Skip to content

Commit ae5688a

Browse files
defguard-communitygitbook-bot
authored andcommitted
GITBOOK-463: change request with no subject merged in GitBook
1 parent 7a40d76 commit ae5688a

File tree

26 files changed

+49
-78
lines changed

26 files changed

+49
-78
lines changed

SUMMARY.md

Lines changed: 16 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -38,10 +38,10 @@
3838
* [External OpenID providers](admin-and-features/external-openid-providers/README.md)
3939
* [Google](admin-and-features/external-openid-providers/google.md)
4040
* [Microsoft](admin-and-features/external-openid-providers/microsoft.md)
41-
* [Zitadel](admin-and-features/external-openid-providers/zitadel.md)
42-
* [Keycloak](admin-and-features/external-openid-providers/keycloak.md)
43-
* [JumpCloud](admin-and-features/external-openid-providers/jumpcloud.md)
4441
* [Okta](admin-and-features/external-openid-providers/okta.md)
42+
* [JumpCloud](admin-and-features/external-openid-providers/jumpcloud.md)
43+
* [Keycloak](admin-and-features/external-openid-providers/keycloak.md)
44+
* [Zitadel](admin-and-features/external-openid-providers/zitadel.md)
4545
* [Custom](admin-and-features/external-openid-providers/custom.md)
4646
* [External OIDC secure enrollment](admin-and-features/external-openid-providers/external-oidc-secure-enrollment.md)
4747
* [LDAP and Active Directory integration](admin-and-features/ldap-and-active-directory-integration/README.md)
@@ -52,23 +52,23 @@
5252
* [ACL Aliases](admin-and-features/access-control-list/acl-aliases.md)
5353
* [Implementation Details](admin-and-features/access-control-list/firewall-internals.md)
5454
* [Network devices](admin-and-features/network-devices.md)
55-
* [Activity & Audit logs](admin-and-features/activity-log/README.md)
56-
* [Audit Log Streaming to SIEM systems](admin-and-features/activity-log/activity-log-streaming/README.md)
57-
* [Supported SIEM systems integrations](admin-and-features/activity-log/activity-log-streaming/activity-log-integrations/README.md)
58-
* [Vector integration guide](admin-and-features/activity-log/activity-log-streaming/activity-log-integrations/vector-integration-guide.md)
59-
* [Logstash integration guide](admin-and-features/activity-log/activity-log-streaming/activity-log-integrations/logstash-integration-guide.md)
60-
* [Notifications](admin-and-features/notifications/README.md)
61-
* [Email notifications](admin-and-features/notifications/setting-up-smtp-for-email-notifications.md)
62-
* [Gateway notifications](admin-and-features/notifications/gateway-notifications.md)
63-
* [New version notifications](admin-and-features/notifications/new-version-notifications.md)
64-
* [Integrations](admin-and-features/integrations/README.md)
65-
* [Webhooks](admin-and-features/integrations/webhooks.md)
66-
* [REST API](admin-and-features/integrations/api-tokens.md)
55+
* [Activity & Audit logs](activity-log/README.md)
56+
* [Audit Log Streaming to SIEM systems](activity-log/activity-log-streaming/README.md)
57+
* [Supported SIEM systems integrations](activity-log/activity-log-streaming/activity-log-integrations/README.md)
58+
* [Vector integration guide](activity-log/activity-log-streaming/activity-log-integrations/vector-integration-guide.md)
59+
* [Logstash integration guide](activity-log/activity-log-streaming/activity-log-integrations/logstash-integration-guide.md)
60+
* [Notifications](notifications/README.md)
61+
* [Email notifications](notifications/setting-up-smtp-for-email-notifications.md)
62+
* [Gateway notifications](notifications/gateway-notifications.md)
63+
* [New version notifications](notifications/new-version-notifications.md)
64+
* [Integrations](integrations/README.md)
65+
* [Webhooks](integrations/webhooks.md)
66+
* [REST API](integrations/api-tokens.md)
6767
* [OPSense Configuartion](admin-and-features/setting-up-your-instance/gateway/README.md)
6868
* [SSH Authentication](admin-and-features/ssh-authentication.md)
6969
* [Forward auth](admin-and-features/forward-auth.md)
7070
* [YubiKey Provisioning](admin-and-features/yubikey-provisioning.md)
71-
* [User SNAT bindings](admin-and-features/user-snat-bindings.md)
71+
* [User SNAT bindings](user-snat-bindings.md)
7272

