Cloud SOAR Bridge
You can only run custom actions or integrations outside of the Sumo Logic cloud in an "on-premise" environment. For on-premise environments, you need to install a bridge as described below.
Requirements
Hardware requirements
- OS:
- Ubuntu (18.04/20.04)
- CentOS 7
- RedHat 8
- RAM: 8GB
- CPU: 4 Core
- DISK: 160GB
- Network card: 1
Network requirements
The Bridge has to be able to resolve DNS host names and needs to reach the below destinations:
DESTINATION | PROTOCOL | PORT |
---|---|---|
sumo-logic-api-url | TCP | 443 |
siem-cloud-url | TCP | 443 |
926226587429.dkr.ecr.us-west-2.amazonaws.com | TCP | 443 |
926226587429.dkr.ecr.us-east-1.amazonaws.com | TCP | 443 |
926226587429.dkr.ecr.ap-southeast-2.amazonaws.com | TCP | 443 |
926226587429.dkr.ecr.eu-central-1.amazonaws.com | TCP | 443 |
926226587429.dkr.ecr.ap-south-1.amazonaws.com | TCP | 443 |
926226587429.dkr.ecr.ap-northeast-1.amazonaws.com | TCP | 443 |
926226587429.dkr.ecr.ca-central-1.amazonaws.com | TCP | 443 |
926226587429.dkr.ecr.eu-west-1.amazonaws.com | TCP | 443 |
index.docker.io* | TCP | 443 |
registry-1.docker.io* | TCP | 443 |
auth.docker.io* | TCP | 443 |
production.cloudflare.docker.com* | TCP | 443 |
long-endpoint1-events.sumologic.net | TCP | 443 |
* Needed only to connect to Docker hub.
Install Docker
- Install Docker-CE following the installation instructions in Docker Docs. Install at least version 20.10 (do not use nightly build).
- As soon as the Docker daemon is installed, start it with:
systemctl start docker
- Enable it on boot:
systemctl enable docker
Using a proxy
- If Docker has to use a proxy to pull images, follow the below instructions:
mkdir -p /etc/systemd/system/docker.service.d
- Create a file named
/etc/systemd/system/docker.service.d/http-proxy.conf
, and add:[Service]
Environment="HTTP_PROXY=http://proxy.example.com:8080"
Environment="HTTPS_PROXY=http://proxy.example.com:8080" - Reload the systemd daemon with:
systemctl daemon-reload
- And restart Docker service with:
systemctl restart docker
Get installation token
Log in to Sumo Logic and create a new installation token with name prefix csoar-bridge-token
.
![Installation token](/img/cse/automations-bridge-installation-token.png)
Automation bridge installation
Ubuntu
- Click the ? icon in the top right.
- In the Automation Bridge Manual box, click UBUNTU.
- Click Download to download the
automation-bridge-X.X.deb
file. - Copy the file to the bridge virtual machine.
- To install the package run from ssh:
sudo dpkg -i automation-bridge-X.X.deb