Send system events to a SIEM solution
- In the management console, on the menu bar, click Settings > External integration > SIEM connectors.
-
Click
.
- In the Name field, type a name for the connector.
- In the Connector format drop-down list, click a logging and auditing file format.
- In the SIEM endpoint server name field, type the SIEM server name.
- In the Port field, type the port of the SIEM server.
- To use a TLS connection and host validation, verify that the Enable TLS and Enable host validation check boxes are selected.
-
From the Status drop-down list, select one of the following:
- To use the connector, click Enabled.
- To turn off the connector, click Disabled.
- Click Save.
- If you enabled a TLS connection, in Settings > External integration > Trusted certificates, click
beside SIEM server trusts to upload a trust certificate.
- To see a list of auditable events, click Settings > Infrastructure > Audit Settingsand click
. In the Security event audit settings section, click
.