# Agent-less Integration

Integrate AQUILA seamlessly across your infrastructure without installing local agents. Using secure network connections and APIs, AQUILA collects data, monitors activity, and delivers real-time insights with minimal system impact. Simplify deployment, reduce maintenance, and gain complete visibility with AQUILA’s efficient agentless integration approach.

# NG SIEM - 1Password Integration

## <span style="color: rgb(53, 152, 219);">**1Password Events Reporting Integration Manual**</span>

<span style="color: rgb(0, 0, 0);">With **1Password Business**, you can forward account activity to your SIEM system using the<span style="color: rgb(132, 63, 161);"> **[1Password Events API](https://support.1password.com/events-reporting/)**</span>. This enables centralized monitoring, improved visibility, and enhanced response to security-related events across your organization.</span>

---

### <span style="color: rgb(53, 152, 219);">**Key Benefits**</span>

<span style="color: rgb(0, 0, 0);">When integrated with your SIEM, 1Password Events Reporting allows you to:</span>

- <span style="color: rgb(0, 0, 0);">**Retain 1Password event data** according to your organization's policies</span>
- <span style="color: rgb(0, 0, 0);">**Build custom dashboards** and visualizations for insights</span>
- <span style="color: rgb(0, 0, 0);">**Configure custom alerts** to automate responses</span>
- <span style="color: rgb(0, 0, 0);">**Correlate 1Password events** with data from other systems and services</span>

---

### <span style="color: rgb(53, 152, 219);">**Permissions Required**</span>

<span style="color: rgb(0, 0, 0);">You must be an **Owner** or **Administrator** of your 1Password Business account to configure Events Reporting.</span>

---

### <span style="color: rgb(53, 152, 219);">**Supported Event Types**</span>

#### <span style="color: rgb(0, 0, 0);">**Sign-In Attempts**</span>

<span style="color: rgb(0, 0, 0);">Track authentication activity including:</span>

- <span style="color: rgb(0, 0, 0);">**Username and IP address** of the user</span>
- <span style="color: rgb(0, 0, 0);">**Timestamp** of the sign-in attempt</span>
- <span style="color: rgb(0, 0, 0);">**Success or failure status**</span>
- <span style="color: rgb(0, 0, 0);">**Cause of failure** (for failed attempts)</span>

<span style="color: rgb(0, 0, 0);">These logs help monitor account access patterns and detect unauthorized access attempts.</span>

---

<span style="color: rgb(0, 0, 0);">*<span class="TextRun SCXW71272603 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0">If you need further </span><span class="NormalTextRun SCXW71272603 BCX0">assistance</span><span class="NormalTextRun SCXW71272603 BCX0">, kindly contact </span></span><span style="color: rgb(53, 152, 219);">**<span class="TextRun SCXW71272603 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0">support@cytechint.com</span></span>**</span><span class="TextRun SCXW71272603 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0"> for prompt </span><span class="NormalTextRun SCXW71272603 BCX0">assistance</span><span class="NormalTextRun SCXW71272603 BCX0"> and guidance.</span></span><span class="EOP SCXW71272603 BCX0" data-ccp-props="{}"></span>*</span>

# NG SIEM - Abusech Integration

<span style="color: rgb(0, 0, 0);">This integration is designed to collect and process **AbuseCH threat intelligence logs**. It retrieves indicators from multiple AbuseCH APIs and makes them available for security monitoring and analysis.</span>

## <span style="color: rgb(53, 152, 219);">Supported Datasets</span>

<span style="color: rgb(0, 0, 0);">The integration provides the following datasets:</span>

- <span style="color: rgb(0, 0, 0);">**URL Dataset**</span>
    
    
    - <span style="color: rgb(0, 0, 0);">Retrieves **URL-based indicators** from the AbuseCH API.</span>
    - <span style="color: rgb(0, 0, 0);">Data source: <span style="color: rgb(132, 63, 161);">[URLhaus API Documentation](https://urlhaus-api.abuse.ch/)</span></span>
- <span style="color: rgb(0, 0, 0);">**Malware Dataset**</span>
    - <span style="color: rgb(0, 0, 0);">Retrieves **malware-based indicators** from the AbuseCH API.</span>
- <span style="color: rgb(0, 0, 0);">**MalwareBazaar Dataset**</span>
    
    
    - <span style="color: rgb(0, 0, 0);">Retrieves indicators from **MalwareBazaar**, a community-driven project hosted by AbuseCH.</span>

### <span style="color: rgb(53, 152, 219);">URL Logs</span>

<span style="color: rgb(0, 0, 0);">The **AbuseCH URL data stream** fetches threat intelligence indicators from the following API endpoint:</span>

```
https://urlhaus-api.abuse.ch/v1/urls/recent/
```

<span style="color: rgb(0, 0, 0);">This stream provides details on recently observed malicious URLs that can be used for detection, correlation, and blocking in security systems.</span>

<span style="color: rgb(0, 0, 0);">*<span class="TextRun SCXW71272603 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0">If you need further </span><span class="NormalTextRun SCXW71272603 BCX0">assistance</span><span class="NormalTextRun SCXW71272603 BCX0">, kindly contact </span></span><span style="color: rgb(53, 152, 219);">**<span class="TextRun SCXW71272603 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0">support@cytechint.com</span></span>**</span><span class="TextRun SCXW71272603 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0"><span style="color: rgb(53, 152, 219);"> </span>for prompt </span><span class="NormalTextRun SCXW71272603 BCX0">assistance</span><span class="NormalTextRun SCXW71272603 BCX0"> and guidance.</span></span><span class="EOP SCXW71272603 BCX0" data-ccp-props="{}"></span>*</span>

# NG SIEM - Atlassian Confluence Integration

#### What are API Token Scopes?

Scopes define what actions an API token is allowed to perform in Atlassian apps such as Jira and Confluence. They enhance security by limiting permissions to only what's needed (e.g., read-only access to audit logs). Always use scoped tokens for AQUILA integrations—unscoped tokens are deprecated for most apps and may not support fine-grained access. For audit logs (events like user actions, config changes, or security incidents), use the specific scopes listed below. Broader scopes may be needed for other integrations (e.g., content indexing), but stick to these for basic monitoring to minimize risk.

---

#### Creating an API Token with Scopes

Follow these steps to create a token. Note: As of March 13, 2025, tokens created before December 15, 2024, will expire between March 14 and May 12, 2026. New tokens default to 1-year expiration (adjustable from 1 to 365 days).

1. Log in to [https://id.atlassian.com/manage-profile/security/api-tokens](https://id.atlassian.com/manage-profile/security/api-tokens).
2. Select "Create API token with scopes".
3. Enter a descriptive name for the token (e.g., "AQUILA- Audit Logs Monitoring").
4. Choose an expiration date for the token (between 1 and 365 days; consider shorter for security).
5. Select the application (Jira or Confluence). **Important:** Create separate tokens for Jira and Confluence—tokens are app-specific and cannot access both.
6. Select the scopes or permissions the token should have: 
    - For Jira (audit logs): read:audit-log:jira (allows viewing audit events).
    - For Confluence (audit logs): read:audit-log:confluence (allows viewing audit events; add write:audit-log:confluence if needed for custom logging, but not required for AQUILA).
7. Click "Create".
8. Copy the token and save it securely. You cannot view it again after this step. If lost, generate a new one. Share only with trusted integrations like AQUILA—revoke if compromised.

---

#### Required Atlassian-Side Permissions

The user account tied to the email (Jira/Confluence User Identifier) must have admin-level access to fetch audit logs via API:

- For Jira: "Administer Jira" global permission (or Jira System Administrator).
- For Confluence: Confluence Administrator permission.

Without these, the API may authenticate successfully (leading to a "healthy" status in AQUILA) but return no data or errors like 403 Forbidden. If you lack access to the client side, request they verify/add these permissions via admin.atlassian.com &gt; Global Permissions.

<p class="callout info">**Additionally, ensure audit logging is enabled and set to "Full" coverage on the Atlassian side (via their admin settings) to generate events. Low activity instances may produce sparse logs.**</p>

<p class="callout info">**Note: If you're on a Free plan without org access, you can't enable advanced features—consider upgrading or using site-level logs in individual apps.**</p>

#### Required Credentials for Integration Access (AQUILA Setup)

Use these in AQUILA &gt; Integrations &gt; Atlassian Jira/Confluence setup (separate integrations for each). For Atlassian Cloud, authentication uses Basic Auth (email + token).

- **API URL**: Base Atlassian API URL without paths (e.g., [https://your-site.atlassian.net](https://your-site.atlassian.net) for Jira; add /wiki for Confluence endpoints if needed, but AQUILA handles this).
- **User Identifier**: Your Atlassian email address (must be linked to an admin account as noted above).
- **API Token**: The scoped token created above.
- **Personal Access Token (PAT) -** : The Personal Access Token used for self-hosted instances. If set, Jira User Identifier and Jira API Token will be ignored. **(Optional)**

For self-hosted (Data Center/Server) instances, a Personal Access Token may be used instead, but Cloud setups prefer the API token.

<p class="callout info">Please provide the following information to CyTech</p>

- **API URL**: Base Atlassian API URL without paths (e.g., [https://your-site.atlassian.net](https://your-site.atlassian.net) for Jira; add /wiki for Confluence endpoints if needed, but AQUILA handles this).
- **Confluence User Identifier**: Your Atlassian email address (must be linked to an admin account as noted above).
- **Confluence API Token**: The scoped token created above.

