Logo
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Sign in
  1. Guardsix Servicedesk
  2. Products Hub
  3. Marketplace

SIEM Management Integration

Standard

Release Details

Version: 1.0.0
Release date: March 7, 2025
Supported On: Logpoint v7.4.0 and Later
SHA 256: d3720156e43b1a0ef5306db8a5e848d0
Download

Key Information

Open outbound port 443 on the on-prem SIEM instance before installing. 

Install SIEM Management Integration on SIEM instance

  1. Download the .pak file.
  2. In the Logpoint SIEM, go to Settings >> System Settingsfrom the navigation bar and click Applications.
  3. Click Import.
  4. Browse to the downloaded .pak file.
  5. Click Upload.

After installing the integration, the SIEM Management Integration and LP SaaS Authentication are listed under Settings >> System Settings >> Plugins on the SIEM where you made the installation.

Enroll or Add a New Instance

  1. Login to Logpoint SIEM.
  2. In the Navigation Bar, click System Settings > Plugins.
  3. Find the SIEM Management integration. Use the search bar at the top right.
  4. Click Manage to open the integration.
  5. In ENROLL SIEM INSTANCE, you need to enter an Enrollment ID and an Enrollment Key. You get the Enrollment ID and Enrollment Key from the Portal.
  6. Login to the Logpoint Portal.
  7. In the navigation bar, click the Tenants icon.
  8. Click Enroll SIEM at the top right.
  9. In SIEM key, copy the Id. The Id is synonymous with Enrollment ID.
  10. Go back to your Logpoint SIEM instance.
  11. In SIEM Management Integration, enter the Id you copied in Enrollment ID.
  12. Go back to the Logpoint Portal and copy the Token.
  13. Go to Logpoint SIEM on your Logpoint SIEM instance.
  14. Enter the token in Enrollment Key and click Enroll.
  15. Under STATUS, Configuration: ONLINE is displayed.
  16. Go back to the Portal.
  17. Refresh the page.
  18. In the Enrolled Instances list, the instance you just added is listed, and under Connected you should see Yes.
  19. Use the Go to SIEM link in Actions to get remote access to your SIEM instance through SSO.

Support

If you have any questions or require assistance, create a support ticket.

Comments

Article is closed for comments.

Follow

Related articles

  • Logpoint
  • Universal REST API Fetcher
  • LP SaaS Authentication
  • Universal Normalizer
  • Microsoft Defender XDR
Consent Required To Proceed
By clicking “I Agree & Download”, you confirm that you are authorized to act on behalf of your organization and you give explicit consent for Guardsix to share your organization’s customer name and log source count with NXLog for the sole purposes of entitlement management, compliance verification, and support delivery related to the embedded NXLog technology in the Guardsix SIEM solution.

This data will not be used for sales or marketing and will not be shared with other third parties. You may withdraw your consent at any time by contacting Guardsix Support; withdrawal will not affect processing already performed.
Cancel I Agree & Download
Privacy policy    EULA    Terms of service   
Copyright © , Guardsix. All rights reserved.

Note: We use cookies that are essential for the smooth functioning of our website.