Custom SIEM Integration with SureMDM
To integrate a third-party SIEM solution with the SureMDM Web Console, follow these steps:
- Navigate to SureMDM Web Console > Settings (icon located at the top-right of the screen) > Account Settings > SIEM Integration.
- Configure the following settings and click Validate.
| Settings | Description |
|---|---|
| Enable SIEM Integration | Enable this option to allow configuration of SIEM settings. |
| Select Server | Select Others from the dropdown menu. |
| Custom Server Name | Enter a name to identify the SIEM server. |
| Syslog Format | Select either RFC5424 or RFC3164, depending on your SIEM server configuration. |
| Server Address | Enter the IP address or Fully Qualified Domain Name (FQDN) of the SIEM server. |
| Port | Enter the port number configured to receive syslog events. |
| Protocol | Select the communication protocol (TCP, UDP, or TCP/TLS) configured on the SIEM server. |
| TCP Message Framing | Select the TCP message framing option if required by your SIEM server. Otherwise, retain the default value (None). |
After the configuration is successfully validated, SureMDM will automatically forward system activity logs and device logs to the configured SIEM server using the specified syslog settings.