Integrating ManageEngine PAM360 with SIEM tools6 minutes to read
This document discusses the process of integrating PAM360 with various SIEM tools. At the end of this document, you will have learned the following:
1. Key Benefits of IntegrationPAM360 integrates with SIEM tools that help in gathering and processing audit logs for resources, passwords, and users from PAM360 in real time and send them as Syslogs to external log management systems. Specific events for which notifications are to be raised can be tailored from the Audit tab of PAM360. The following are the SIEM tools that can be currently integrated with PAM360 to collect syslogs:
Apart from the above SIEM tools, you can set up any other log management tool also to collect audit logs. You can have multiple log management tools configured concurrently. 2. How does the Integration Work?Once the details of the the collector host, such as the host name and port are given and the integration is enabled, an RFC-3164 compliant Syslog message will be generated and sent to the configured host and port, using the chosen protocol (TCP or UDP). Default facility name will be AUTH, but you can change it to any of the unassigned facility names from the list.
2.1 Format of the Syslog Messages Sent from PAM360PAM360 uses different Syslog message formats for Resource Audit and User Audit. The RFC-3164 compliant Syslog message indicates the type of audit event at the start of the message, followed by the username and IP address from which the operation was performed. The message typically includes details such as the type of operation, the timestamp, and status. It also displays the name of the PAM360 server where the operation was carried out, along with the resource & account name details. A notable difference between the Syslog messages for MSP and Non-MSP is that the MSP format includes the ORG_NAME in the message. i. Syslog Format for MSPResource Audit [ResourceAudit:LOGGED_IN_USERNAME:IPADDRESS] [OPERATION_TYPE] [OPERATED_TIME] [STATUS_OF_OPERATION] [PAM360_SERVER_NAME] [ORG_NAME-RESOURCE_NAME:ACCOUNT_NAME:SHARED_USER:REASON] User Audit [UserAudit:LOGGED_IN_USERNAME:IPADDRESS] [OPERATION_TYPE] [OPERATED_TIME] [STATUS_OF_OPERATION] [PAM360_SERVER_NAME] [ORG_NAME-LOGGED_IN_USERNAME:REASON] ii. Syslog Format for Non-MSPResource Audit [ResourceAudit:LOGGED_IN_USERNAME:IPADDRESS] [OPERATION_TYPE] [OPERATED_TIME] [STATUS_OF_OPERATION] [PAM360_SERVER_NAME] [ORG_NAME-RESOURCE_NAME:ACCOUNT_NAME:SHARED_USER:REASON] User Audit [UserAudit:LOGGED_IN_USERNAME:IPADDRESS] [OPERATION_TYPE] [OPERATED_TIME] [STATUS_OF_OPERATION] [PAM360_SERVER_NAME] [LOGGED_IN_USERNAME:REASON] 3. Steps to Integrate a SIEM Tool and Configure Syslog CollectionFollow the below steps to integrate any SIEM tool with PAM360 and configure syslog collection.
Buttons and Definitions:
3.1 Customizing the Syslog Event Notifications in PAM360After enabling the integration and configuring the settings, you can customize the events for which you wish to generate the syslog messages.
See also: | ||||||||||||