How to Configure the Send to SIEM Option
The Send to SIEM option is available for Change Alert and Threat Model Alert Configuration and is configured as follows:
From the Web Console Home screen, select Lepide Detect
From the Lepide Detect Dashboard, select Lepide Detect, Alert Configuration
The Alert Configuration screen is displayed
From the Alert Configuration screen, select the Email Settings tab
Click the Add button and select Add SIEM Account
The IP Address and Port Number need to be created from the SIEM device to input into these mandatory fields
The port needs to be open one way from Lepide to the device machine
Click Submit to create the alert
Select the option Send Alert to SIEM from the Select Alert Action drop down menu
Select the SIEM account (Recipients) and click Done when finished
SIEM is now supported for all components in Threat Models and Change Alerts
Feeds are created once an alert is triggered as per the alert configuration, and they are pushed to the SIEM account
CEF format is also supported