# NG SIEM - (Plain Scope) Atlassian Confluence Integration

#### What is API Token?

A secure string used to **authenticate external applications or scripts** so they can access Confluence’s REST APIs without needing a user password. Its main use is to **allow programmatic access** for integrations, automation, or tools to interact with Confluence content.<span class="relative -top-px inline-flex max-w-full items-center align-middle" data-testid="conversation-context-citation-pill-wrapper"><button aria-label="Memory" class="text-token-text-secondary! relative ms-1 inline-flex h-6 min-w-8 cursor-pointer items-center justify-center rounded-[40px] px-2 transition-colors duration-150 ease-in-out bg-token-bg-tertiary hover:bg-token-bg-secondary" data-testid="conversation-context-citation-pill" type="button"><svg aria-hidden="true" class="size-4 shrink-0" data-rtl-flip="" data-testid="conversation-context-citation-pill-icon" height="20" width="20" xmlns="http://www.w3.org/2000/svg"></svg></button></span>

---

#### Creating an API Token

Follow these steps to create a token. Note: As of March 13, 2025, tokens created before December 15, 2024, will expire between March 14 and May 12, 2026. New tokens default to 1-year expiration (adjustable from 1 to 365 days).

1. Log in to [https://id.atlassian.com/manage-profile/security/api-tokens.](https://id.atlassian.com/manage-profile/security/api-tokens)
2. Select "Create API token".
3. Enter a descriptive name for the token (e.g., "AQUILA- Audit Logs Monitoring").
4. Choose an expiration date for the token (between 1 and 365 days; consider shorter for security).
5. Click "Create".
6. Copy the token and save it securely. You cannot view it again after this step. If lost, generate a new one. Share only with trusted integrations like AQUILA—revoke if compromised.

---

#### Required Atlassian-Side Permissions

The user account tied to the email (Jira/Confluence User Identifier) must have admin-level access to fetch audit logs via API:

- For Confluence: Confluence **Global permission**.   
    [https://your-domain.atlassian.net/wiki/admin/permissions/global?tab=internal](https://your-domain.atlassian.net/wiki/admin/permissions/global?tab=internal)
- The **confluence-admins-ronaldoa** both **Personal Space** and **Create Space** should be checked. Click the "Edit" to proceed.

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-04/scaled-1680-/tUvojKfkEvIQ5k6A-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-04/tUvojKfkEvIQ5k6A-image.png)

- For Confluence: Confluence **Administration** permission.  
    [https://admin.atlassian.com/o/8d1afe09-e60a-4bf3-87d9-c71b10e4842b/atlassian-apps](https://admin.atlassian.com/o/8d1afe09-e60a-4bf3-87d9-c71b10e4842b/atlassian-apps)
- Click "**Manage app**".

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-04/scaled-1680-/YZ4HkbMl8V7btAlU-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-04/YZ4HkbMl8V7btAlU-image.png)

- Provide Role **App admin**, **User access admin**, **user** in **confluence-admins-ronaldoa.**

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-04/scaled-1680-/AVedDSkvYeLC8TSf-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-04/AVedDSkvYeLC8TSf-image.png)

- In **Groups** under by **Directory,** make sure the **User** is active.

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-04/scaled-1680-/7WJJsYhOPV3zCzXs-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-04/7WJJsYhOPV3zCzXs-image.png)

Without this, the API may authenticate successfully (leading to a "healthy" status in AQUILA) but return no data or errors like 403 Forbidden. If you lack access to the client side, request they verify/add these permissions via admin.atlassian.com &gt; Global Permissions.

<p class="callout info">**Note: If you're on a Free plan without org access, you can't enable advanced features—consider upgrading or using site-level logs in individual apps.**</p>

#### Required Credentials for Integration Access (AQUILA Setup)

Use these in AQUILA &gt; Integrations &gt; Atlassian Jira/Confluence setup (separate integrations for each). For Atlassian Cloud, authentication uses Basic Auth (email + token).

- **API URL**: Base Atlassian API URL without paths (e.g., [https://your-site.atlassian.net](https://your-site.atlassian.net) for Confluence; add /wiki for Confluence endpoints if needed, but AQUILA handles this).
- **User Identifier**: Your Atlassian email address (must be linked to an admin account as noted above).
- **API Token**: The scoped token created above.
- **Personal Access Token (PAT) -** : The Personal Access Token used for self-hosted instances. If set, Jira User Identifier and Jira API Token will be ignored. **(Optional)**

For self-hosted (Data Center/Server) instances, a Personal Access Token may be used instead, but Cloud setups prefer the API token.

<p class="callout info">Please provide the following information to CyTech</p>

- **API URL**: Base Atlassian API URL without paths (e.g., [https://your-site.atlassian.net](https://your-site.atlassian.net) for Jira; add /wiki for Confluence endpoints if needed, but AQUILA handles this).
- **Confluence User Identifier**: Your Atlassian email address (must be linked to an admin account as noted above).
- **Confluence API Token**: The scoped token created above.

# NG SIEM - Atlassian Jira Integration

#### What are API Token Scopes?

Scopes define what actions an API token is allowed to perform in Atlassian apps such as Jira and Confluence. They enhance security by limiting permissions to only what's needed (e.g., read-only access to audit logs). Always use scoped tokens for AQUILA integrations—unscoped tokens are deprecated for most apps and may not support fine-grained access. For audit logs (events like user actions, config changes, or security incidents), use the specific scopes listed below. Broader scopes may be needed for other integrations (e.g., content indexing) but stick to these for basic monitoring to minimize risk.

---

#### Creating an API Token with Scopes

Follow these steps to create a token. Note: As of March 13, 2025, tokens created before December 15, 2024, will expire between March 14 and May 12, 2026. New tokens default to 1-year expiration (adjustable from 1 to 365 days).

1. Log in to [https://id.atlassian.com/manage-profile/security/api-tokens](https://id.atlassian.com/manage-profile/security/api-tokens).
2. Select "Create API token with scopes".
3. Enter a descriptive name for the token (e.g., "AQUILA- Audit Logs Monitoring").
4. Choose an expiration date for the token (between 1 and 365 days; consider shorter for security).
5. Select the application (Jira or Confluence). **Important:** Create separate tokens for Jira and Confluence—tokens are app-specific and cannot access both.
6. Select the scopes or permissions the token should have: 
    - For Jira (audit logs): read:audit-log:jira (allows viewing audit events).
    - For Confluence (audit logs): read:audit-log:confluence (allows viewing audit events; add write:audit-log:confluence if needed for custom logging, but not required for AQUILA).
7. Click "Create".
8. Copy the token and save it securely. You cannot view it again after this step. If lost, generate a new one. Share only with trusted integrations like AQUILA—revoke if compromised.

---

#### Required Atlassian-Side Permissions

The user account tied to the email (Jira/Confluence User Identifier) must have admin-level access to fetch audit logs via API:

- For Jira: "Administer Jira" global permission (or Jira System Administrator).
- For Confluence: Confluence Administrator permission.

Without these, the API may authenticate successfully (leading to a "healthy" status in AQUILA) but return no data or errors like 403 Forbidden. If you lack access to the client side, request they verify/add these permissions via admin.atlassian.com &gt; Global Permissions.

<p class="callout info">**Additionally, ensure audit logging is enabled and set to "Full" coverage on the Atlassian side (via their admin settings) to generate events. Low activity instances may produce sparse logs.** </p>

<p class="callout info">**Note: If you're on a Free plan without org access, you can't enable advanced features—consider upgrading or using site-level logs in individual apps.**</p>

#### Required Credentials for Integration Access (AQUILA Setup)

Use these in AQUILA &gt; Integrations &gt; Atlassian Jira/Confluence setup (separate integrations for each). For Atlassian Cloud, authentication uses Basic Auth (email + token).

- **API URL**: Base Atlassian API URL without paths (e.g., [https://your-site.atlassian.net](https://your-site.atlassian.net) for Jira; add /wiki for Confluence endpoints if needed, but AQUILA handles this).
- **User Identifier**: Your Atlassian email address (must be linked to an admin account as noted above).
- **API Token**: The scoped token created above.
- **Personal Access Token (PAT) -** : The Personal Access Token used for self-hosted instances. If set, Jira User Identifier and Jira API Token will be ignored. **(Optional)**

For self-hosted (Data Center/Server) instances, a Personal Access Token may be used instead, but Cloud setups prefer the API token.

<div id="bkmrk-issue-possible-cause"></div><p class="callout info">Please provide the following information to CyTech</p>

- **API URL**: Base Atlassian API URL without paths (e.g., [https://your-site.atlassian.net](https://your-site.atlassian.net) for Jira; add /wiki for Confluence endpoints if needed, but AQUILA handles this).
- **Jira User Identifier**: Your Atlassian email address (must be linked to an admin account as noted above).
- **Jira API Token**: The scoped token created above.

