network Requirements guide.  

]]>
Syslog configuration on Sophos Firewall https://www.sgbox.eu/en/knowledge-base/syslog-configuration-on-sophos-firewall/ Mon, 12 Jan 2026 16:49:30 +0000 https://www.sgbox.eu/?post_type=epkb_post_type_1&p=35579

Introduction

to be able to receive logs from Sophos appliance, the syslog must be configured.

Example configuration

NOTE: this is only an example configuration, the options may change due to different version or changed options.

Connect to your Sophos firewall system. Choose  System services > Log settings and click Add.

  1. Enter a name
  2. Specify settings
  3. Click on Save
  4. Go to Log settings and select the logs you want to send to the syslog server.
Knowledge Base

From SGBox WebUI downlaod Sophos Firewall Package: SCM > Application > Pacakges

Knowledge Base
]]>
Associate Collector to Tenant https://www.sgbox.eu/en/knowledge-base/associate-collector-to-tenant/ Fri, 28 Nov 2025 10:47:22 +0000 https://www.sgbox.eu/?post_type=epkb_post_type_1&p=34848

Associate Collector to Tenant

This operation is needed in order to forward logs to the correct SGBox tenant. It could be done in two ways:

  1.  from the collector with option “Register collector” (https://www.sgbox.eu/en/knowledge-base/the-sgbox-collector-v6/#Register_the_collector). You need insert the “key probe for connection” you choosed when tenant was created (in our example https://www.sgbox.eu/en/knowledge-base/create-new-tenant/ is Key1234)
  2. On SGBox by manually associate the collector to the right tenant.  From SCM > Multitenant  > Manager > Probes. Once identified your probes, select from drop down menu the correct tenant
 
Starting from version 6.2.2, new installations need a collector configured.
If your installation has just one tenant you can avoid deploy the collector VM and use the preconfigured collector: sgboxprobeid
 
Knowledge Base

Identify and assign it to the correct tenant.

 
]]>
Alarm & Incident Management https://www.sgbox.eu/en/knowledge-base/alarm-incident-management/ Tue, 21 Oct 2025 12:01:53 +0000 https://www.sgbox.eu/?post_type=epkb_post_type_1&p=34246
Click to open the Alarm & Incident Management User Guide

]]>
6.2.2 https://www.sgbox.eu/en/knowledge-base/6-2-2/ Wed, 15 Oct 2025 13:28:19 +0000 https://www.sgbox.eu/?post_type=epkb_post_type_1&p=34168

6.2.2

A new version of SGBox that improve a lot of backend features and performance has been released


SGBOX > SCM > Applications > SGBox Updates
Knowledge Base
]]>