New to Advanced Reporting Tool or Siem feeder?
Here are some helpful links to get you started:
About the Advanced Reporting Tool
About the Advanced Visualization Tooll
Configure and Run Event Importer
Gill McDonald | WatchGuard Representative
WatchGuard Technologies, Inc.
0
Sign In to comment.
Comments
Subject: SIEMFeeder Event Importer connected to Azure Service Bus but receiving zero events — how to enable endpoint forwarding?
Hi everyone,
I'm setting up SIEMFeeder to forward EPDR events to our internal SIEM. I have a trial license active until 2026-05-24 for our WatchGuard Endpoint Security 360 account (56 endpoints).
Current status:
What I've verified:
Questions:
1. Is there a specific step required to enable EPDR event forwarding to the Service Bus topic, beyond activating the trial license?
2. Should SIEMFeeder appear as a configurable module/policy inside the Endpoint Security console? We see nothing there.
3. Does Event Importer need to run inside the same network as the EPDR endpoints, or is a cloud/VPS deployment supported?
4. Is there a way to verify whether the Service Bus topic is actually receiving events from WatchGuard's side?
Any help or guidance from someone who has SIEMFeeder working would be much appreciated. Thank you.
Hello, @Angel
Without data, we cannot know what the issue is in your specific case.
So the best thing to do here is to open a case with support so they can start analysing it from provision to packet-send and identify where the error might be.
David Carro | Technical support
WatchGuard Technologies, Inc. | www.watchguard.com