Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Getting Started > Security Information and Event Management (SIEM) integration
Security Information and Event Management (SIEM) integration
Administrator Help | TRITON AP-EMAIL | Version 8.2.x
Third-party security information and event management (SIEM) tools allow the logging and analysis of internal alerts generated by network devices and software. Integration with SIEM technology allows the transfer of message activity events to a SIEM server for analysis and reporting.
Access SIEM integration settings on the Settings > General > SIEM Integration page. Mark the Enable SIEM integration check box to activate SIEM integration functions.
After you enable SIEM integration, use the following steps to configure the SIEM server and transport protocol:
1.
2.
3.
Select the protocol used for data transport, either UDP or TCP. User datagram protocol (UDP) is a transport layer protocol in the Internet protocol suite. UDP is stateless and therefore faster than transmission control protocol (TCP), but it can be unreliable. Like UDP, TCP is a transport layer protocol, but it provides reliable, ordered data delivery at the expense of transport speed.
4.
Click Send Test Message to confirm that the SIEM product is properly configured and can receive messages from your email software.

Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Getting Started > Security Information and Event Management (SIEM) integration
Copyright 2016 Forcepoint LLC. All rights reserved.