7373
## Deployment strategies
7474

admin-and-features/activity-log/README.md renamed to activity-log/README.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ Activity log is available as a dedicated page in Defguard core Web UI that's use
1212

1313
To access it click the `Activity log` button in the navbar.
1414

15-
<figure><img src="../../.gitbook/assets/image.png" alt=""><figcaption><p>Activity log page</p></figcaption></figure>
15+
<figure><img src="../.gitbook/assets/image.png" alt=""><figcaption><p>Activity log page</p></figcaption></figure>
1616

1717
### Overview
1818

@@ -35,12 +35,12 @@ Currently there are four modules:
3535

3636
* **Defguard** - operations performed in the core Web UI (e.g. adding users, modifying devices, managing groups etc.)
3737
* **Client** - actions performed by desktop client applications
38-
* **Enrollment** - events related to the [user enrollment](../../help/enrollment/) process
38+
* **Enrollment** - events related to the [user enrollment](../help/enrollment/) process
3939
* **VPN -** events related to VPN clients (e.g. client connecting to a location)
4040

4141
### Filtering
4242

43-
<figure><img src="../../.gitbook/assets/image (1).png" alt=""><figcaption><p>Event filter modal</p></figcaption></figure>
43+
<figure><img src="../.gitbook/assets/image (1).png" alt=""><figcaption><p>Event filter modal</p></figcaption></figure>
4444

4545
By clicking the `Filter` button above the list you can narrow down the displayed events based on following criteria:
4646

@@ -52,7 +52,7 @@ For each of those you can select multiple options.
5252

5353
Filtering by date can be done by clicking the `Time range` button above the list.
5454

55-
<figure><img src="../../.gitbook/assets/image (2).png" alt=""><figcaption><p>Time range filter modal</p></figcaption></figure>
55+
<figure><img src="../.gitbook/assets/image (2).png" alt=""><figcaption><p>Time range filter modal</p></figcaption></figure>
5656

5757
### Sorting
5858

admin-and-features/activity-log/activity-log-streaming/README.md renamed to activity-log/activity-log-streaming/README.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ description: >-
88
# Audit Log Streaming to SIEM systems
99

1010
{% hint style="warning" %}
11-
This is an enterprise feature. To use it, purchase our [enterprise license](../../../enterprise/license.md) or ensure that your deployment does not exceed the [usage limits](../../../enterprise/license.md#enterprise-is-free-up-to-certain-limits).
11+
This is an enterprise feature. To use it, purchase our [enterprise license](../../enterprise/license.md) or ensure that your deployment does not exceed the [usage limits](../../enterprise/license.md#enterprise-is-free-up-to-certain-limits).
1212
{% endhint %}
1313

1414
{% hint style="info" %}
Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
description: List of supported services to stream activity logs into.
33
---
44

5-
# Activity log integrations
5+
# Supported SIEM systems integrations
66

77
{% hint style="info" %}
88
We're actively working to expand support for additional SIEM and log management platforms. If your organization uses a tool that's not currently supported, we welcome your feedback—user requests help us prioritize future integrations.
Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -40,15 +40,15 @@ Add Logstash service to the `docker-compose.yaml` and start it.
4040
4141
### Add Logstash destination
4242
43-
In Defguard UI with an administrator account, go into settings page and choose `Activity log streaming`.
43+
In Defguard UI with an administrator account, go into settings page and choose `Activity log streaming`.
4444

4545
Click `Add new` and choose `Vector` destination.
4646

47-
<figure><img src="../../../../.gitbook/assets/image (111).png" alt=""><figcaption></figcaption></figure>
47+
<figure><img src="../../../.gitbook/assets/image (111).png" alt=""><figcaption></figcaption></figure>
4848

4949
Fill out `Name` and `Url` fields and click **Submit**.
5050

51-
<figure><img src="../../../../.gitbook/assets/image (112).png" alt=""><figcaption></figcaption></figure>
51+
<figure><img src="../../../.gitbook/assets/image (112).png" alt=""><figcaption></figcaption></figure>
5252

5353
That's it! Defguard should now be sending activity events to Logstash, and you should see them printed to `stdout` in the running Logstash container.
5454

@@ -78,7 +78,7 @@ output {
7878

7979
Modify Logstash destination in settings and fill`username` and `password` in settings.
8080

81-
<figure><img src="../../../../.gitbook/assets/image (113).png" alt=""><figcaption></figcaption></figure>
81+
<figure><img src="../../../.gitbook/assets/image (113).png" alt=""><figcaption></figcaption></figure>
8282

