Generated by Rank Math SEO, this is an llms.txt file designed to help LLMs better understand and index this website. # SGBox: Next Generation SIEM & SOAR ## Sitemaps [XML Sitemap](https://www.sgbox.eu/sitemap_index.xml): Includes all crawlable and indexable pages. ## Posts - [NIS2 Directive and OT Security: impacts, requirements and solutions](https://www.sgbox.eu/en/nis2-and-ot-security/): For manufacturing companies and organizations that manage industrial processes, the relationship between NIS2 and OT Security has become a fundamental pillar of cybersecurity governance. - [The SIEM for OT Security](https://www.sgbox.eu/en/siem-for-ot-security/): OT Security (Operational Technology Security) refers to the protection of systems and networks that manage and control physical operations in industrial environments and critical infrastructure.  - [NIS2 Compliance: security Log Management](https://www.sgbox.eu/en/compliance-to-nis2-and-log-management/): Log management plays a fundamental role in achieving compliance with the NIS2 Directive because it provides objective evidence that the necessary security measures have been adopted to fully meet the required standards. - [Log Management vs SIEM: what are the differences?](https://www.sgbox.eu/en/log-management-vs-siem-the-differences/): Log Management and SIEM functionalities are both essential pillars of modern security information management, yet they serve distinct purposes and operate in fundamentally different ways. - [Ignored Logs, exposed businesses: why your infrastructure already produces the data to prevent a cyber attack](https://www.sgbox.eu/en/ignored-logs-exposed-businesses/): Every company’s IT systems tell a story every single day, quietly and with remarkable precision. - [Cloud Log Management and On-Premise: a feature guide](https://www.sgbox.eu/en/cloud-log-management-vs-on-premise/): An On-Premise Log Management system involves the entire infrastructure dedicated to collecting, storing, and analyzing logs physically residing within enterprise environments, while a Cloud Log Management system involves collecting and storing logs within Cloud environments, which provides greater flexibility and scalability. - [SIEM vs SOAR: key differences](https://www.sgbox.eu/en/siem-vs-soar-key-differences/): SOAR (Security Orchestration, Automation, and Response) and SIEM (Security Information and Event Management) are two distinct security technologies that vary in several aspects. - [How can a SIEM & SOAR Platform transform your company’s security posture?](https://www.sgbox.eu/en/how-sgbox-transform-the-security-posture/): Today, the traditional approach to cybersecurity is no longer enough to keep up with the unpredictability and speed of modern cyber threats. - [Next Generation SIEM uncovered: definition, benefits, and best practices](https://www.sgbox.eu/en/what-is-next-generation-siem/): Next Generation SIEM represents the evolution of traditional Security Information and Event Management solutions. - [Zero Trust Security: what does it consist of?](https://www.sgbox.eu/en/definition-of-zero-trust-security/): The SGBox platform is designed to integrate Zero Trust security principles simply and effectively. - [The Key Cybersecurity Challenges for SMEs and Large Enterprises in 2026](https://www.sgbox.eu/en/the-key-cybersecurity-challenges-in-2026/): Throughout 2026, both small and medium-sized enterprises (SMEs) and large organizations will face increasingly complex cybersecurity challenges. - [Cyber Security in Italy: analysis of the Clusit 2025 Report and solutions for protecting SMEs](https://www.sgbox.eu/en/report-clusit-analysis-2025-and-solutions-for-smes/): The new update of the Clusit 2025 Report paints a picture of rapid evolution. While the world battles financial cybercrime, Italy faces an unprecedented wave of geopolitical activism.  - [11 ways to optimize logging costs](https://www.sgbox.eu/en/11-ways-to-optimize-logging-costs/): In an increasingly data-driven world marked by constantly evolving threats, efficiently managing logs becomes a key strategic lever: it’s not just about controlling costs, but about ensuring operational visibility, security, and compliance without unnecessary expenses. - [What is Cyber Threat Intelligence? An introductory guide](https://www.sgbox.eu/en/what-is-cyber-threat-intelligence-an-introductory-guide/): This is where the technique of Cyber Threat Intelligence comes into play. - [The role of SIEM in producing and managing security audits for regulatory compliance](https://www.sgbox.eu/en/the-role-of-siem-in-producing-and-managing-security-audits-for-regulatory-compliance/): In a context where cybersecurity regulations are becoming increasingly stringent, ensuring compliance is no longer just a legal obligation, it’s a fundamental requirement for maintaining the trust of clients and partners. - [SGBox for CGNAT: features and benefits](https://www.sgbox.eu/en/sgbox-and-cgnat-features-and-benefits/): Carrier-Grade NAT (CGNAT) is a large-scale network address translation technology used by Internet Service Providers (ISPs) to manage the scarcity of IPv4 addresses. - [New threats (Ransomware and AI): defending with an advanced SIEM](https://www.sgbox.eu/en/new-threats-defending-with-advanced-siem/): In recent years, Ransomware has become increasingly sophisticated and widespread. The rise of the Ransomware-as-a-Service model has enabled even criminals with limited skills to launch complex attacks. - [SecureGate appoints Nusantara Asia Pacific as its Official Distributor in the ASEAN region](https://www.sgbox.eu/en/new-partnership-with-nusantara-asia-pacific/): Milan, August 4th – SecureGate, a leading provider of cybersecurity products and services, has officially appointed Nusantara Asia Pacific as its distributor across the ASEAN region. - [SGBox SOAR: the ally that simplifies SOC operations](https://www.sgbox.eu/en/sgbox-soar-the-ally-that-simplifies-soc-operations/): To address the growing challenges of cybersecurity, it is essential to implement automated countermeasures capable of reducing the average response time to an attack and quickly handling potential incidents. - [SGBox