How to integrate a SIEM server with a tenant
- 1 minute to read
- Print
- DarkLight
- PDF
How to integrate a SIEM server with a tenant
- 1 minute to read
- Print
- DarkLight
- PDF
Article summary
Did you find this summary helpful?
Thank you for your feedback
This tutorial presents a step-by-step process on how to add SIEM integrations to a tenant in Cloud Security.
Requirements
- Have the role Cloud Security - Tenant Administrator.
- Have one or more SIEM sockets configured in a third-party service.
Add a SIEM server integration
- On Cloud Security, click the User menu icon on the top right corner of the screen.
- In the dropdown menu, select Admin console.
- Under Tenant settings, select SIEM Servers.
- Click + Add.
- Fill in the fields as follows:
- Name: type a name for the SIEM integration being created.
- Address: in the select field, choose between:
- DNS: add the full hostname of the SIEM socket.
- IPv4: add the IP address of the SIEM socket.
- Port: add the listener port that should receive the logs.
- Protocol: in the select field, choose between TCP or UDP.
- Message type: in the select field, choose between Syslog or CEF.
- Use TLS: in the select field, select Yes to enable the TLS handshake for communication with the SIEM socket or choose No if Cloud Security should not initiate a TLS handshake.
- Click Add.
Was this article helpful?