SIEM Settings tab¶
Note
To view the SIEM Settings tab, the option to use SIEM must be enabled in the organization settings.
If you want to use SIEM, please contact your service partner.
SIEM Settings tab
In the SIEM Settings tab, you will find an overview of all the information and settings available to you for managing a company's users.
The following options are available:
| Name | Definition |
|---|---|
| SIEM provider | Defines the SIEM provider.NoteCurrently, only Splunk is supported as an HTTP Event Collector (HEC). |
| Host | Defines the name of the host for data transfer. |
| Port | Defines the port of a host for the connection used to transfer data. |
| API tokens | Defines the API token for authentication with the host.NoteThe API token used must be a HEX token. |
The following information is shown in the SIEM log when SIEM is activated:
Table 1: Data recorded in the SIEM log
| Function | Event |
|---|---|
| Mitigation | Automatic mitigation started |
| Automatic mitigation completed | |
| Start Manual mitigation | |
| Stop manual mitigation | |
| User management | Add account |
| Delete account | |
| Verify email | |
| Reset password | |
| Enable and disable 2FA |