Device Integration: Nozomi Networks

Modified on Mon, 24 Aug at 1:45 PM

TABLE OF CONTENTS


Overview

Nozomi Networks provides advanced OT, ICS, IoT, and IT visibility, monitoring, and threat detection. By integrating Nozomi Networks with ADR SIEM, organizations gain centralized visibility and proactive threat detection across IT/OT environments. Logs and events are forwarded to the ADR APE (Analytics and Policy Engine) through the CCE (Collection and Control Engine).


Prerequisites

Before configuration, ensure the following:

  • Administrative access to the Nozomi Networks console.

  • IP address of the ADR CCE server.

  • Syslog (UDP/514) allowed between Nozomi and ADR CCE (for syslog integration).


Syslog Integration Steps

  1. Log in to the Nozomi Networks console with admin rights.

  2. Navigate to: Settings → Integrations → Syslog.

  3. Click Add Syslog Server.

  4. Configure the following parameters:

    • Name: ADR CCE

    • Server IP/Host: Enter ADR CCE IP

    • Port: 514

    • Protocol: UDP

    • Format: CEF or JSON (ensure consistent parsing in ADR SIEM)

    • Facility/Severity: Default or as per organizational policy

  5. Save and Apply configuration.


Verification (MSSP Only)

From ADR UI

  1. Log in to the ADR SIEM UI with admin rights.

  2. Navigate to: System → Logs and Flows Collection Status.

  3. Verify that the SOURCE DEVICE IP of the Nozomi device is visible and logs/events are ingested.

From CCE Server

Run the following commands to verify log/flow collection:

  • For Syslog:

    sudo tcpdump -i any port 514 and host <Nozomi_IP> -AAA

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article