Announces New Distribution Agreement with CIPS Informatica](https://www.sgbox.eu/en/new-partnership-between-sgbox-and-cips-informatica/): Milan, June 19, 2025 – SecureGate is pleased to announce a new partnership with the Italian distributor Cips Informatica for the supply of IT products included in the proprietary SIEM & SOAR platform, as well as the related managed security services provided through the CyberTrust 365 Business Unit. - [Cloud SIEM and transparent costs: SGBox’s solution for SMEs](https://www.sgbox.eu/en/sgbox-siem-cloud-for-smes/): When it comes to cybersecurity, one of the most common misconceptions among many Italian small and medium-sized enterprises (SMEs) is that a SIEM solution is expensive and suitable only for large companies with structured IT teams. - [The most widespread cyberattacks in 2025](https://www.sgbox.eu/en/cyber-attacks-in-2025/): Today's digital landscape, marked by the proliferation of digital devices and new technologies, is seeing a rise in cyber threats that can compromise data integrity and operational security in organizations. - [SecureGate appoints Softprom as its official Distributor in CIS and Eastern Europe](https://www.sgbox.eu/en/securegate-appoints-softprom-as-its-official-distributor-in-cis-and-eastern-europe/): Milan, April 23, 2025 – SecureGate, a leading provider of cybersecurity products and services, has officially appointed Softprom as its distributor in CIS and Eastern European countries. - [Compliance with NIS2: essential tools for DPOs](https://www.sgbox.eu/en/nis-2-and-data-protection-officer/): The NIS2 Directive marks a turning point for cyber security in Europe, imposing higher standards on companies regarding network and information system security. - [Cyber Security in the Healthcare Sector](https://www.sgbox.eu/en/cyber-security-in-the-healthcare-sector/): The healthcare sector is facing numerous challenges related to technological advancements and the maintenance of personal data privacy. - [Cloud SIEM: features, functions and advantages](https://www.sgbox.eu/en/cloud-siem-features-functions-advantages/): In this scenario, the key solution to ensure the protection of sensitive corporate data is represented by the revolutionary technology of Cloud SIEM (Security Information and Event Management). - [NIS2 Directive: what you need to know](https://www.sgbox.eu/en/nis-2-directive-what-you-need-to-know/): The NIS2 Directive (Network and Information Security Directive) is a European regulation focusing on cyber security and the resilience of critical infrastructures and digital service providers. - [Key Challenges for Italian SMEs in Cybersecurity in 2025](https://www.sgbox.eu/en/key-challenges-for-italian-smes-in-cybersecurity-in-2025/): In 2025, Italian small and medium-sized enterprises (SMEs) will encounter significant challenges in cybersecurity. - [Best practices to enhance Threat Hunting](https://www.sgbox.eu/en/best-practices-to-enhance-threat-hunting/): In today’s digital landscape, marked by the constant growth and unpredictability of cyber threats, the practice of Threat Hunting is essential for identifying gaps and vulnerabilities within a company's IT infrastructure. - [Cyber Security and AI: the current situation](https://www.sgbox.eu/en/cyber-security-and-ai/): Artificial intelligence is rapidly revolutionizing the field of cyber security thanks to its ability to automate detection and incident response processes. - [Supply Chain Cyber Security: how to defend your company](https://www.sgbox.eu/en/supply-chain-cyber-security/): In recent years, supply chain cyber security has become a major concern for companies, especially small and medium-sized enterprises (SMEs). - [Cyber Resilience Act: what Impact does it have on businesses?](https://www.sgbox.eu/en/cyber-resilience-act/): The Cyber Resilience Act marks a significant step towards creating a more secure and resilient digital environment.  - [Threat Hunting: what it is and how it works](https://www.sgbox.eu/en/what-is-threat-hunting/): In this scenario, the concept of Threat Hunting emerges as a proactive approach to cyber security that is gaining more and more relevance. - [What is Log Management: features and regulatory obligations](https://www.sgbox.eu/en/what-is-log-management/): Log Management is the process of collecting, analyzing, and archiving logs generated by an organization's various computer systems. - [The importance of Cyber Security for Industry 5.0](https://www.sgbox.eu/en/the-importance-of-cyber-security-for-industry-5-0/): Industry 5.0 represents a new paradigm in the world of production and manufacturing, where the interaction between humans and machines reaches unprecedented levels. - [New version 6.0.0 of SGBox Platform](https://www.sgbox.eu/en/new-sgbox-platform-6-0-0-release/): The SGBox Platform, with the release of version 6.0.0, introduces new features that enhance the functionalities offered by its various modules. - [DDoS attack: what is and how it works](https://www.sgbox.eu/en/what-is-ddos-attack-and-how-it-works/): In other words, a DDoS attack aims to disrupt the functioning of a website, server, or network by sending an excessive volume of requests, saturating the available resources. - [The Ransomware attack: features and defense strategies](https://www.sgbox.eu/en/what-is-ransomware/): Ransomware is a type of threat that aims to encrypt the data of the target IT asset in a way that compromises its availability, integrity, and confidentiality. - [What is SIEM? Features and benefits](https://www.sgbox.eu/en/what-is-siem/): The SIEM (Security Information & Event Management) is one of the most effective solutions for managing vulnerabilities in companies IT infrastructures. - [Cybersecurity in the Manufacturing Sector: how to defend your company from cyber attacks](https://www.sgbox.eu/en/cyber-security-in-the-manufacturing-sector/): The manufacturing sector is increasingly becoming a target for cybercriminals. According to the latest Clusit Report, the manufacturing sector has seen its share of total recorded incidents rise from 6% in 2024 to 8% in the first half of 2025, moving from seventh to fourth place in the