SIEM Integration


How to Configure the Send to SIEM Option

The Send to SIEM option is available for Change Alert and Threat Model Alert Configuration and is configured as follows:

  • From the Web Console Home screen, select Lepide Detect

  • From the Lepide Detect Dashboard, select Lepide Detect, Alert Configuration

A screenshot of a computer

Description automatically generated
Lepide Detect Menu

The Alert Configuration screen is displayed

  • From the Alert Configuration screen, select the Email Settings tab

  • Click the Add button and select Add SIEM Account

Email Settings

A screenshot of a computer

Description automatically generated
Add SIEM Account

  • The IP Address and Port Number need to be created from the SIEM device to input into these mandatory fields

  • The port needs to be open one way from Lepide to the device machine

  • Click Submit to create the alert

  • Select the option Send Alert to SIEM from the Select Alert Action drop down menu

  • Select the SIEM account (Recipients) and click Done when finished


Configure Report Delivery Action

  • SIEM is now supported for all components in Threat Models and Change Alerts

  • Feeds are created once an alert is triggered as per the alert configuration, and they are pushed to the SIEM account

  • CEF format is also supported