# NG SIEM - AWS Integration

#### <span style="color: rgb(53, 152, 219);">**Overview**</span>

  
<span style="color: rgb(0, 0, 0);">The AWS Integration enables the collection of logs and metrics from your Amazon Web Services (AWS) environment. This integration helps centralize security and operational data for monitoring, investigation, and reporting.</span>

#### <span style="color: rgb(53, 152, 219);">**Data Streams**</span>

  
<span style="color: rgb(0, 0, 0);">The AWS integration collects two main types of data:</span>

1. <span style="color: rgb(0, 0, 0);">**Logs** – Records of events that occur within your AWS account.</span>  
    <span style="color: rgb(0, 0, 0);">Examples:</span>
    
    
    - <span style="color: rgb(0, 0, 0);">Every request received by CloudFront</span>
    - <span style="color: rgb(0, 0, 0);">Actions performed by AWS users or roles</span>
    - <span style="color: rgb(0, 0, 0);">API activity captured by CloudTrail</span>
2. <span style="color: rgb(0, 0, 0);">**Metrics** – Real-time insights into the performance and health of AWS services.</span>  
    <span style="color: rgb(0, 0, 0);">Examples:</span>
    
    
    - <span style="color: rgb(0, 0, 0);">CPU utilization of EC2 instances</span>
    - <span style="color: rgb(0, 0, 0);">S3 storage usage</span>
    - <span style="color: rgb(0, 0, 0);">RDS performance metrics</span>
    - <span style="color: rgb(0, 0, 0);">AWS cost and usage breakdowns</span>

#### <span style="color: rgb(53, 152, 219);">**Requirements**</span>

  
<span style="color: rgb(0, 0, 0);">Before configuring the AWS integration, ensure you have:</span>

1. <span style="color: rgb(0, 0, 0);">**AWS Credentials** – To connect to your AWS account.</span>
2. <span style="color: rgb(0, 0, 0);">**AWS Permissions** – To grant access to the necessary AWS services.</span>

##### <span style="color: rgb(53, 152, 219);">**Step 1. Create IAM User and Custom Policy**</span>

1. <span style="color: rgb(0, 0, 0);">**IAM User**</span>  
    <span style="color: rgb(0, 0, 0);">-an identity you create in **AWS Identity and Access Management (IAM)** that represents a person or application which needs to interact with your AWS resources.</span>
2. <span style="color: rgb(0, 0, 0);">**User Policy and Permissions**</span>

<span style="color: rgb(0, 0, 0);">The IAM User must be granted the following permissions:</span>

```javascript
{
	"Version": "2012-10-17",
	"Statement": [
		{
			"Effect": "Allow",
			"Action": [
				"ce:GetCostAndUsage",
				"cloudwatch:GetMetricData",
				"cloudwatch:ListMetrics",
				"ec2:DescribeInstances",
				"ec2:DescribeRegions",
				"iam:ListAccountAliases",
				"inspector2:ListFindings",
				"logs:DescribeLogGroups",
				"logs:FilterLogEvents",
				"organizations:ListAccounts",
				"rds:DescribeDBInstances",
				"rds:ListTagsForResource",
				"s3:GetBucketLocation",
				"s3:GetObject",
				"s3:ListBucket",
				"sns:ListTopics",
				"sqs:ChangeMessageVisibility",
				"sqs:DeleteMessage",
				"sqs:GetQueueAttributes",
				"sqs:ListQueues",
				"sqs:ReceiveMessage",
				"sts:AssumeRole",
				"sts:GetCallerIdentity",
				"tag:GetResources"
			],
			"Resource": "*"
		}
	]
}
```

##### <span style="color: rgb(0, 0, 0);">**<span style="color: rgb(53, 152, 219);">Step 2: Create Access Key</span>** </span>  


<span style="color: rgb(0, 0, 0);">Long-term credentials associated with an IAM user or the AWS root account.</span>

- 1. <span style="color: rgb(0, 0, 0);">**Access Key ID** – First part of the access key</span>
    2. <span style="color: rgb(0, 0, 0);">**Secret Access Key** – Second part of the access key</span>

##### <span style="color: rgb(53, 152, 219);">**Step 3: Create a CloudTrail Trail and Send Logs to S3**</span>

<span style="color: rgb(0, 0, 0);">Set up an AWS CloudTrail trail to record account activity and deliver log files into an S3 bucket for secure storage, auditing, and compliance monitoring.</span>

1. <span style="color: rgb(0, 0, 0);">**Open CloudTrail** &gt; Create a **New Trail**</span>
2. <span style="color: rgb(0, 0, 0);">**Trail Settings**</span>
    
    
    - <span style="color: rgb(0, 0, 0);">Trail name: Enter a unique name.</span>
    - <span style="color: rgb(0, 0, 0);">Apply trail to all accounts in my organization.</span>
3. <span style="color: rgb(0, 0, 0);">Choose an S3 Bucket</span>
    
    
    - <span style="color: rgb(0, 0, 0);">**Storage location** → Select **Create new S3 bucket** or **Use existing bucket**.</span>
    
    <span style="color: rgb(0, 0, 0);"> If using **new bucket**:</span>
    
    
    - <span style="color: rgb(0, 0, 0);">Enter a bucket name.</span>
    - <span style="color: rgb(0, 0, 0);">CloudTrail will create the bucket and add the correct permissions.</span>
    
    <span style="color: rgb(0, 0, 0);"> If using **existing bucket**:</span>
    
    
    - <span style="color: rgb(0, 0, 0);">Select your bucket from the dropdown.</span>
    - <span style="color: rgb(0, 0, 0);">CloudTrail will prompt you to allow access. Click **Yes** to let CloudTrail update the bucket policy.</span>
4. <span style="color: rgb(0, 0, 0);">Additional Settings</span>
    
    
    - <span style="color: rgb(0, 0, 0);">**Enable for all accounts in my organization**</span>
    - <span style="color: rgb(0, 0, 0);">**Log file SSE-KMS encryption:** Enable if you want encryption with a KMS key(optional).</span>
    - <span style="color: rgb(0, 0, 0);">**Log file validation:** Enable to verify log integrity.</span>
5. <span style="color: rgb(0, 0, 0);">Choose Log Events</span>
    1. <span style="color: rgb(0, 0, 0);">**Event Type**</span>
        - <span style="color: rgb(0, 0, 0);">**Management events** - Capture management operations performed on your AWS resources.</span>
        - <span style="color: rgb(0, 0, 0);">**Data events** - Log the resource operations performed on or within a resource.</span>
        - <span style="color: rgb(0, 0, 0);">**Insights events** - Identify unusual activity, errors, or user behavior in your account.</span>
        - <span style="color: rgb(0, 0, 0);">**Network activity events** - Network activity events provide information about resource operations performed on a resource within a virtual private cloud endpoint.</span>
    2. <span style="color: rgb(0, 0, 0);">**Management events:**</span>
        
        
        - <span style="color: rgb(0, 0, 0);">Check **Read**(default is usually All).</span>
6. <span style="color: rgb(0, 0, 0);">Review and Create</span>
    
    
    - <span style="color: rgb(0, 0, 0);">Review your configuration summary.</span>
    - <span style="color: rgb(0, 0, 0);">Click **Create trail**.</span>

<span style="color: rgb(0, 0, 0);">To configure the AWS Integration:</span>

<p class="callout danger">**<span class="TextRun SCXW124724174 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW124724174 BCX0">Please provide the following information to </span><span class="NormalTextRun SpellingErrorV2Themed SCXW124724174 BCX0">CyTech Support</span><span class="NormalTextRun SCXW124724174 BCX0">:</span></span><span class="EOP SCXW124724174 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}"> </span>**</p>

<div class="ListContainerWrapper SCXW124724174 BCX0" id="bkmrk-project-id%C2%A0---the-pr">- <span style="color: rgb(0, 0, 0);">**Access key ID**</span>
- <span style="color: rgb(0, 0, 0);">**Secret Access Key**</span>
- <span style="color: rgb(0, 0, 0);">**Region**</span>
- <span style="color: rgb(0, 0, 0);">**Trail Log Collection &gt; S3 Bucket ARN**</span>

</div><span style="color: rgb(0, 0, 0);">*If you need further assistance, kindly contact <span style="color: rgb(53, 152, 219);">**[support@cytechint.com](mailto:info@cytechint.com)** </span>for prompt assistance and guidance.*</span>

# NG SIEM - Azure CSPM Integration

<span style="color: rgb(0, 0, 0);">This manual explains how to get started monitoring the security posture of your Azure CSP using the Cloud Security Posture Management (CSPM) feature.</span>

#### <span style="color: rgb(53, 152, 219);">**Requirements**</span>

<div class="ulist itemizedlist" id="bkmrk-cspm-only-works-in-t">- <span style="color: rgb(0, 0, 0);">The user who gives the CSPM integration permissions in Azure must be an Azure subscription **admin**.</span>

</div>#### <span style="color: rgb(53, 152, 219);">**Setup**</span>

<span style="color: rgb(0, 0, 0);">**Service principal with client secret** </span>

<span style="color: rgb(0, 0, 0);">Before using this method, you must have set up a **Microsoft Entra application** and **service principal that can access resources**. Please go **<span style="color: rgb(132, 63, 161);">[here](https://learn.microsoft.com/en-us/entra/identity-platform/howto-create-service-principal-portal#get-tenant-and-app-id-values-for-signing-in)</span>** before following the steps below.</span>

<div class="olist orderedlist" id="bkmrk-on-the%C2%A0add-cloud-sec">1. <span style="color: rgb(0, 0, 0);">The following information is required.</span>
    1. <span style="color: rgb(0, 0, 0);">Directory **(tenant) ID** and **Application (client) ID**</span>
        - <span style="color: rgb(0, 0, 0);">To get these values:</span>
            - <span style="color: rgb(0, 0, 0);">Go to the <span class="strong strong">**Registered apps**</span> section of Microsoft Entra ID.</span>
            - <span style="color: rgb(0, 0, 0);">Click on <span class="strong strong">**New Registration**</span>, name your app and click <span class="strong strong">**Register**</span>.</span>
            - <span style="color: rgb(0, 0, 0);">Copy your new app’s **Directory (tenant) ID** and **Application (client) ID**. </span>
    2. <span style="color: rgb(0, 0, 0);">**Client Secret**</span>
        - <span style="color: rgb(0, 0, 0);">In Azure portal, select <span class="strong strong">Certificates &amp; secrets</span>, then go to the <span class="strong strong">Client secrets</span> tab. Click <span class="strong strong">New client secret</span>.</span>
        - <span style="color: rgb(0, 0, 0);">Copy the new secret.</span>
2. <span style="color: rgb(0, 0, 0);">Return to Azure. Go to your Azure subscription list and select the subscription or management group you want to monitor with CSPM.</span>
3. <span style="color: rgb(0, 0, 0);">Go to <span class="strong strong">**Access control (IAM)**</span> and select <span class="strong strong">**Add Role Assignment**</span>.</span>
4. <span style="color: rgb(0, 0, 0);">Select the **Reader** function role, assign access to <span class="strong strong">**User, group, or service principal**</span>, and select your new app.</span>