ranking. In this case, in just one semester the sector has reached 90% of the total incidents recorded throughout the whole of 2024. - [What is Cyber Security Awareness?](https://www.sgbox.eu/en/what-is-cyber-security-awareness/): In this article, we delve into the meaning of Cyber Security Awareness, its significance, and why every company should prioritize continuous training in cybersecurity. - [The main Cyber Security risks in Public Administration](https://www.sgbox.eu/en/the-main-cybersecurity-risks-in-public-administration/): The Public Administration sector is one of the most affected industries by cyberattacks. - [Cloud Security: what it is, how to implement it, and future trends](https://www.sgbox.eu/en/cloud-security-what-it-is/): In this article, we'll explore what Cloud Security is, why it's important to implement it, and what future trends to expect. - [Malware: what it is and how to best defend yourself](https://www.sgbox.eu/en/malware-what-is-and-how-to-best-defend-yourself/): In the vast and intricate world of technology, there's a term that's frequently mentioned, representing one of the major threats to cybersecurity: Malware. - [Cyber Security forecasts in 2024: 5 trends](https://www.sgbox.eu/en/cyber-security-forecasts-in-2024-5-trends/): Forecasts on Cyber Security for 2024 highlight a rapidly evolving landscape, with new challenges and emerging trends. - [Cyber Attacks: common types and how to protect your company](https://www.sgbox.eu/en/common-types-of-cyber-attacks/): Today, cyber attacks are proliferating exponentially due to the increased number and variety of malicious software. This is a consequence of the growing number of devices connected to the internet.  - [Incident Management: what is and why it’s essential](https://www.sgbox.eu/en/what-is-incident-management-and-why-it-is-essential/): The operational efficiency of a company is increasingly threatened by various types of cybersecurity risks. Fortunately, there is a key solution to swiftly and effectively handle such situations: Incident Management. - [What is SOAR? (Security Orchestration Automation and Response)](https://www.sgbox.eu/en/what-is-soar/): In this context, Security Orchestration Automation and Response (SOAR) emerges as a strategic answer to the ever-growing challenges of cybersecurity. - [SGBox Platform: Next Generation SIEM & SOAR](https://www.sgbox.eu/en/sgbox-platform-next-generation-siem-soar/): The SGBox platform is suitable for safeguarding the infrastructure of organizations of all sizes, including small, medium, and large enterprises, and it also finds application in the Public Administration sector. ## Pages - [LOG MANAGEMENT: more than a Log repository](https://www.sgbox.eu/en/log-management-more-than-a-log-repository-2/): The Log Management module can manage logs of events related to the security of any device. - [PROJECTS](https://www.sgbox.eu/en/sgbox-projects/): // latest case studies - [TECHNOLOGY PARTNERS](https://www.sgbox.eu/en/technology-partners/): The main platforms supported by SGBox:  - [NIS2 Directive](https://www.sgbox.eu/en/sgbox-and-nis-2-directive/): The NIS2 Directive is an important step towards more regulation of cyber security across the European Union and will have to be transposed into national law by Member States. - [PUBLIC ADMINISTRATION: data protection in compliance with privacy](https://www.sgbox.eu/en/public-administration/): SGBox is a proprietary platform developed 100% in Italy. The functionalities of the various modules are able to respond to the minimum ICT security measures for public administrations issued by AGID. - [FILE INTEGRITY: enterprise data security](https://www.sgbox.eu/en/file-integrity-enterprise-data-security/): File integrity, as a fundamental principle of data security, implies that the data contained in files or storage systems is not subject to unauthorized manipulation or alteration. - [Knowledge Base](https://www.sgbox.eu/en/knowledge-base/): Search another article? Search Introduction First Steps Network Requirements Client Configuration Cloud Applications Sophos Central configuration Syslog configuration on Cynet Database MariaDB - Enable audit log Linux rSyslog (imfile module) read custom files Rsyslog strict connection Syslog configuration on AIX Syslog configuration on Debian Syslog configuration on Fedora Syslog configuration on OpenSuse Syslog configuration on RedHat Syslog configuration on Solaris Syslog configuration on Ubuntu Syslog configuration on XenServer Configure SNMP Service on Linux Show all articles ( 3 ) Collapse Articles Network Appliance Syslog configuration on Bitdefender GravityZone Syslog configuration on CheckPoint Syslog configuration on Cisco devices Syslog configuration on ESXi - Vmware Syslog configuration on Fortinet Syslog Configuration on Kaspersky Syslog configuration on MikroTik Syslog Configuration on PaloAlto Syslog configuration on PFSense Syslog configuration on Watchguard Syslog configuration on SonicWall Syslog configuration on Wildix syslog configuration on Zyxel Firewalls Syslog configuration on MikroTik Firewalls Syslog configuration on ForcePoint Syslog configuration on Sentinel Syslog configuration on Ubiquiti Syslog configuration on Cisco WLC Syslog configuration on Cortex Syslog configuration on ESET Syslog configuration on Sangfor SIEM solutions integration with Apex Central Syslog configuration on Sophos Firewall Syslog configuration on Proxmox Syslog configuration on Sangfor HCI / VDI Syslog configuration on Crowdstrike Syslog configuration on Deceptive Bytes Syslog configuration on DarkTrace Show all articles ( 20 ) Collapse Articles Network Storage Appliance Synology (NAS) QNAP (NAS) Microsoft (Windows) ADE - Active Directory Engine Create Microsoft CA How to Install and configure the new Windows Audit package Configure SNMP service on Windows SGBox Agent Centralizing Windows Logs ( Forwarded Events ) Microsoft 365 (Office 365) – SGBox SIEM Integration Guide Configure login auditing MSSQL (SQL Server Management Studio) AWA - Advanced Windows Audit Show all articles ( 1 ) Collapse Articles Antispam Libra ESVA Syslog configuration Web Server software Apache HTTP