SIEM integration
With its SIEM integration capabilities, DataSecurity Plus allows you to forward all file server audit data to your syslog server or Splunk.
To configure a SIEM solution, follow the below steps:
- Go to Configuration > Administration > SIEM Integration.
- Click on + Add Configuration at the top right corner.
- Select whether you want to configure Syslog or Splunk.
- If you are configuring a syslog server:
- Provide the name, port number, and protocol (UDP/TCP).
- Select the Syslog standard and the data format you wish to forward data in.
- Click Save.
- If you are configuring Splunk:
- Input the Splunk server name and port number.
- Provide a post URL and authentication token.
- Click Save.