</div><p class="callout warning">**<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 3">Please saved and provide this values to AQUILA Support Team.</span></span>**</p>

1. <span style="color: rgb(0, 0, 0);">**<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 3">Directory (tenant) ID</span></span>**</span>
2. <span style="color: rgb(0, 0, 0);">**<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 3">Application (client) ID</span></span>**</span>
3. <div aria-label="Client Secret" class="euiFlexItem css-kpsrin-euiFlexItem-growZero"><span style="color: rgb(0, 0, 0);">**Client Secret Value:**</span></div>

<span style="color: rgb(0, 0, 0);">*<span class="TextRun SCXW71272603 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0">If you need further </span><span class="NormalTextRun SCXW71272603 BCX0">assistance</span><span class="NormalTextRun SCXW71272603 BCX0">, kindly contact </span></span><span style="color: rgb(53, 152, 219);">**<span class="TextRun SCXW71272603 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0">support@cytechint.com</span></span>**</span><span class="TextRun SCXW71272603 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0"> for prompt </span><span class="NormalTextRun SCXW71272603 BCX0">assistance</span><span class="NormalTextRun SCXW71272603 BCX0"> and guidance.</span></span><span class="EOP SCXW71272603 BCX0" data-ccp-props="{}"></span>*</span>

# NG SIEM - Azure Logs Integration

<span style="color: rgb(0, 0, 0);">The **Azure Logs integration** enables you to collect logs from specific Azure services such as:</span>

- <span style="color: rgb(0, 0, 0);">**Microsoft Entra ID** (Sign-in, Audit, Identity Protection, Provisioning logs)</span>
- <span style="color: rgb(0, 0, 0);">**Azure Spring Apps**</span>
- <span style="color: rgb(0, 0, 0);">**Azure Firewall**</span>
- <span style="color: rgb(0, 0, 0);">**Microsoft Graph Activity**</span>
- <span style="color: rgb(0, 0, 0);">**Activity and Platform logs**</span>
- <span style="color: rgb(0, 0, 0);">Additional supported Azure services</span>

#### <span style="color: rgb(53, 152, 219);">**Example Use Cases**</span>

- <span style="color: rgb(0, 0, 0);">**Brute force sign-in detection**: Collect **Microsoft Entra ID sign-in logs** and configure an alert in the Observability Logs app to notify you if failed sign-in attempts exceed a defined threshold.</span>
- <span style="color: rgb(0, 0, 0);">**Capacity planning**: Collect **Azure Activity logs** to track when virtual machines fail to start due to quota limits, helping plan resource scaling.</span>

---

#### <span style="color: rgb(53, 152, 219);">**Data Streams**</span>

<span style="color: rgb(0, 0, 0);">The Azure Logs integration collects **log data streams** from the following sources:</span>

- <span style="color: rgb(0, 0, 0);">Activity Logs</span>
- <span style="color: rgb(0, 0, 0);">Platform Logs</span>
- <span style="color: rgb(0, 0, 0);">Microsoft Entra ID Logs (Sign-in, Audit, Identity Protection, Provisioning)</span>
- <span style="color: rgb(0, 0, 0);">Microsoft Graph Activity Logs</span>
- <span style="color: rgb(0, 0, 0);">Azure Spring Apps Logs</span>

<span style="color: rgb(0, 0, 0);">Logs provide a complete record of events that occur in your Azure environment, allowing you to detect threats, troubleshoot issues, and plan capacity.</span>

---

#### <span style="color: rgb(53, 152, 219);">**Azure Setup Prerequisites**</span>

<span style="color: rgb(0, 0, 0);">To successfully forward Azure logs, you will need:</span>

1. <span style="color: rgb(0, 0, 0);">**Diagnostic Settings**</span>
    
    
    - <span style="color: rgb(0, 0, 0);">Configure diagnostic settings in Azure to export metrics and logs from source services (e.g., Entra ID, Activity Logs).</span>
    - <span style="color: rgb(0, 0, 0);">Logs must be sent to a supported destination for analysis and storage.</span>
2. <span style="color: rgb(0, 0, 0);">**Event Hubs**</span>
    
    
    - <span style="color: rgb(0, 0, 0);">One or more **Event Hubs** to temporarily store and stream logs exported by Azure services.</span>
    - <span style="color: rgb(0, 0, 0);">Log Collector will use Event Hubs as the ingestion point.</span>
3. <span style="color: rgb(0, 0, 0);">**Storage Account Container**</span>
    
    
    - <span style="color: rgb(0, 0, 0);">A **Storage Account container** to store checkpoint information about logs consumed by Log Collector.</span>
    - <span style="color: rgb(0, 0, 0);">This ensures logs are ingested reliably without duplication or loss.</span>


---

#### <span style="color: rgb(53, 152, 219);">**Step 1: Create an Event Hub for Microsoft Entra ID Logs**</span>

1. <span style="color: rgb(0, 0, 0);">**Go to Azure Portal &gt; Event Hubs &gt; Create Namespace**</span>
    
    
    - <span style="color: rgb(0, 0, 0);">Select **Resource Group** or create a new one.</span>
    - <span style="color: rgb(0, 0, 0);">Choose a **Region** and a **Pricing Tier (Standard or Premium)**.</span>
    - <span style="color: rgb(0, 0, 0);">Click **Review + Create** → **Create**.</span>
2. <span style="color: rgb(0, 0, 0);">**Create an Event Hub** inside the namespace</span>
    
    
    - <span style="color: rgb(0, 0, 0);">Navigate to the **Namespace** → Click **+ Event Hub**.</span>
    - <span style="color: rgb(0, 0, 0);">Set **Name**: entra-id-logs (Example)</span>
    - <span style="color: rgb(0, 0, 0);">Set **Partitions**: At least **2** (for redundancy).</span>
    - <span style="color: rgb(0, 0, 0);">Click **Create**.</span>
3. <span style="color: rgb(0, 0, 0);">**Create a Consumer Group (Optional)**</span>
    
    
    - <span style="color: rgb(0, 0, 0);">Go to **Event Hub &gt; Consumer Groups**.</span>
    - <span style="color: rgb(0, 0, 0);">Add a new group (e.g., aquila-agent-group).</span>
4. <span style="color: rgb(0, 0, 0);">**Generate Connection String**</span>
    
    
    - <span style="color: rgb(0, 0, 0);">Navigate to **Event Hubs Namespace &gt; Shared Access Policies**.</span>
    - <span style="color: rgb(0, 0, 0);">Click **+ Add Policy**.</span>
    - <span style="color: rgb(0, 0, 0);">Set Name: AquilaAgentPolicy.</span>
    - <span style="color: rgb(0, 0, 0);">Select **"Listen"** permission.</span>
    - <span style="color: rgb(0, 0, 0);">Copy **Primary Connection String** (used in the next steps).</span>

---

#### <span style="color: rgb(53, 152, 219);">**Step 2: Enable Diagnostic Settings for Microsoft Entra ID**</span>

1. <span style="color: rgb(0, 0, 0);">**Go to Azure Portal &gt; Microsoft Entra ID**.</span>
2. <span style="color: rgb(0, 0, 0);">Navigate to **Monitoring &gt; Diagnostic Settings**.</span>
3. <span style="color: rgb(0, 0, 0);">Click **+ Add Diagnostic Setting** and configure:</span>
    - <span style="color: rgb(0, 0, 0);">**Name**: entra-logs-to-aquila</span>
    - <span style="color: rgb(0, 0, 0);">**Log Categories**:</span>  
        <span style="color: rgb(0, 0, 0);">-Sign-in logs</span>  
        <span style="color: rgb(0, 0, 0);">-Audit logs</span>  
        <span style="color: rgb(0, 0, 0);">-Identity Protection logs</span>  
        <span style="color: rgb(0, 0, 0);">-Provisioning logs</span>
    - <span style="color: rgb(0, 0, 0);">**Destination**: Select **Event Hubs**.</span>
    - <span style="color: rgb(0, 0, 0);">**Choose the Event Hub Namespace** created earlier.</span>
    - <span style="color: rgb(0, 0, 0);">**Select the Event Hub (entra-id-logs)**.</span>
    - <span style="color: rgb(0, 0, 0);">Click **Save**.</span>

---

#### <span style="color: rgb(53, 152, 219);">**Step 3: Configure Azure Storage for Checkpointing**</span>

1. <span style="color: rgb(0, 0, 0);">**Create a Storage Account**</span>
    
    
    - <span style="color: rgb(0, 0, 0);">Navigate to **Azure Portal &gt; Storage Accounts &gt; Create**.</span>
    - <span style="color: rgb(0, 0, 0);">Select **Resource Group** (same as Event Hub).</span>
    - <span style="color: rgb(0, 0, 0);">Set **Storage Account Name**: </span>
    - <span style="color: rgb(0, 0, 0);">**Disable Hierarchical Namespace** and **Enable TLS 1.2**.</span>
    - <span style="color: rgb(0, 0, 0);">Click **Create**.</span>
2. <span style="color: rgb(0, 0, 0);">**Create a Blob Container**</span>
    
