SIEM Integration

'SIEM Integration' option allows you to forward data from ADAuditPlus to an external SIEM product or to a Syslog Server in real time.

You can choose to forward

 

Forwarding ADAudit Plus data to a Syslog Server

Syslog is the event logging service in unix systems.You may also use this setting to forward to your SIEM's UDP or TCP Receiver.

Configuring a Syslog Server:

Steps to enable Syslog Logging in ADAuditPlus:

  1. Click on 'Admin' Tab → 'SIEM Integration'.
  2. Tick the 'Enable' checkbox and choose the 'Syslog' radio button.
  3. Enter the Syslog server name. Ensure that the Syslog server is reachable from the ADAuditPlus server.
  4. Enter Syslog port number and protocol.
  5. Choose Syslog standard and data format as required by your SIEM Parser.
  6. After saving this configuration, Choose the categories to forward.

 

Forwarding ADAudit Plus data to an external SIEM product : Splunk HTTP

Configuring Splunk Http Event Collector:

Steps to enable Splunk forwarding in ADAuditPlus:

  1. Click on 'Admin' Tab → 'SIEM Integration'.
  2. Tick the 'Enable' Checkbox and choose the 'Splunk' Radio Button.
  3. Enter the Splunk Server name. Ensure that the Splunk Server is reachable from the ADAuditPlus Server.
  4. Enter Splunk Http Event Collector port number and protocol.
  5. Specify the Http Event Collector token generated in Splunk for ADAuditPlus.
  6. After saving this configuration, Choose the categories to forward.

 

Forwarding ADAudit Plus data to an external SIEM product : ArcSight

Steps to enable ArcSight forwarding in ADAuditPlus:

  1. Click on 'Admin' Tab → 'SIEM Integration'.
  2. Tick the 'Enable' Checkbox and choose the 'ArcSight' Radio Button.
  3. Enter the ArcSight Server name. Ensure that the ArcSight Server is reachable from the ADAuditPlus Server.
  4. Enter the ArcSight collector port number and protocol.
  5. After saving this configuration, Choose the categories to forward.

ArcSight CEF Key Mappings

 

The forwarded ADAudit Plus events can be searched, grouped into reports and categorized as needed in your SIEM product.

Copyright © 2014, ZOHO Corp. All Rights Reserved.
ManageEngine