Hi,
I couldn’t find any information regarding the network requirements for firewall rules related to the Remote Agent. Could someone provide the necessary addresses and details?
Thanks in advance!
Solved! Go to Solution.
When I checked the agent’s Docker container logs, I noticed that it couldn’t reach <customerid>.siemplify-soar.com. After allowing access to this address, the issue was resolved. It seems that each Chronicle instance has its own dedicated Siemplify SOAR endpoint.
Please take a look at this doc to see if it helps.
Hi, I’ve seen this document before, but unfortunately, it doesn’t provide the URLs or IP addresses. Therefore, it won’t be helpful for me to configure my firewall rules.
Hi @tnxtr , Specific URLs, For both SIEM and SOAR agents:
malachiteingestion-pa.googleapis.com
malachiteingestion-pa.googleapis.com
(e.g., asia-northeast1-malachiteingestion-pa.googleapis.com
, europe-west2-malachiteingestion-pa.googleapis.com
, etc.). The specific regional endpoints will depend on your Google Cloud region.accounts.google.com
oauth2.googleapis.com.
Additional URLs for SOAR agents:PROXY_ADDRESS
, HTTP_PROXY
, HTTPS_PROXY
, and NO_PROXY
.
When I checked the agent’s Docker container logs, I noticed that it couldn’t reach <customerid>.siemplify-soar.com. After allowing access to this address, the issue was resolved. It seems that each Chronicle instance has its own dedicated Siemplify SOAR endpoint.