    
    - <span style="color: rgb(0, 0, 0);">Open the **Storage Account &gt; Containers**.</span>
    - <span style="color: rgb(0, 0, 0);">Click **+ Container**.</span>
    - <span style="color: rgb(0, 0, 0);">Set **Name**: </span>
    - <span style="color: rgb(0, 0, 0);">Set **Public Access Level**: Private.</span>
3. <span style="color: rgb(0, 0, 0);">**Copy Storage Account Keys**</span>
    
    
    - <span style="color: rgb(0, 0, 0);">Go to **Storage Account &gt; Access Keys**.</span>
    - <span style="color: rgb(0, 0, 0);">Copy **Storage Account Name &amp; Key** for integration configuration.</span>

---

<p class="callout warning">**<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 3">Please saved and provide this values to AQUILA Support Team.</span></span>**</p>

- <span style="color: rgb(0, 0, 0);">**Event Hub Name**: </span>
- <span style="color: rgb(0, 0, 0);">**Consumer Group**: </span>
- <span style="color: rgb(0, 0, 0);">**Event Hub Connection String**: </span>
- <span style="color: rgb(0, 0, 0);">**Storage Account Name**: </span>
- <span style="color: rgb(0, 0, 0);">**Storage Account Key**: </span>
- <span style="color: rgb(0, 0, 0);">**Storage Container Name**: </span>
- <span style="color: rgb(0, 0, 0);">**Resource Manager Endpoint(optional)**: </span>

---

<span style="color: rgb(0, 0, 0);">*<span class="TextRun SCXW71272603 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0">If you need further </span><span class="NormalTextRun SCXW71272603 BCX0">assistance</span><span class="NormalTextRun SCXW71272603 BCX0">, kindly contact </span></span><span style="color: rgb(53, 152, 219);">**<span class="TextRun SCXW71272603 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0">support@cytechint.com</span></span>**</span><span class="TextRun SCXW71272603 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0"> for prompt </span><span class="NormalTextRun SCXW71272603 BCX0">assistance</span><span class="NormalTextRun SCXW71272603 BCX0"> and guidance.</span></span><span class="EOP SCXW71272603 BCX0" data-ccp-props="{}"></span>*</span>

# NG SIEM - CISCO Meraki Integration

<span style="color: rgb(0, 0, 0);">Cisco Meraki provides a centralized cloud management platform for devices like MX Security Appliances, MR Access Points, and more. Its cloud-based architecture enables secure, scalable networks manageable from anywhere via the Meraki Dashboard or Mobile App. Each Meraki network generates events that can be collected and analyzed.</span>

---

### <span style="color: rgb(53, 152, 219);">**Integration Overview**</span>

<span style="color: rgb(0, 0, 0);">This integration supports event collection through:</span>

- <span style="color: rgb(0, 0, 0);">**Syslog** messages from Meraki devices</span>
- <span style="color: rgb(0, 0, 0);">**API Reporting Webhooks** via the Meraki cloud</span>

<span style="color: rgb(0, 0, 0);">Events can be searched, observed, and visualized.</span>

---

### <span style="color: rgb(53, 152, 219);">**Compatibility**</span>

- <span style="color: rgb(0, 0, 0);">Supports event collection from **MX Security Appliances** and **MR Access Points** via syslog.</span>
- <span style="color: rgb(0, 0, 0);">**MS Switch** events are **not supported** and will not be recognized.</span>

---

#### <span style="color: rgb(53, 152, 219);">**Cisco Meraki Dashboard Configuration**</span>

<span style="color: rgb(0, 0, 0);">**Syslog Setup:**</span>  
<span style="color: rgb(0, 0, 0);">Configure one or more syslog servers and specify Meraki message types to send to those servers. For details, refer to the <span style="color: rgb(132, 63, 161);">**[Syslog Server Overview and Configuration guide](https://documentation.meraki.com/General_Administration/Monitoring_and_Reporting/Syslog_Server_Overview_and_Configuration#Configuring_a_Syslog_Server)**</span>.</span>

<span style="color: rgb(0, 0, 0);">**API Endpoint (Webhooks):**</span>  
<span style="color: rgb(0, 0, 0);">Configure Meraki webhooks from the dashboard. See the <span style="color: rgb(132, 63, 161);">**[Webhooks Dashboard Setup](https://documentation.meraki.com/General_Administration/Monitoring_and_Reporting/Meraki_Device_Reporting_-_Syslog%2C_SNMP%2C_and_API#Webhooks_Dashboard_Setup)**</span> for detailed instructions.</span>

---

#### <span style="color: rgb(53, 152, 219);">**Configuring the Cisco Meraki Integration**</span>

<span style="color: rgb(0, 0, 0);">**Syslog Collection:**</span>

- <span style="color: rgb(0, 0, 0);">Select one or more of these options based on your syslog server setup:</span>
    
    
    - <span style="color: rgb(0, 0, 0);">Collect syslog via **UDP**</span>
    - <span style="color: rgb(0, 0, 0);">Collect syslog via **TCP**</span>
    - <span style="color: rgb(0, 0, 0);">Collect syslog from a **file**</span>
- <span style="color: rgb(0, 0, 0);">Enter the appropriate **Syslog Host**, **Port**, or **File Path** based on your selection.</span>

<span style="color: rgb(0, 0, 0);">**API Webhooks Collection:**</span>

- <span style="color: rgb(0, 0, 0);">Enable **Collect events from Cisco Meraki via Webhooks**.</span>
- <span style="color: rgb(0, 0, 0);">Enter the following values to configure the webhook listener endpoint:</span>
    
    
    - <span style="color: rgb(0, 0, 0);">**Listen Address**</span>
    - <span style="color: rgb(0, 0, 0);">**Listen Port**</span>
    - <span style="color: rgb(0, 0, 0);">**Webhook Path**</span>
- <span style="color: rgb(0, 0, 0);">The endpoint URL will be:</span>  
    <span style="color: rgb(0, 0, 0);">`https://{AGENT_ADDRESS}:8686/meraki/events`</span>
- <span style="color: rgb(0, 0, 0);">Enter the **Secret Value** matching the “Shared Secret” set in your Meraki webhook configuration.</span>
- <span style="color: rgb(0, 0, 0);">Provide **TLS configuration**: Meraki requires HTTPS for webhook endpoints, so configure a valid TLS certificate or use a reverse proxy with HTTPS in front of the integration.</span>

---

### <span style="color: rgb(53, 152, 219);">**Log Events**</span>

<span style="color: rgb(0, 0, 0);">Enable this option to collect Cisco Meraki log events across all applications configured for the selected log stream.</span>

---

### <span style="color: rgb(53, 152, 219);">**Logs Dataset**</span>

- <span style="color: rgb(0, 0, 0);">The `cisco_meraki.log` dataset contains events collected from the configured syslog server.</span>
- <span style="color: rgb(0, 0, 0);">All Cisco Meraki specific syslog fields are available under the `cisco_meraki.log` field group for detailed analysis.  
      
    </span>

<span style="color: rgb(0, 0, 0);">*<span class="TextRun SCXW71272603 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0">If you need further </span><span class="NormalTextRun SCXW71272603 BCX0">assistance</span><span class="NormalTextRun SCXW71272603 BCX0">, kindly contact </span></span><span style="color: rgb(53, 152, 219);">**<span class="TextRun SCXW71272603 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0">support@cytechint.com</span></span>**</span><span class="TextRun SCXW71272603 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0"> for prompt </span><span class="NormalTextRun SCXW71272603 BCX0">assistance</span><span class="NormalTextRun SCXW71272603 BCX0"> and guidance.</span></span><span class="EOP SCXW71272603 BCX0" data-ccp-props="{}"></span>*</span>

# NG SIEM - CISCO Umbrella Integration

##### <span style="color: rgb(53, 152, 219);">**Introduction**</span>

<span style="color: rgb(0, 0, 0);">Cisco Umbrella is a cloud-delivered security platform that provides an additional layer of defense against malicious threats on the internet using Cisco’s threat intelligence. It helps block access to:</span>

- <span style="color: rgb(0, 0, 0);">**Malware**</span>
- <span style="color: rgb(0, 0, 0);">**Adware**</span>
- <span style="color: rgb(0, 0, 0);">**Botnets**</span>
- <span style="color: rgb(0, 0, 0);">**Phishing attacks**</span>
- <span style="color: rgb(0, 0, 0);">**Known malicious websites**</span>

##### <span style="color: rgb(53, 152, 219);">**Assumptions**</span>

<span style="color: rgb(0, 0, 0);">The procedures described in this guide assume that a Log Collector has already been set up.</span>

##### <span style="color: rgb(53, 152, 219);">**Prerequisites**</span>

- <span style="color: rgb(0, 0, 0);">Full Admin access to Cisco Umbrella to create and manage Umbrella API keys.</span>
- <span style="color: rgb(0, 0, 0);">Umbrella API KeyAdmin access (if managing API key scopes and expirations).</span>

---

##### <span style="color: rgb(53, 152, 219);">**Requirements**</span>

<span style="color: rgb(0, 0, 0);">**This integration supports log ingestion from Cisco Umbrella. Data is collected from:**</span>

- <span style="color: rgb(0, 0, 0);">AWS S3 buckets using an SQS notification queue</span>
- <span style="color: rgb(0, 0, 0);">Cisco-managed S3 buckets without SQS</span>

##### <span style="color: rgb(53, 152, 219);">**Supported Dataset**</span>

- <span style="color: rgb(0, 0, 0);">log dataset: Collects Cisco Umbrella logs.</span>

---

##### <span style="color: rgb(53, 152, 219);">**Umbrella Logs**</span>

<span style="color: rgb(0, 0, 0);">**When using Cisco-managed S3 buckets without SQS:**</span>