Server Input Logs Methods Cato Network – SGBox SIEM Integration Guide SCM - System Control Management Dashboards SGBox ETL Dashboard Management Panel – Functionalities and usage Dashboards Users Show SGBox SCMID Configure AD/LDAP Server Configure Strong Authentication Profile Panel - functionalities and usage Group panel - functionalities and usage Network Create an asset Hosts Management Network Panel – Functionalities and usage Add Probe Actions Configure Basic Feed List Upload SGBox custom certificate Tag Panel – Functionalities and usage Applications Packages Management Syslog forwarding from sgbox to another server Export SGBox GPG Key Schedule Application User Behavior Analytics SGBox App Restore Configure Oracle App Configure MySQL App Configure MSSQL App SGBox Backup Show all articles ( 2 ) Collapse Articles Advanced Options Configure a mail server SGBox Alerts SGBox Data Retention User Asset Checking Change your own user settings Notifications LM - Log Management Configuration Automatic Vendor Recognition Directory Import log decryption test Parameter translation SGBox Agent Regex Pattern Syslog Forwarder Online logs manager Analysis The Events Queries (examples) Multiclass Analysis Logs Queries Risk Analysis The Events Queries Class/Pattern Analysis Historical Search Reporting Create Executive Reports Custom Report LCE - Log Correlation Engine Rules Create a correlation rule Default Correlation Rules Explained Multiple events correlation rule LCE Rules Sensors Create a sensor Replace a Sensor with Events Queries Threat Intelligence Queries Threat Intelligence Queries NVS - Network Vulnerabilty Scanner Scan Launch a Scan Prepare an asset to NVS Configure a Qualys probe for SGBox Qualys scan – with Windows authentication Troubleshooting on NVS SM - System Monitoring Configuration Create a new test script Create custom ping script View Change Test Script View test script PB - Playbooks 1 - Playbooks Base Playbooks - Base settings Playbooks - Basic Authentication Playbooks - Generic API 2 - Playbooks Intermediate Playbooks - Create a list Playbooks - Retrieve Logs Playbooks - Retrieve logs (alternative mode) 3 - Playbooks Advanced Playbooks - IF condition Playbooks - Samples Package Playbooks - Trigger Node Playbooks - Trigger with LCE Playbooks - Trigger with Query Playbooks and Dashboards ADE - Active Directory Engine ADE - Active Directory Engine SGBox Clipboard IM - Incident Management Alarm & Incident Management SGBox Clipboard RS - Report System Report Catalog Custom Report - Detailed Report System Multi Tenant Create new tenant Associate Collector to Tenant Create end user access Create new tenant admin Access to remote SGBox Register a collector SGBox CLI Disk management Extend Data Disk (SGBox V4) Extend Full Disk SGBox V5-6 Password management Change CLI Password Reset Admin password Rsyslog configuration Rsyslog TCP support Rsyslog TCP TLS Support Troubleshooting on Collector Troubleshooting on Collector 6 Troubleshooting on SGBox TCPDump and SGTop Configure SGBox IP Configure SGBox Timezone Network debugging Releases 5.x 5.6 5.6.0 5.6.1 5.7 5.7.0 5.7.1 5.8 5.8.0 5.8.1 6.x 6.0 6.0.0 6.0.1 6.0.2 6.0.3 6.0.4 6.0.5 6.0.6 6.0.7 6.1 6.1.0 6.2 6.2.0 6.2.1 6.2.2 6.2.3 6.2.4 6.2.5 6.3 6.3.0 6.3.1 6.3.2 6.4 6.4.0 6.4.2 SGBox Main Versions SGBox Bundle Collector The SGBox Collector (v5) The SGBox Collector (v6) Register a collector SOAR API configuration on Virus Total API configuration on OPSWAT API configuration on Telegram API configuration on MISP Popular Articles Network Requirements First Steps SGBox Agent Microsoft 365 (Office 365) – SGBox SIEM Integration Guide The SGBox Collector (v6) Newest Articles 6.4.2 Dashboards 6.4.0 6.3.2 Online logs manager Recently Updated Articles 6.4.2 SGBox-API Dashboards Prepare an asset to NVS Network debugging - [PROJECTS](https://www.sgbox.eu/en/projects/) - [The Offer of SGBox Products](https://www.sgbox.eu/en/offer-sgbox-products/): The SGBox product offering consists of a progressive licensing plan, able to meet the different security needs depending on the type of business and the data to be analyzed. - [Privacy Policy](https://www.sgbox.eu/en/privacy-policy-sgbox/): The Personal Data collected by this Application, automatically or via third parties, are: Cookies, Usage Data, and Email.Other Personal Data collected could be indicated in other sections of this privacy policy or by dedicated informational text displayed contextually when the Data is collected. The Personal Data may be freely provided by the User, or collected automatically when using this Application. Any use of Cookies – or of other tracking tools – by this Application or by the owners of third party services used, unless stated otherwise, serves to identify Users and remember their preferences, for the sole purpose of providing the service required by the User. Failure to provide certain Personal Data may make it impossible for this Application to provide its services.Users are responsible for any Personal Data of third parties obtained, published, or shared through this Application and confirm that they have the third party’s consent to provide the Data to the Owner. - [The Platform](https://www.sgbox.eu/en/the-platform-sgbox/): SGBox is a Next Generation SIEM & SOAR platform developed for cybersecurity control and management. Its modular and distributed architecture allows its use to be adapted to different business needs. - [EVENT CORRELATION & RESPONSE SYSTEM](https://www.sgbox.eu/en/event-correlation-response-system/): The Event Correlation provides the capability to define rules and detect threat scenarios. SGBox aggregates and analyzes log data from across your network applications, systems and devices, making it possible to discover security threats alerts or trigger automatic countermeasures using scripts or interacting with external systems via API’s. - [nLPD: Swiss federal law on data protection](https://www.sgbox.eu/en/nlpd-federal-law-on-data-protection/): With the revision of the General Data Protection Act (nLPD), important provisions on the processing of personal data have changed since 2023. - [HEALTHCARE SECTOR: protection of personal data and