SIEM

MetaDefender Cloud Email Security ™ allows integration with external SIEM systems. Follow the steps below to configure a provider.

Supported Integrations

Elasticsearch

Use this option to forward events directly to an Elasticsearch cluster.

Configuration Steps

  1. Select Elasticsearch under Service Selection.

  2. Endpoint URL Enter the Elasticsearch endpoint, for example: https://<host>:9200

  3. Authentication Type Select Basic Authentication.

  4. Authentication Details

    • Username: Enter the Elasticsearch username.

    • Password: Enter the corresponding password.

  5. Event Filters

    • Enable Send Events to forward events.

    • Select one or more Statuses, such as:

      • Closed Without Action

      • Deleted

      • Delivered

      • Failed to Deliver

      • Investigating

      • Quarantined

      • Released

      • Rescanning

    • Select one or more Verdicts, such as:

      • Malicious

      • Suspicious

      • Sanitized

      • No threat detected

      • Encrypted content

      • Unsupported file type

      • Invalid file structure

      • Failure to analyze

      • Skipped

      • Sanitization policy error

  6. Audit Log Filters

    • Enable Send Audit Logs to forward administrative activity.

    • Select Event Types, such as:

      • Authentication

      • Configuration

  7. Click Save Changes to apply the configuration.

Generic HTTP

Use this option to forward events to a custom HTTP endpoint or third-party SIEM service.

Configuration Steps

  1. Select HTTP under Service Selection.

  2. Endpoint URL Enter the destination service endpoint, for example: https://<host>:8080

  3. API Key Specify the API key required by the destination service.

  4. Event Filters

    • Enable Send Events to forward events.

    • Configure Status and Verdict filters as needed.

  5. Audit Log Filters

    • Enable Send Audit Logs to forward audit events.

    • Select relevant Event Types (for example, Authentication or Configuration).

  6. Click Save Changes to apply the configuration.

IP ranges

See Locations for the list of IP addresses from which MetaDefender Cloud Email Security ™ sends SIEM data.

JSON Output Reference

Common Fields

Event Fields

Processing Details

Metadata

Overall Scan Result

Parts

Audit History

Audit Fields

Connection Test Fields