- <span style="color: rgb(0, 0, 0);">Load balancing across multiple agents is not supported.</span>
- <span style="color: rgb(0, 0, 0);">A single agent must be configured to poll the S3 bucket.</span>
- <span style="color: rgb(0, 0, 0);">Vertical scaling can be applied by configuring the number of workers.</span>

<span style="color: rgb(0, 0, 0);">**The log dataset is responsible for collecting all Cisco Umbrella logs.**</span>

---

##### <span style="color: rgb(53, 152, 219);">**Advantages of the Umbrella API Integration**</span>

<span style="color: rgb(0, 0, 0);">**The Umbrella API introduces several improvements over older versions (v1 and Reporting v2 APIs):**</span>

- <span style="color: rgb(0, 0, 0);">Intuitive base URI</span>
- <span style="color: rgb(0, 0, 0);">API paths defined by top-level scopes</span>
- <span style="color: rgb(0, 0, 0);">Granular, intent-based API key scopes</span>
- <span style="color: rgb(0, 0, 0);">API key expiration support</span>
- <span style="color: rgb(0, 0, 0);">Updated API administration dashboard</span>
- <span style="color: rgb(0, 0, 0);">Programmatic API key administration</span>
- <span style="color: rgb(0, 0, 0);">Authentication &amp; authorization via OAuth 2.0 client credentials flow</span>
- <span style="color: rgb(0, 0, 0);">Portable, programmable API interface for integrations</span>

<span style="color: rgb(0, 0, 0);"> **Before sending requests to the Umbrella API, create Umbrella API credentials and generate an access token.**</span>  
<span style="color: rgb(0, 0, 0);">**More details: <span style="color: rgb(132, 63, 161);">[Cisco Umbrella API Authentication](https://developer.cisco.com/docs/cloud-security/authentication/#authentication)</span>** </span>

---

##### <span style="color: rgb(53, 152, 219);">**Authentication**</span>

- <span style="color: rgb(0, 0, 0);">The Umbrella API provides a **REST interface**.</span>
- <span style="color: rgb(0, 0, 0);">Supports **OAuth 2.0 client credentials flow**.</span>

<span style="color: rgb(0, 0, 0);">**Steps:**</span>

1. <span style="color: rgb(0, 0, 0);">Log in to Umbrella at: <span style="color: rgb(132, 63, 161);">**[https://dashboard.umbrella.com](https://dashboard.umbrella.com/)**</span></span>
2. <span style="color: rgb(0, 0, 0);">Create a new **API Key (ID + Secret)**.</span>
    
    
    - <span style="color: rgb(0, 0, 0);">Keys can only be copied once at creation.</span>
    - <span style="color: rgb(0, 0, 0);">Lost secrets cannot be retrieved.</span>
3. <span style="color: rgb(0, 0, 0);">Generate an **API Access Token** using your credentials.</span>

<p class="callout warning"><span style="color: rgb(0, 0, 0);"> **Important:** API keys, passwords, and tokens grant access to private customer data. **Never share them** with external users or organizations.</span></p>

---

##### <span style="color: rgb(53, 152, 219);">**Managing Umbrella API Keys**</span>

<span style="color: rgb(0, 0, 0);">**Create a New API Key**</span>

1. <span style="color: rgb(0, 0, 0);">Navigate to **Admin &gt; API Keys**</span>
    
    
    - <span style="color: rgb(0, 0, 0);">For MSP/MSSP: **Console Settings &gt; API Keys**</span>
2. <span style="color: rgb(0, 0, 0);">Click **Add Key**.</span>
3. <span style="color: rgb(0, 0, 0);">Enter a **Name** (≤256 characters) and optional **Description**.</span>
4. <span style="color: rgb(0, 0, 0);">Select **Scopes** (Read-Only or Read/Write).</span>
5. <span style="color: rgb(0, 0, 0);">Configure an **Expiry Date** (or select *Never Expire*).</span>
6. <span style="color: rgb(0, 0, 0);">(Optional) Add **Network Restrictions** (up to 10 public IPs or CIDRs).</span>
7. <span style="color: rgb(0, 0, 0);">Click **Create Key** → Copy and save **Key + Secret**.</span>

<span style="color: rgb(0, 0, 0);">**Refresh an API Key**</span>

1. <span style="color: rgb(0, 0, 0);">Go to **Admin &gt; API Keys**.</span>
2. <span style="color: rgb(0, 0, 0);">Expand the target key → Click **Refresh Key**.</span>
3. <span style="color: rgb(0, 0, 0);">Copy and save the new **Key + Secret**.</span>

<span style="color: rgb(0, 0, 0);">**Update an API Key**</span>

1. <span style="color: rgb(0, 0, 0);">Expand an existing key.</span>
2. <span style="color: rgb(0, 0, 0);">Update **Name, Description, Scopes, Expiry, or Network Restrictions**.</span>
3. <span style="color: rgb(0, 0, 0);">Click **Save**.</span>

---

<p class="callout warning"><span style="color: rgb(0, 0, 0);">To integrate Cisco Umbrella logs into AQUILA, provide the following details to **CyTech Support**:</span></p>

- <span style="color: rgb(0, 0, 0);">**Queue URL**</span>
    
    
    - <span style="color: rgb(0, 0, 0);">AWS SQS queue URL where messages will be received.</span>
    - <span style="color: rgb(0, 0, 0);">For Cisco-managed S3 without SQS, use **Bucket ARN** instead.</span>
- <span style="color: rgb(0, 0, 0);">**Bucket ARN**</span>
    
    
    - <span style="color: rgb(0, 0, 0);">Required for Cisco-managed S3.</span>
    - <span style="color: rgb(0, 0, 0);">Example: `arn:aws:s3:::cisco-managed-eu-central-1`</span>
    - **<span style="color: rgb(132, 63, 161);">[List of Cisco-managed S3 buckets](https://docs.umbrella.com/mssp-deployment/docs/enable-logging-to-a-cisco-managed-s3-bucket)</span>**
- <span style="color: rgb(0, 0, 0);">**Bucket Region**</span>
    
    
    - <span style="color: rgb(0, 0, 0);">The AWS region where the bucket is located.</span>
- <span style="color: rgb(0, 0, 0);">**Bucket List Prefix**</span>
    
    
    - <span style="color: rgb(0, 0, 0);">The root folder of the S3 bucket to be monitored (visible in the S3 UI).</span>
    - <span style="color: rgb(0, 0, 0);">Example: `1235_654vcasd23431e5dd6f7fsad457sdf1fd5`</span>
- <span style="color: rgb(0, 0, 0);">**Number of Workers**</span>
    
    
    - <span style="color: rgb(0, 0, 0);">Number of workers to process S3 objects (min = 1).</span>
- <span style="color: rgb(0, 0, 0);">**Bucket List Interval**</span>
    
    
    - <span style="color: rgb(0, 0, 0);">Time interval for polling the S3 bucket. Default = 120s.</span>
- <span style="color: rgb(0, 0, 0);">**Access Key ID**</span>
- <span style="color: rgb(0, 0, 0);">**Secret Access Key**</span>

<span style="color: rgb(0, 0, 0);">*<span class="TextRun SCXW71272603 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0">If you need further </span><span class="NormalTextRun SCXW71272603 BCX0">assistance</span><span class="NormalTextRun SCXW71272603 BCX0">, kindly contact </span></span><span style="color: rgb(53, 152, 219);">**<span class="TextRun SCXW71272603 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0">support@cytechint.com</span></span>**</span><span class="TextRun SCXW71272603 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0"><span style="color: rgb(53, 152, 219);"> </span>for prompt </span><span class="NormalTextRun SCXW71272603 BCX0">assistance</span><span class="NormalTextRun SCXW71272603 BCX0"> and guidance.</span></span><span class="EOP SCXW71272603 BCX0" data-ccp-props="{}"></span>*</span>

# NG SIEM - CISCO Secure Endpoint Integration

##### **<span style="color: rgb(53, 152, 219);">Introduction</span>**

<span style="color: rgb(0, 0, 0);">Cisco **Secure Endpoint** is a cloud-delivered, advanced **endpoint detection and response (EDR)** solution. It provides visibility and protection across multiple control points, enabling organizations to rapidly detect, contain, and remediate advanced threats.</span>

---

##### <span style="color: rgb(53, 152, 219);">**Assumptions**</span>

<span style="color: rgb(0, 0, 0);">The procedures in this guide assume that a **Log Collector** has already been set up.</span>

---

##### <span style="color: rgb(53, 152, 219);">**Requirements**</span>

<span style="color: rgb(0, 0, 0);">This integration is designed for collecting **Cisco Secure Endpoint logs**.</span>

##### <span style="color: rgb(53, 152, 219);">**Supported Dataset**</span>

- <span style="color: rgb(0, 0, 0);">**event dataset** → Supports Cisco Secure Endpoint **event logs**, either:</span>
    
    
    - <span style="color: rgb(0, 0, 0);">Received over **syslog**</span>
    - <span style="color: rgb(0, 0, 0);">Read from a **file**</span>

---

##### **<span style="color: rgb(53, 152, 219);">Generating Client ID and API Key</span>**

<span style="color: rgb(0, 0, 0);">To collect logs via the **Secure Endpoint API**, you must first generate API credentials:</span>

1. <span style="color: rgb(0, 0, 0);">Log in to your **AMP for Endpoints Console**.</span>
2. <span style="color: rgb(0, 0, 0);">Navigate to **Accounts &gt; Organization Settings**.</span>
3. <span style="color: rgb(0, 0, 0);">Under **Features**, click **Configure API Credentials**.</span>
4. <span style="color: rgb(0, 0, 0);">Generate and copy the **Client ID** and **Secure API Key**.</span>