8383
### Logstash integration configuration
8484

Lines changed: 5 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -58,17 +58,17 @@ INFO vector::app: Loading configs. paths=["/etc/vector/vector.toml"]
5858
5959
### Add Vector destination
6060
61-
In Defguard UI with an administrator account, go into settings page and choose `Activity log streaming`.
61+
In Defguard UI with an administrator account, go into settings page and choose `Activity log streaming`.
6262
6363
Click `Add new` and choose `Vector` destination.
6464
65-
<figure><img src="../../../../.gitbook/assets/image (107).png" alt=""><figcaption></figcaption></figure>
65+
<figure><img src="../../../.gitbook/assets/image (107).png" alt=""><figcaption></figcaption></figure>
6666
6767
Fill out `Name` and `Url` of the form and click `Submit`.
6868
6969
If your `defguard` instance is running in the same Docker Compose network as Vector, use `http://vector:8001` as the URL instead of `http://127.0.0.1`, since services in the same Compose network communicate by container name.
7070
71-
<figure><img src="../../../../.gitbook/assets/image (108).png" alt=""><figcaption></figcaption></figure>
71+
<figure><img src="../../../.gitbook/assets/image (108).png" alt=""><figcaption></figcaption></figure>
7272
7373
That's it! Defguard should now be sending activity events to Vector, and you should see them printed to `stdout` in the running Vector container.
7474
@@ -93,7 +93,7 @@ sources:
9393

9494
Next, add the configured `username` and `password` in Defguard settings to the Vector destination.
9595

96-
<figure><img src="../../../../.gitbook/assets/image (109).png" alt=""><figcaption></figcaption></figure>
96+
<figure><img src="../../../.gitbook/assets/image (109).png" alt=""><figcaption></figcaption></figure>
9797

9898
### TLS
9999

@@ -139,9 +139,8 @@ sources:
139139
140140
Next, copy the contents of `cert.pem` into the **Certificate** field in the Vector destination settings. Then, update the **URL** field to use the `https` scheme instead of `http`.
141141

142-
<figure><img src="../../../../.gitbook/assets/image (110).png" alt=""><figcaption></figcaption></figure>
142+
<figure><img src="../../../.gitbook/assets/image (110).png" alt=""><figcaption></figcaption></figure>
143143

144144
### Vector integration configuration
145145

146146
<table data-full-width="true"><thead><tr><th>Name</th><th width="203.7999267578125">Example value</th><th width="111.199951171875" data-type="checkbox">Required</th><th width="179">Vector related configuration</th><th>Description</th></tr></thead><tbody><tr><td>Name</td><td>Vector</td><td>true</td><td></td><td>Assigned name for the destination.</td></tr><tr><td>Url</td><td>http(s)://127.0.0.1:8001</td><td>true</td><td><a href="https://vector.dev/docs/reference/configuration/sources/http_server/#address">address</a></td><td>Address of running vector HTTP source.</td></tr><tr><td>Username</td><td>vector</td><td>false</td><td><a href="https://vector.dev/docs/reference/configuration/sources/http_server/#auth.username">auth.username</a></td><td>username for Basic Authentication</td></tr><tr><td>Password</td><td>strongPassword</td><td>false</td><td><a href="https://vector.dev/docs/reference/configuration/sources/http_server/#auth.password">auth.password</a></td><td>password for Basic Authentication</td></tr><tr><td>Cert</td><td>contents of cert.pem</td><td>false</td><td><a href="https://vector.dev/docs/reference/configuration/sources/http_server/#tls">tls</a></td><td>Used for TLS connection</td></tr></tbody></table>
147-

admin-and-features/external-openid-providers/custom.md

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,3 @@
1-
---
2-
hidden: true
3-
---
4-
51
# Custom
62

73
{% hint style="warning" %}

admin-and-features/external-openid-providers/google.md

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,3 @@
1-
---
2-
hidden: true
3-
---
4-
51
# Google
62

73
{% hint style="info" %}

admin-and-features/external-openid-providers/jumpcloud.md

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,3 @@
1-
---
2-
hidden: true
3-
---
4-
51
# JumpCloud
62

73
1. Login to your JumpCloud admin account.
Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,3 @@
1-
---
2-
hidden: true
3-
---
4-
51
# Keycloak
62

73
A basic guide about securing applications using Keycloack can be found [here](https://www.keycloak.org/getting-started/getting-started-docker#_secure_the_first_application).

0 commit comments

Comments
 (0)