Integration with SIEM tools
SharePoint Manager Plus can forward the collected logs to a third-party server enabling integration with a SIEM such as Splunk. The HTTP event collector in Splunk can collect logs from SharePoint Manager Plus. Please ensure the following.
- When creating a new token in the HTTP Event Collector settings, Enable indexer acknowledgment should not be checked. If it's checked, then the existing tokens can be edited.
- In the Global Settings of the HTTP Event Collector settings, Use Deployment Server should not be checked.
- In Global Settings if Enable SSL is selected then a verified certificate has to be provided, otherwise the logs will not be forwarded because of unverified certificate exception.