<p class="callout warning"><span style="color: rgb(0, 0, 0);"> **Important:** You can only copy your **API Key** at the time of creation. It cannot be retrieved later. Store it securely.</span></p>

---

##### <span style="color: rgb(53, 152, 219);">**Secure Endpoint Logs**</span>

- <span style="color: rgb(0, 0, 0);">The **event dataset** collects Cisco Secure Endpoint event logs.</span>

---

##### <span style="color: rgb(53, 152, 219);">**Secure Endpoint API Capabilities**</span>

<span style="color: rgb(0, 0, 0);">The **Secure Endpoint API** can be used to retrieve and manage detailed information, including:</span>

- <span style="color: rgb(0, 0, 0);">Generate a list of **organizations** a user has access to.</span>
- <span style="color: rgb(0, 0, 0);">Generate a list of **policies** for a specified organization.</span>
- <span style="color: rgb(0, 0, 0);">Retrieve detailed information about a specific policy, such as:</span>
    
    
    - <span style="color: rgb(0, 0, 0);">General policy data</span>
    - <span style="color: rgb(0, 0, 0);">Associated network control lists</span>
    - <span style="color: rgb(0, 0, 0);">Associated computers</span>
    - <span style="color: rgb(0, 0, 0);">Associated groups</span>
    - <span style="color: rgb(0, 0, 0);">Proxy settings</span>
    - <span style="color: rgb(0, 0, 0);">Policy XML</span>
- <span style="color: rgb(0, 0, 0);">Generate a list of all **policy types** and supported **operating systems** for an organization.</span>

---

##### **<span style="color: rgb(53, 152, 219);">Top Use Cases</span>**

- <span style="color: rgb(0, 0, 0);">**Reporting:** Generate reports on policy settings across an organization.</span>
- <span style="color: rgb(0, 0, 0);">**Inspection:** Review a particular policy’s detailed settings.</span>
- <span style="color: rgb(0, 0, 0);">**Policy Auditing:** Query for policies that match specific criteria to determine which should be updated.</span>

---

##### **<span style="color: rgb(53, 152, 219);">API Response Format</span>**

<span style="color: rgb(0, 0, 0);">The Secure Endpoint API provides responses in three key objects:</span>

- <span style="color: rgb(0, 0, 0);">**Data** → Requested content.</span>
- <span style="color: rgb(0, 0, 0);">**Meta** → Metadata describing the request/response.</span>
- <span style="color: rgb(0, 0, 0);">**Errors** → Error details if the request fails.</span>

---

<p class="callout warning"><span style="color: rgb(0, 0, 0);">To enable log collection from the Cisco Secure Endpoint API, provide the following information to **CyTech Support**:</span></p>

- <span style="color: rgb(0, 0, 0);">**Client ID** → Cisco Secure Endpoint Client ID</span>
- <span style="color: rgb(0, 0, 0);">**API Key** → Cisco Secure Endpoint API Key</span>

<span style="color: rgb(0, 0, 0);">*<span class="TextRun SCXW71272603 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0">If you need further </span><span class="NormalTextRun SCXW71272603 BCX0">assistance</span><span class="NormalTextRun SCXW71272603 BCX0">, kindly contact </span></span><span style="color: rgb(53, 152, 219);">**<span class="TextRun SCXW71272603 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0">support@cytechint.com</span></span>**</span><span class="TextRun SCXW71272603 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0"> for prompt </span><span class="NormalTextRun SCXW71272603 BCX0">assistance</span><span class="NormalTextRun SCXW71272603 BCX0"> and guidance.</span></span><span class="EOP SCXW71272603 BCX0" data-ccp-props="{}"></span>*</span>

# NG SIEM - Cloudflare Integration

#### **<span style="color: rgb(53, 152, 219);">Introduction</span>**

<span style="color: rgb(0, 0, 0);">Cloudflare logs provide detailed insights into client connections, request paths through the Cloudflare network, and origin server responses. These logs help track activity, identify issues, and support security and performance analysis.</span>

---

#### <span style="color: rgb(53, 152, 219);">**Authentication Options**</span>

<span style="color: rgb(0, 0, 0);">You can configure log retrieval using the following authentication methods:</span>

1. <span style="color: rgb(0, 0, 0);">**Auth Email and Auth Key(Depreciated)**</span>
2. <span style="color: rgb(0, 0, 0);">**API Token**</span>

<span style="color: rgb(0, 0, 0);">For detailed information on authentication, refer to the<span style="color: rgb(132, 63, 161);"> **[Cloudflare API documentation](https://developers.cloudflare.com/api/)**</span>.</span>

---

#### <span style="color: rgb(53, 152, 219);">**1. Configure Using Auth Email and Auth Key**</span>

<span style="color: rgb(0, 0, 0);">To set up using this method, you need:</span>

- <span style="color: rgb(0, 0, 0);">**Auth Email**: The email address associated with your Cloudflare account.</span>
- <span style="color: rgb(0, 0, 0);">**Auth Key**: Your global API key, available on the <a class="cursor-pointer" data-end="1015" data-start="955" rel="noopener" style="color: rgb(0, 0, 0);" target="_new">My Profile</a> page.</span>
- <span style="color: rgb(0, 0, 0);">**Zone ID**: The unique identifier of your **<span style="color: rgb(132, 63, 161);">[Cloudflare zone](https://developers.cloudflare.com/fundamentals/account/find-account-and-zone-ids/)</span>**, available in the zone's dashboard.</span>

<span style="color: rgb(0, 0, 0);">These credentials must be included in the request headers:</span>

- <span style="color: rgb(0, 0, 0);">`X-Auth-Email`: Your account email.</span>
- <span style="color: rgb(0, 0, 0);">`X-Auth-Key`: Your global API key.</span>

<span style="color: rgb(0, 0, 0);">For more details, refer to Cloudflare’s <a class="cursor-pointer" data-end="1381" data-start="1297" rel="noopener" style="color: rgb(0, 0, 0);" target="_new">authentication headers guide</a>.</span>

---

#### <span style="color: rgb(53, 152, 219);">**2. Configure Using API Token**</span>

<span style="color: rgb(0, 0, 0);">To set up using an API token, you need:</span>

- <span style="color: rgb(0, 0, 0);">**API Token**: A token with appropriate permissions.</span>
- <span style="color: rgb(0, 0, 0);">**Zone ID**: As noted above, can be found in your Cloudflare zone dashboard.</span>

<span style="color: rgb(0, 0, 0);">**Minimum Required Permissions for the API Token**:</span>

- <span style="color: rgb(0, 0, 0);">`Account.Access:Audit Logs:Read`</span>
- <span style="color: rgb(0, 0, 0);">`Account.Account:Settings:Read`</span>

<span style="color: rgb(0, 0, 0);">API Tokens are preferred for security as they support fine-grained access control. Create and manage tokens via the <a class="cursor-pointer" data-end="1877" data-start="1807" rel="noopener" style="color: rgb(0, 0, 0);" target="_new">API Tokens dashboard</a>.</span>

<span style="color: rgb(0, 0, 0);">Manage Account&gt;Account API Tokens&gt;Custom Token&gt;Get Started</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-07/scaled-1680-/JtkhHwPR53u18MYN-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-07/JtkhHwPR53u18MYN-image.png)

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-07/scaled-1680-/ZmQwl21RBq8SR7QU-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-07/ZmQwl21RBq8SR7QU-image.png)

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-07/scaled-1680-/VDSOq15OcoEmSVPu-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-07/VDSOq15OcoEmSVPu-image.png)

```python
curl -X GET "https://api.cloudflare.com/client/v4/user/tokens/verify" \
  -H "Authorization: Bearer <token>" \
  -H "Content-Type: application/json"

```

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-07/scaled-1680-/ATiOTiGP9Lom8Psr-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-07/ATiOTiGP9Lom8Psr-image.png)

---

#### <span style="color: rgb(53, 152, 219);">**Audit Logs**</span>

<span style="color: rgb(0, 0, 0);">Audit logs provide a record of configuration changes within your Cloudflare account, including:</span>

- <span style="color: rgb(0, 0, 0);">Logins/logouts</span>
- <span style="color: rgb(0, 0, 0);">DNS setting changes</span>
- <span style="color: rgb(0, 0, 0);">Modifications to Firewall, Caching, Page Rules, Speed, Network, and Traffic features</span>

<span style="color: rgb(0, 0, 0);">These logs are essential for tracking administrative activity and detecting unusual behavior.</span>

---

<p class="callout warning"><span style="color: rgb(0, 0, 0);">To enable log collection from the Cloudflare API token, provide the following information to **CyTech Support**:</span></p>

- **<span style="color: rgb(0, 0, 0);">Account ID</span>**
- **<span style="color: rgb(0, 0, 0);">API Token</span>**

<span style="color: rgb(0, 0, 0);">*<span class="TextRun SCXW71272603 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0">If you need further </span><span class="NormalTextRun SCXW71272603 BCX0">assistance</span><span class="NormalTextRun SCXW71272603 BCX0">, kindly contact </span></span><span style="color: rgb(53, 152, 219);">**<span class="TextRun SCXW71272603 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0">support@cytechint.com</span></span>**</span><span class="TextRun SCXW71272603 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0"> for prompt </span><span class="NormalTextRun SCXW71272603 BCX0">assistance</span><span class="NormalTextRun SCXW71272603 BCX0"> and guidance.</span></span><span class="EOP SCXW71272603 BCX0" data-ccp-props="{}"></span>*</span>