privacy](https://www.sgbox.eu/en/ealthcare-sector/): The healthcare sector is particularly vulnerable to various types of cyber attacks, including: - [LEGAL SECTOR: data protection of law firms](https://www.sgbox.eu/en/legal-sector/): In the legal sector, cybersecurity is critical to protecting the sensitive data of law firms and ensuring customer confidentiality. - [SIEM: Security Information and Event Management](https://www.sgbox.eu/en/security-information-and-event-management/): Security information and Event Management (SIEM) is a solution that allows the centralized collection of all information from multiple devices and security systems, to gain real-time insight into potential threats and respond quickly and effectively to security incidents. - [THREAT INTELLIGENCE FEED: proactive defense against complex threats](https://www.sgbox.eu/en/threat-intelligence-feed/): Threat Intelligence involves gathering and analyzing data to identify potential or actual threats to an IT environment. Security teams look for Indicators of Compromise (IoCs) for persistent threats and zero-day exploits.  - [SOAR: Security Orchestration, Automation and Response](https://www.sgbox.eu/en/soar-security-operation-automation-and-response/): SOAR (Security Orchestration, Automation and Response) is a solution that combines orchestration, automation and response in a single tool, allowing you to address threats quickly and effectively. - [ADVANCED EVENT SEARCH: deeper visibility on connected devices](https://www.sgbox.eu/en/advanced-event-search-2/): Through the Advanced Event Search module, SGBox provides real-time devices health monitoring and offers detailed insights into various problematic areas of the network.  - [NETWORK VULNERABILITY SCANNER: comprehensive threat assessment](https://www.sgbox.eu/en/network-vulnerability-scanner-comprehensive-threat-assessment/): The Network Vulnerability Scanner module integrates the Qualys technology-based scanning engine to perform state-of-the-art and in-depth scans of all existing vulnerabilities. - [INCIDENT MANAGEMENT: management of security incidents](https://www.sgbox.eu/en/incident-management-and-anomalies/): The Incident Management module provides an integrated platform to manage the incidents and anomalies detected from the other SGBox modules.  - [ACTIVE DIRECTORY AUDITOR: advanced report on Active Directory](https://www.sgbox.eu/en/active-directory-auditor-advanced-report-on-active-directory/): Active Directory Auditor (ADA) is a tool designed to constantly monitor the status of Active Directories, determine risk, and warn when set KPI thresholds are exceeded. - [CLOUD SIEM: reduce costs and management efforts with Cloud](https://www.sgbox.eu/en/cloud-siem-reduce-costs-and-management-efforts/): SGBox’s Cloud SIEM takes advantage of the full potential of Security Information and Event Management (SIEM), with the flexibility and ease of use of the Cloud in saas mode (Software as a Service). - [USER BEHAVIOR ANALYTICS (UBA): analysis of user behavior](https://www.sgbox.eu/en/user-behavior-analytics-uba/): User Behavior Analytics (UBA) is a function that tracks and collects information about user behavior using advanced monitoring systems. - [CLOUD LOG MANAGEMENT: simplify the regulatory compliance](https://www.sgbox.eu/en/cloud-log-management/): Cloud Log Management provides the ability to collect, manage, and store logs within SGBox’s Cloud environment, supporting organisations in achieving full regulatory compliance. - [FINANCIAL SECTOR: maximum safety in operations](https://www.sgbox.eu/en/financial-sector/): The financial sector is one of the targets most affected by cyber attacks.  - [UTILITIES SECTOR: protection of critical infrastructure](https://www.sgbox.eu/en/utilities-sector/): In the utilities sector, IT security is crucial to ensure the proper functioning of critical infrastructure, such as grids and distribution systems for electricity, gas or water. - [MANUFACTURING SECTOR: protection of production data](https://www.sgbox.eu/en/manufacturing-sector/): In the manufacturing sector, the convergence between Operational Technology (OT) and Information Technology (IT) leads to the generation of an increasingly number of production data, with a consequent growth of the cyber attack surface. - [PARTNER PROGRAM](https://www.sgbox.eu/en/become-partner/): // partnership - [Become Partner of SGBox](https://www.sgbox.eu/en/become-partner-of-sgbox/): Your name (required) Your email (required) Company (required) Subject (required) Your message Insert the code to send your message: I accept the Privacy Policy - [Request a Demo](https://www.sgbox.eu/en/request-a-demo/): Try SGBox with a free Demo! We are ready to show you the features of the platform Your name (required) Your Email (required) Company (required) Subject (required) Your message Enter the code to send your message: I accept the Privacy Policy - [WHY CHOOSE SGBox](https://www.sgbox.eu/en/why-choose-sgbox/): // Next generation siem & soar platform - [ABOUT US](https://www.sgbox.eu/en/who-we-are/): // who we are - [Guarantor of privacy: measure SA](https://www.sgbox.eu/en/guarantor-of-privacy-system-administartor/): However, the "Provision of system administrators" (published in the G.U. n. 300 of 24 December 2008), issued by the Data Protection Authority, is still current and perfectly integrated with the provisions of the GDPR (in particular Articles 24, "responsibility of the controller" and 32, "security of processing").  - [GDPR: General Data Protection Regulation](https://www.sgbox.eu/en/gdpr-general-data-protection-regulation-2/): Each module, which can be activated individually, has its own specific functionality and cooperates with other modules to share the information collected, facilitating compliance with the requirements imposed by the GDPR. - [FAQs](https://www.sgbox.eu/en/faqs-2/): // FAQ - [Contact Us](https://www.sgbox.eu/en/contact-us/): // contact details - [SGBox – Next Generation SIEM & SOAR Platform](https://www.sgbox.eu/en/): SGBox is an all-in-one, modular and scalable SIEM and SOAR platform that allows you to protect your IT infrastructure by effectively counteracting any type of cyber threat. ## Knowledge Base - [6.4.2](https://www.sgbox.eu/en/knowledge-base/releases-en/6-x/6-4/6-4-2/): A new version of SGBox that improve a lot of backend features and performance has been released - [Dashboards](https://www.sgbox.eu/en/knowledge-base/scm-system-control-management-en/dashboards-it-en-en/dashboards/): In SGBox, key elements and the most important monitoring data are displayed to the administrator immediately after logging in through the Dashboards. - [6.4.0](https://www.sgbox.eu/en/knowledge-base/releases-en/6-x/6-4/6-4-0/): A new version of SGBox that improve a lot of backend features and performance has been released - [6.3.2](https://www.sgbox.eu/en/knowledge-base/releases-en/6-x/6-3/6-3-2/): A new version of SGBox that improve a lot of backend features and performance has been released - [Online logs manager](https://www.sgbox.eu/en/knowledge-base/lm-log-management-en/configuration/online-logs-manager/): This guide explains how to import encrypted raw logs saved on the SGBox disk online, in order to analyze them from the Historical Search page. - [Syslog Forwarder](https://www.sgbox.eu/en/knowledge-base/lm-log-management-en/configuration/syslog-forwarder/): The purpose of the Syslog Forwarder feature in SGBox is not merely log duplication, but the intelligent filtering and selective redistribution of security data. - [API configuration on MISP](https://www.sgbox.eu/en/knowledge-base/soar/api-configuration-on-misp/): This guide describes the installation and configuration of the MISP integration for SGBox. It enables users to make API calls, download feeds into SGBox, and perform cross-analyses between SGBox events and MISP data. - [6.3.1](https://www.sgbox.eu/en/knowledge-base/releases-en/6-x/6-3/6-3-1/): A new version of SGBox that improve a lot of backend features and performance has been released - [Syslog configuration on DarkTrace](https://www.sgbox.eu/en/knowledge-base/client-configuration-en/network-appliance/syslog-configuration-on-darktrace/): Log in to your DarkTrace Management Console. - [Syslog configuration on Deceptive Bytes](https://www.sgbox.eu/en/knowledge-base/client-configuration-en/network-appliance/syslog-configuration-on-deceptive-bytes/): The procedure is carried out primarily within the platform's Management Console. - [Syslog configuration on Sangfor HCI / VDI](https://www.sgbox.eu/en/knowledge-base/client-configuration-en/network-appliance/syslog-configuration-on-sangfor-hci-vdi/): This article explain how to forward logs from Sangfor HCI / VDI to SGBox: Go to System  > Log or Monitor > Log Management - [SGBox Clipboard](https://www.sgbox.eu/en/knowledge-base/active-directory-engine-en/sgbox-clipboard/): Click to open the SGBox Clipboard user guide - [6.3.0](https://www.sgbox.eu/en/knowledge-base/releases-en/6-x/6-3/6-3-0/): A new version of SGBox that improve a lot of backend features and performance has been released - [API configuration on Telegram](https://www.sgbox.eu/en/knowledge-base/soar/api-configuration-on-telegram/): Requirements: - [API configuration on OPSWAT](https://www.sgbox.eu/en/knowledge-base/soar/api-configuration-on-opswat/): In this article is explained how to create your OPSWAT API key and how to configure SGBox PB. - [API configuration on Virus Total](https://www.sgbox.eu/en/knowledge-base/soar/api-configuration-on-virus-total/): In this article is explained how to create your Virus Total API key and how to configure SGBox PB. - [Syslog configuration on Proxmox](https://www.sgbox.eu/en/knowledge-base/client-configuration-en/network-appliance/syslog-configuration-on-proxmox/): apt-get -y install rsyslog - [Syslog configuration on Crowdstrike](https://www.sgbox.eu/en/knowledge-base/client-configuration-en/network-appliance/syslog-configuration-on-crowdstrike/): This guide provides instructions to configure Crodstrike console to send log to SGBox. In order to do that an additional software provided by Crowdstrike must installedi in your environment, alternatively you can use Crowdstrike application provided by SGBox. - [Troubleshooting on NVS](https://www.sgbox.eu/en/knowledge-base/nvs-network-vulnerabilty-scanner-en/troubleshooting-on-nvs/): In this guide, we show you how to perform debugging: to resolve certain issues that may arise on the NVS module and scan it manages. - [Syslog configuration on Cynet](https://www.sgbox.eu/en/knowledge-base/client-configuration-en/cloud-applications-it-en-en/syslog-configuration-on-cynet/): Configure Cynet to send syslog notifications to a remote Syslog. - [Troubleshooting on Collector 6](https://www.sgbox.eu/en/knowledge-base/sgbox-cli-en/troubleshooting-on-collector/troubleshooting-on-collector-6/): In this guide, we show you how to perform debugging: to quickly check if the collector has all the main processes active for correct communication with the Host or SGBox appliance. - [6.2.5](https://www.sgbox.eu/en/knowledge-base/releases-en/6-x/6-2/6-2-5/): A new version of SGBox that improve a lot of backend features and performance has been released - [6.2.3](https://www.sgbox.eu/en/knowledge-base/releases-en/6-x/6-2/6-2-3/): A new version of SGBox that improve a lot of backend features and performance has been released - [6.2.4](https://www.sgbox.eu/en/knowledge-base/releases-en/6-x/6-2/6-2-4/): A new version of SGBox that improve a lot of backend features and performance has been released - [Network debugging](https://www.sgbox.eu/en/knowledge-base/sgbox-cli-en/network-debugging/): In this guide, we show you how to perform network debugging: to quickly check that a port on a server is reachable from SGBox. - [Syslog configuration on Sophos Firewall](https://www.sgbox.eu/en/knowledge-base/client-configuration-en/network-appliance/syslog-configuration-on-sophos-firewall/): to be able to receive logs from Sophos appliance, the syslog must be configured. - [Associate Collector to Tenant](https://www.sgbox.eu/en/knowledge-base/multi-tenant-en/associate-collector-to-tenant/):   - [Alarm & Incident Management](https://www.sgbox.eu/en/knowledge-base/im-incident-management-en/alarm-incident-management/): Click to open the Alarm & Incident Management User Guide - [6.2.2](https://www.sgbox.eu/en/knowledge-base/releases-en/6-x/6-2/6-2-2/): A new version of SGBox that improve a lot of backend features and performance has been released - [Cato Network – SGBox SIEM Integration Guide](https://www.sgbox.eu/en/knowledge-base/client-configuration-en/elementor-33629/): This guide explains how to set up the configuration that allows SGBox to make API calls to the Cato Network service in order to collect events in SIEM and will help you analyze events generated by activities related to Network, Security, Sockets, Cato Clients, and more. - [Qualys scan – with Windows authentication](https://www.sgbox.eu/en/knowledge-base/nvs-network-vulnerabilty-scanner-en/qualys-scan-with-windows-authentication/): This article describes how to configure Qualys Probe to monitor and perform vulnerability assessments on Windows servers with authentication. - [Configure login auditing MSSQL (SQL Server Management Studio)](https://www.sgbox.eu/en/knowledge-base/client-configuration-en/windows-it-en-en/configure-login-auditing-mssql-sql-server-management-studio/): This article describes how to configure login auditing in SQL Server on Windows, to monitor SQL Server Database Engine login activity. Login auditing can be configured to write to the error log on the following events. - [Microsoft 365 (Office 365) – SGBox SIEM Integration Guide](https://www.sgbox.eu/en/knowledge-base/client-configuration-en/windows-it-en-en/microsoft-365-office-365-sgbox-siem-integration-guide/): This Guide explains how to configure SGBox to make API calls to Microsoft 365 (previously called Office 365) with the purpose of collecting events in SGBox SIEM related to activities managed by Microsoft 365. - [6.2.1](https://www.sgbox.eu/en/knowledge-base/releases-en/6-x/6-2/6-2-1/): A new version of SGBox that improve a lot of backend features and performance has been released - [6.2.0](https://www.sgbox.eu/en/knowledge-base/releases-en/6-x/6-2/6-2-0/): A new version of SGBox that improve a lot of backend features and performance has been released - [6.1.0](https://www.sgbox.eu/en/knowledge-base/releases-en/6-x/6-1/6-1-0/): A new version of SGBox that improve a lot of backend features and performance has been released - [Custom Report](https://www.sgbox.eu/en/knowledge-base/lm-log-management-en/custom-report/): Custom reports are used to filter search results and extract information from different classes.To create a Custom report go to LM > Custom Report, this page open the list of existing reports but you can also create a new one. - [LCE Rules](https://www.sgbox.eu/en/knowledge-base/lce-log-correlation-engine-en/rules/lce_rules/): This page allows you to create and edit a rule. - [6.0.7](https://www.sgbox.eu/en/knowledge-base/releases-en/6-x/6-0/6-0-7/): A new version of SGBox that improve features and performance has been released - [The SGBox Collector (v6)](https://www.sgbox.eu/en/knowledge-base/collector-en/the-sgbox-collector-v6/):   - [Custom Report – Detailed](https://www.sgbox.eu/en/knowledge-base/rs-report-system/report-catalog/custom-report-detailed/): In this section you can create report in PDF starting from Custom Report previously configured.From RS > Report Catalog, select  Custom Report - Detailed.  Click on printer icon select timerange and custom report you want use.The generated report will be shown and stored in RS > Report archive. - [Historical Search](https://www.sgbox.eu/en/knowledge-base/lm-log-management-en/analysis-en/historical-search/): This section is used to analyze logs coming from each data source. You can see them in:  LM > Analysis > Historical Search.  - [SIEM solutions integration with Apex Central](https://www.sgbox.eu/en/knowledge-base/client-configuration-en/network-appliance/siem-solutions-integration-with-apex-central/): In order to send logs to SGBox you need to modify first you syslog settings: - [Syslog configuration on Sangfor](https://www.sgbox.eu/en/knowledge-base/client-configuration-en/network-appliance/syslog-configuration-on-sangfor/): In order configure Cyber Command to send logs to SGBox you need to: - [6.0.6](https://www.sgbox.eu/en/knowledge-base/releases-en/6-x/6-0/6-0-6/): A new version of SGBox that improve features and performance has been released - [Syslog configuration on ESET](https://www.sgbox.eu/en/knowledge-base/client-configuration-en/network-appliance/syslog-configuration-on-eset/): If you have a Syslog server running in your network, you can Export logs to Syslog to receive certain events (Detection Event, Firewall Aggregated Event, HIPS Aggregated Event, etc.) from client computers running ESET Endpoint Security. You can also configure ESET PROTECT Server to send Notifications to your Syslog server.  - [Syslog configuration on Cortex](https://www.sgbox.eu/en/knowledge-base/client-configuration-en/network-appliance/syslog-configuration-on-cortex/): Syslog configuration on Cortex XDR  Select Settings → Configurations → Integrations → External Applications.In Syslog Servers, click + New Server.Define the following parameters:Name: for the server profileDestination: IP address or fully qualified domain name (FQDN) of SGBox.port: number on which to send syslog messages.facility: Select one of the syslog standard values. The value maps to how your syslog server uses the facility field to manage messages. For details on the facility field, see RFC 5424Protocol: method of communication with the syslog receiver. TCP: No validation is made on the connection with the syslog receiver. However, if an error occurred with the domain used to make the connection, the Test connection will fail.UDP: No error checking, error correction, or acknowledgment. No validation is done for the connection or when sending data.TCP + SSL: Cortex XDR validates the syslog receiver certificate and uses the certificate signature and public key to encrypt the data sent over the connection. Certificate: The communication between Cortex XDR and the syslog destination can use TLS. In this case, upon connection, Cortex XDR validates that the syslog receiver has a certificate signed by either a trusted root CA or a self-signed certificate. You may need to merge the