Skip Navigation

Send system events to a SIEM solution

Security Information and Event Management (SIEM) software collects, analyzes, and aggregates security data from multiple sources to detect potential security threats. To send 
 system events to your organization’s SIEM software, you can add a SIEM connector. Currently, adding a SIEM connector is supported for 
 on-premises only.
  1. On the menu bar, click 
    Settings > External integration > SIEM connectors
  2. Click The Add icon.
  3. In the 
     field, type a name for the connector.
  4. In the 
    Connector format
     drop-down list, click a logging and auditing file format.
  5. In the 
    SIEM endpoint server name
     field, type the SIEM server name.
  6. In the 
     field, type the port of the SIEM server.
  7. To use a TLS connection and host validation, verify that the 
    Enable TLS
    Enable host validation
     check boxes are selected.
  8. In the 
     drop-down list, do one of the following:
    • Click 
       to use the connector.
    • Click 
       to turn off the connector.
  9. Click 
If you enabled a TLS connection, in 
Settings > External integration > Trusted certificates
, click The Add icon beside 
SIEM server trusts
 to upload a trust certificate.