This document provides information on how to add SIEM integrations to a tenant in Cloud Security.
Requirements
- User with the Cloud Security - Tenant Administrator role.
- One or more SIEM sockets configured in a third-party service.
Integrate a SIEM server with a tenant
To integrate a SIEM server with a tenant, see the following steps:
- Access Cloud Security.
- Click the User menu icon located on the top right corner of your screen.
- In the dropdown menu, click Settings.
- In the Settings menu, click Admin console.
- In the Tenant settings section, click SIEM Servers.
- Click + Add.
- In the Name * field, enter a name for the SIEM integration.
- In the Address * field, choose between:
- DNS: enter the full hostname of the SIEM socket.
- IPv4: enter the SIEM socket’s IP address.
- In the Port * field, enter the listener port to receive the logs.
- In the Protocol * field, select the protocol between TCP and UDP.
- In the Message type * field, select the message type between CEF and Syslog.
- In the Use TLS * field, select if TLS handshake should be used for communication with the SIEM socket.
- Click Add.
After completing these steps, the SIEM Servers report will display the new SIEM integration.