Integrating PAM360 with Microsoft Sentinel7 minutes to read
PAM360, a unified Privileged Access Management product from ManageEngine, integrates with Microsoft Sentinel, a cloud-native security information and event management (SIEM) solution by Microsoft. This is in addition to the already available integrations with the third-party SIEM solutions such as Splunk, ManageEngine EventLog Analyzer, and Sumo Logic. At the end of this document, you will have learned the following:
1. Key Benefits of IntegrationPAM360's extensive auditing capabilities include gathering and processing audit logs for resources, passwords, and users in real time. The product allows you to tailor notifications for specific events from the Audit tab. Through the PAM360-Microsoft Sentinel integration, PAM360 sends detailed logs to the SIEM tool as syslogs, enabling you to view PAM360 audit trails from the Microsoft Sentinel interface. Apart from the above-mentioned SIEM tools, you can set up any other log management tool to collect audit logs. It is possible to configure multiple log management tools concurrently. 2. Configuring a PAM360 Workspace in Microsoft SentinelPrerequisites
![]() ![]() ![]() ![]() ![]() ![]() Notes: ![]() You have successfully configured a workspace for PAM360 in the Microsoft Sentinel portal. 3. Enabling Microsoft Sentinel Integration in PAM360Follow the below steps to complete the Microsoft Sentinel configuration in PAM360.
The integration process is now complete. All audit trails that are captured in PAM360 will be transferred to the Microsoft Sentinel portal. 4. Viewing PAM360 Logs in Microsoft SentinelTo view the PAM360 logs in Microsoft Sentinel, go to the Microsoft Sentinel portal.
![]() 5. Troubleshooting TipsAfter configuring the integration, if you are still unable to view the PAM360 logs in the Microsoft Sentinel portal, try the below steps:
See also: | |