Title
Create new category
Edit page index title
Edit category
Edit link
SIEM
MetaDefender Cloud Email Security ™ allows integration with external SIEM systems. Follow the steps below to configure a provider.
Supported Integrations
Elasticsearch
Use this option to forward events directly to an Elasticsearch cluster.
Configuration Steps
Select Elasticsearch under Service Selection.
Endpoint URL Enter the Elasticsearch endpoint, for example:
https://<host>:9200Authentication Type Select Basic Authentication.
Authentication Details
Username: Enter the Elasticsearch username.
Password: Enter the corresponding password.
Event Filters
Enable Send Events to forward events.
Select one or more Statuses, such as:
Closed Without Action
Deleted
Delivered
Failed to Deliver
Investigating
Quarantined
Released
Rescanning
Select one or more Verdicts, such as:
Malicious
Suspicious
Sanitized
No threat detected
Encrypted content
Unsupported file type
Invalid file structure
Failure to analyze
Skipped
Sanitization policy error
Audit Log Filters
Enable Send Audit Logs to forward administrative activity.
Select Event Types, such as:
Authentication
Configuration
Click Save Changes to apply the configuration.
Generic HTTP
Use this option to forward events to a custom HTTP endpoint or third-party SIEM service.
Configuration Steps
Select HTTP under Service Selection.
Endpoint URL Enter the destination service endpoint, for example:
https://<host>:8080API Key Specify the API key required by the destination service.
Event Filters
Enable Send Events to forward events.
Configure Status and Verdict filters as needed.
Audit Log Filters
Enable Send Audit Logs to forward audit events.
Select relevant Event Types (for example, Authentication or Configuration).
Click Save Changes to apply the configuration.
See Locations for the list of IP addresses from which MetaDefender Cloud Email Security ™ sends SIEM data.