ManageEngine ADSelfService Plus
This pack includes Cortex XSIAM content.
Configuration on Server Side
You need to configure ManageEngine ADSelfService Plus to forward Syslog messages to Cortex XSIAM.
Follow the below steps:
- Log in to ADSelfService Plus as default Admin.
- Navigate to Admin > Product Settings > Integration Settings.
- Click the Syslog Server tile.
- Enter the details including Syslog Server Name, Port Number and Port Protocol.
- Select CEF for the Syslog Standard.
- Click Save.
Note:
Make sure that the time zone of the logs are set to UTC.
Time parsing is based on "TIME" field (UTC epoch).
For additional information, refer to the official ManageEngine documentation.
Collect Events from Vendor
In order to use the collector, use the Broker VM option.
Broker VM
To create or configure the Broker VM, use the information described here.
You can configure the specific vendor and product for this instance.
- Navigate to Settings > Configuration > Data Broker > Broker VMs.
- Go to the apps tab and add the Syslog app. If it already exists, click the Syslog app and then click Configure.
- Click Add New.
- When configuring the Syslog Collector, set the following values:
- Vendor as "Auto-Detect".
- Product as "Auto-Detect".
- Format as "Auto-Detect".