Root and Intermediate certificate if you receive a certificate error when using a public certificate. If your syslog receiver uses a self-signed CA, upload your self-signed syslog receiver CA. If you only use a trusted root CA leave the certificate field empty. Note: Up to TLS 1.3 is supported. - Make sure the self-signed CA includes your public key.You can ignore certificate errors. For security reasons, this is not recommended. If you choose this option, logs will be forwarded even if the certificate contains errors.Test the parameters to ensure a valid connection, and click Create when ready For more information visit this link - [User Asset Checking](https://www.sgbox.eu/en/knowledge-base/scm-system-control-management-en/advanced-options-it-en-en/user-asset-checking/): The purpose of this feature is to limit the visibility of a user on a set of hosts present on SGBox, showing only those that are part of an asset to which his user is assigned. - [Syslog configuration on Cisco WLC](https://www.sgbox.eu/en/knowledge-base/client-configuration-en/network-appliance/syslog-configuration-on-cisco-wlc/): Syslog configuration on WLC ( GUI ) Go to Management > Logs > Config. The Syslog Configuration (GUI) age appears: Enter the Syslog Server IP Address and click Add. You can add up to three syslog servers to the controller. The list of syslog servers that have already been added to the controller appears under this text box. If you want to remove a syslog server from the controller, click Remove to the right of the desired server.To set the Syslog Level (severity) for filtering syslog messages to the syslog servers, choose one of the next options from the Syslog Level drop-down list:Emergencies= Severity level 0Alerts= Severity level 1 (default value)Critical= Severity level 2Errors= Severity level 3Warnings= Severity level 4Notifications= Severity level 5Informational= Severity level 6Debugging= Severity level 7 NOTE: If you set a syslog level, only those messages whose severity is equal to or less than that level are sent to the syslog servers. For example, if you set the syslog level to Notifications (severity level 5), only those messages whose severity is betwen 0 and 5 are sent to the syslog servers.NOTE: If you have enabled logging of Debugging messages to the logging buffer, some messages from application debug could be listed in message log with severity that is more than the level set. For example, if you execute the debug client mac-addr command, the client event log could be listed in message log even though the message severity level is set to Errors.To set the Syslog Facility for outgoing syslog messages to the syslog servers, choose one of these options from the Syslog Facility drop-down list:Kernel= Facility level 0User Process= Facility level 1Mail= Facility level 2System Daemons= Facility level 3Authorization= Facility level 4Syslog = Facility level 5 (default value)Line Printer= Facility level 6USENET= Facility level 7Unix-to-Unix Copy= Facility level 8Cron= Facility level 9FTP Daemon= Facility level 11System Use 1= Facility level 12System Use 2= Facility level 13System Use 3= Facility level 14System Use 4= Facility level 15Local Use 0= Facility level 16Local Use 2= Facility level 17Local Use 3= Facility level 18Local Use 4= Facility level 19Local Use 5= Facility level 20Local Use 5= Facility level 21Local Use 5= Facility level 22Local Use 5 = Facility level 23NOTE: For example, selecting Kernel makes only kernel related messages to be sent. Authorization, makes only AAA related messages to be sent, and so on. Click Apply. Configuring Syslog on WLC ( CLI ) Enable system logging and set the IP address of the syslog server to which to send the syslog messages by entering this command: (Cisco Controller) >config logging syslog host server_IP_addressTo remove a syslog server from the controller by entering this command:(Cisco Controller) >config logging syslog host server_IP_address delete Set the severity level for filtering syslog messages to the syslog server by entering this command: (Cisco Controller) >config logging syslog level severity_level - [QNAP (NAS)](https://www.sgbox.eu/en/knowledge-base/client-configuration-en/storage-it-en-en/syslog-configuration-on-qnap/): Here the steps to send logs to SGBox.  ## Portfolios - [Si Collection](https://www.sgbox.eu/portfolio/case-study-sgbox-si-collection/): Si Collection S.p.A. è una delle realtà più consolidate nel mercato italiano per i servizi di “Credit Management” conto terzi, con oltre 30 anni di esperienza nel settore. - [AIL – Aziende Industriali Lugano](https://www.sgbox.eu/portfolio/case-study-ail-aziende-industriali-lugano/): Aziende Industriali Lugano (AIL) is the most important retail and wholesale distributor of water, natural gas, and electricity in the Canton of Ticino. - [AIL – Aziende Industriali Lugano](https://www.sgbox.eu/portfolio/case-study-ail/): Aziende Industriali Lugano (AIL) è il più importante distributore al dettaglio e all'ingrosso di acqua, gas naturale ed energia elettrica del Canton Ticino. I loro prodotti e servizi sono acquistati quotidianamente da oltre 110000 clienti privati e aziendali, distribuiti in circa 54 Comuni. - [Robintour Travel Group](https://www.sgbox.eu/portfolio/robintour-travel-group/): Robintur Travel Group è uno dei principali attori della distribuzione turistica italiana. Opera nei segmenti leisure (viaggi individuali e di gruppo) attraverso varie società e una rete di vendita di circa 300 agenzie viaggi a insegna Robintur o Viaggi Coop.  - [Comune di Modena](https://www.sgbox.eu/portfolio/comune-di-modena/): Tutte le realtà aziendali, comprese quelle della pubblica amministrazione, non possono sottrarsi agli adempimenti di legge in materia di protezione dei dati e privacy.  - [Amaro Montenegro](https://www.sgbox.eu/portfolio/case-study-amaro-montenegro/): Gruppo Montenegro è una realtà imprenditoriale italiana leader di mercato nel settore delle bevande alcoliche che vanta marchi da sempre nell’immaginario degli italiani tra cui Amaro Montenegro che ancora oggi, dal 1885, è il simbolo della tradizione e dell’eccellenza italiana nel campo della produzione di liquori.