Coralogix Integration with SureMDM
To integrate Coralogix with the SureMDM Web Console, follow these steps:
- Navigate to SureMDM Web Console > Settings (icon located at the top-right of the screen) > Account Settings > SIEM Integration.
- Configure the following settings and click Validate.
| Settings | Description |
|---|---|
| Enable SIEM Integration | Enable this option to allow configuration of SIEM settings. |
| Select Server | Select Coralogix from the dropdown menu. |
| Syslog Format | Select either RFC5424 or RFC3164, based on your Coralogix configuration. |
| Server Address | Enter the IP address or Fully Qualified Domain Name (FQDN) of the Coralogix Syslog endpoint. |
| Port | Enter the port number configured in Coralogix to receive syslog events. |
| Protocol | Select the communication protocol (TCP, UDP, or TCP/TLS) configured in Coralogix. |
| TCP Message Framing | Select the TCP message framing option if required by your Coralogix configuration. Otherwise, retain the default value (None). |
| Private Key | Enter the Coralogix Private Key (Ingestion Key) used for authentication. |
| Application Name | Enter the application name under which SureMDM logs should appear in Coralogix. |
| Subsystem Name | Enter the subsystem name that will be used to categorize SureMDM logs within the selected application. |
After the configuration is successfully validated, SureMDM will automatically forward system activity logs and device logs to Coralogix using the configured syslog settings.
Related Coralogix Articles
For additional information about configuring syslog ingestion in Coralogix, please refer to Coralogix Syslog Documentation
Disclaimer
The third-party configuration steps in this article are based on the vendor's documentation available at the time of publication and may change. Always refer to the official vendor documentation for the latest instructions.