LogRhythm Integration with SureMDM
To integrate LogRhythm with SureMDM Web Console, follow these steps:
- Navigate to SureMDM Web Console > Settings (icon located at the top-right of the screen) > Account Settings > SIEM Integration.
- Configure the following settings and click Save.
| Settings | Description |
|---|---|
| Enable SIEM Integration | Enable this option to allow configuration of SIEM settings. |
| Select Server | Select LogRhythm from the dropdown menu. |
| Syslog Format | Select either RFC5424 or RFC3164, depending on the LogRhythm configuration. |
| Server Address | Enter the IP address or Fully Qualified Domain Name (FQDN) of the LogRhythm server. |
| Port | Enter the port number configured in LogRhythm to receive syslog events. |
| Protocol | Select the communication protocol (TCP, UDP, or TLS) configured in LogRhythm. |
| TCP Message Framing | Select the TCP message framing option if required by your LogRhythm configuration. Otherwise, keep the default value (None). |
After the configuration is successfully saved, SureMDM will automatically forward system activity logs and device logs to LogRhythm using the configured syslog settings.
Related LogRhythm Articles
For additional information about configuring LogRhythm for syslog collection, please refer to More Information.
Disclaimer
The third-party configuration steps in this article are based on the vendor's documentation available at the time of publication and may change. Always refer to the official vendor documentation for the latest instructions.