Skip to main content

Custom SIEM Integration with SureMDM

To integrate a third-party SIEM solution with the SureMDM Web Console, follow these steps:

  1. Navigate to SureMDM Web Console > Settings (icon located at the top-right of the screen) > Account Settings > SIEM Integration.
  2. Configure the following settings and click Validate.
SettingsDescription
Enable SIEM IntegrationEnable this option to allow configuration of SIEM settings.
Select ServerSelect Others from the dropdown menu.
Custom Server NameEnter a name to identify the SIEM server.
Syslog FormatSelect either RFC5424 or RFC3164, depending on your SIEM server configuration.
Server AddressEnter the IP address or Fully Qualified Domain Name (FQDN) of the SIEM server.
PortEnter the port number configured to receive syslog events.
ProtocolSelect the communication protocol (TCP, UDP, or TCP/TLS) configured on the SIEM server.
TCP Message FramingSelect the TCP message framing option if required by your SIEM server. Otherwise, retain the default value (None).

After the configuration is successfully validated, SureMDM will automatically forward system activity logs and device logs to the configured SIEM server using the specified syslog settings.

💬 Help us improve this documentation

Was this information useful?

Your feedback helps us keep our documentation accurate, up to date, and useful.