# NG SIEM - CrowdStrike Integration

### CrowdStrike Integration

The [CrowdStrike](https://www.crowdstrike.com/) Falcon integration allows you to easily connect your CrowdStrike Falcon platform to Elastic for seamless onboarding of alerts and telemetry from CrowdStrike Falcon and Falcon Data Replicator. Elastic Security can leverage this data for security analytics including correlation, visualization and incident response

##### **Requirements** 

**API - Steps to Get Client ID and Client Secret in CrowdStrike Falcon (Recomended)**

1. **Log in to the Falcon Console**
    
    
    - Go to: [https://falcon.crowdstrike.com](https://falcon.crowdstrike.com/)
    - Use your admin credentials to log in.
2. **Navigate to API Clients and Keys**
    
    
    - Click on the **"Support"** (question mark icon) or your **User avatar** on the top right.
    - Select **"API Clients and Keys"** from the dropdown.  
        Alternatively, go to: `https://falcon.crowdstrike.com/support/api-clients-and-keys`
3. **Create a New API Client**
    
    
    - Click on **“Add new API client”**.
    - **Name** your client and optionally add a **description**.
    - Under **API Scopes**, select the required **permissions** based on what you need (e.g., read access to Hosts, Alerts, IOCs, etc.).
4. **Click** **Save**
5. **Copy the Client ID and Client Secret**
    
    
    - After saving, the **Client ID** and **Client Secret** will be displayed **once**.
    - Copy them immediately and store them securely (e.g., in a password manager or secrets vault).
6. **Token URL**

**<span class="TextRun SCXW161465391 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW161465391 BCX8" data-ccp-charstyle="eop">Collect CrowdStrike Falcon Data </span></span>Data Replicator Logs (input: aws-s3)**

1. Go to: [https://falcon.crowdstrike.com](https://falcon.crowdstrike.com)
2. Log in with your CrowdStrike account
3. In the left menu, click **Support &amp; Resources** → **Falcon Data Replicator** (or directly **FDR Access**)
4. You will immediately see a section called **AWS-S3 (Option 1)** with the three fields already filled in for your customer account:
    
    
    - **AWS: Access Key ID** → copy this
    - **AWS: Secret Access Key** → copy this (it’s shown only here; you can’t retrieve it again)
    - **AWS: Queue URL** → copy this exact SQS URL

<p class="callout info"><span class="TextRun SCXW161465391 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW161465391 BCX8" data-ccp-charstyle="eop">Please provide the following information to </span><span class="NormalTextRun SpellingErrorV2Themed SCXW161465391 BCX8" data-ccp-charstyle="eop">CyTech</span><span class="NormalTextRun SCXW161465391 BCX8" data-ccp-charstyle="eop">:</span></span><span class="EOP SCXW161465391 BCX8" data-ccp-props="{"201341983":0,"335559685":720,"335559739":160,"335559740":259}"> </span></p>

**<span class="TextRun SCXW161465391 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW161465391 BCX8" data-ccp-charstyle="eop">Collect CrowdStrike Falcon Data</span></span> Replicator Logs (input: aws-s3)**

- **AWS: Access Key ID**
- **AWS: Secret Access Key**
- **AWS: Queue URL**

**API - Steps to Get Client ID and Client Secret in CrowdStrike Falcon**

- **Client ID: <span class="TextRun SCXW161465391 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW161465391 BCX8" data-ccp-charstyle="eop">Client ID for the CrowdStrike.</span></span><span class="EOP SCXW161465391 BCX8" data-ccp-props="{"201341983":0,"335559739":160,"335559740":259}"> </span>**
- **Client Secret: <span class="TextRun SCXW161465391 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW161465391 BCX8" data-ccp-charstyle="eop">Client Secret for the CrowdStrike.</span></span><span class="EOP SCXW161465391 BCX8" data-ccp-props="{"201341983":0,"335559739":160,"335559740":259}"> </span>**
- **URL: <span class="TextRun SCXW161465391 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW161465391 BCX8" data-ccp-charstyle="eop">Token URL of CrowdStrike.</span></span><span class="EOP SCXW161465391 BCX8" data-ccp-props="{"201341983":0,"335559739":160,"335559740":259}"> </span>**

<div class="ListContainerWrapper SCXW161465391 BCX8" id="bkmrk-"></div>

# NG SIEM - GCP CSPM Integration

<span style="color: rgb(0, 0, 0);">The Google Cloud integration collects and parses **Google Cloud** **Audit Logs**, **VPC Flow Logs**, **Firewall Rules Logs,** and **Cloud DNS** **Logs** that have been exported from **Cloud Logging** to a **Google Pub/Subtopic sink** and collects **Google Cloud** **metrics** and metadata from **Google Cloud Monitoring.**</span>

#### <span style="color: rgb(53, 152, 219);">**Logs**</span>

- <span style="color: rgb(0, 0, 0);">**<span style="color: rgb(52, 73, 94);">Firewall Logs</span>:** Record allowed and denied network traffic based on firewall rules.</span>
- <span style="color: rgb(0, 0, 0);">**<span style="color: rgb(52, 73, 94);">VPC Flow Logs</span>:** Capture IP traffic flowing to and from network interfaces in a VPC.</span>
- <span style="color: rgb(0, 0, 0);">**<span style="color: rgb(52, 73, 94);">DNS Logs</span>:** Track DNS queries and responses handled by Google Cloud DNS.</span>
- <span style="color: rgb(0, 0, 0);">**<span style="color: rgb(52, 73, 94);">Load Balancing Logs</span>:** Provide request-level logs of traffic handled by load balancers, including latency and backend info.</span>

#### <span style="color: rgb(53, 152, 219);">**Metrics**</span>  


- **GCP Billing Metrics**: Track resource usage and cost across GCP services.
- **GCP Compute Metrics**: Monitor performance of Compute Engine instances (CPU, memory, disk, etc.).
- **GCP Firestore Metrics**: Provide insights into Firestore usage like reads, writes, and storage.
- **GCP Load Balancing Metrics**: Measure load balancer traffic, request counts, latency, and backend health.
- **GCP Storage Metrics**: Report usage, operation counts, and latency for Cloud Storage buckets.
- **GCP GKE Metrics**: Monitor Kubernetes clusters including node health, pod usage, and resource consumption.
- **GCP Dataproc Metrics**: Track job status, cluster usage, and Hadoop/Spark performance in Dataproc.
- **GCP PubSub Metrics**: Show message throughput, subscription rates, and processing latency.
- **GCP Redis Metrics**: Display memory usage, operations per second, and cache hit/miss rates for Memorystore Redis.
- **GCP Cloud Run Metrics**: Measure request counts, container instance metrics, and response times.
- **GCP CloudSQL Metrics**: Provide visibility into database performance, including connections, query latency, and CPU usage.

---

#### <span style="color: rgb(53, 152, 219);">**Authentication**</span>

<span style="color: rgb(0, 0, 0);">To use the **Google Cloud Platform (GCP)** integration, the client must configure a **Service Account (SA)** that represents a non-human identity requiring access to **GCP** resources.  
</span>

#### <span style="color: rgb(0, 0, 0);"><span style="color: rgb(53, 152, 219);">**Service Account**</span></span>

First, you need to [create a Service Account](https://cloud.google.com/iam/docs/creating-managing-service-accounts). A Service Account (SA) is a particular type of Google account intended to represent a non-human user who needs to access the GCP resources.

The AQUILA Agent uses the SA to access data on Google Cloud Platform using the Google APIs.

#### **<span style="color: rgb(53, 152, 219);">IAM Service Account Roles  
</span>**

##### **<span style="color: rgb(53, 152, 219);">For CSPM-GCP Integration</span>**

- <span style="color: rgb(0, 0, 0);">**Browser:** Access to browse GCP resources.</span>
- <span style="color: rgb(0, 0, 0);">**Cloud Asset Viewer:** Read only access to cloud assets metadata</span>

#### **<span style="color: rgb(53, 152, 219);">Logs Collection Configuration</span>**

The **Logs Collection Configuration** defines how log data is exported, transmitted, and processed within the system. It enables seamless integration between **Cloud Logging** and other Google Cloud services to ensure logs are efficiently collected, stored, and made available for analysis or monitoring.

**<span style="color: rgb(53, 152, 219);">Requirements</span>**

- **Pub/Sub Topic:** A **Pub/Sub topic** is a messaging channel that allows publishers to send messages asynchronously to multiple subscribers without them needing to know each other.
- **Subscription:** Subscriptions are named resources that receive messages on a particular topic. A subscriber client receives messages from a subscription and processes them.
- **Log Sink:** A log sink is a configuration that routes log entries from **Cloud Logging** to a chosen destination — such as **Cloud Storage**, **BigQuery**, or a **Pub/Sub topic** — for storage, analysis, or further processing.

<p class="callout info"><span class="TextRun SCXW124724174 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW124724174 BCX0">It’s</span><span class="NormalTextRun SCXW124724174 BCX0"> </span><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW124724174 BCX0">recommend</span><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW124724174 BCX0">ed</span> <span class="NormalTextRun SCXW124724174 BCX0">to have </span><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW124724174 BCX0">a </span><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW124724174 BCX0">separate</span><span class="NormalTextRun SCXW124724174 BCX0"> Pub/</span><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW124724174 BCX0">Sub topics</span><span class="NormalTextRun SCXW124724174 BCX0"> for each of the log types so that they can be parsed and stored in a specific data stream.</span></span><span class="EOP SCXW124724174 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335551550":1,"335551620":1,"335559685":0,"335559738":0,"335559739":0}"> </span></p>

---

#### **<span style="color: rgb(53, 152, 219);">Example Setup Using Google Cloud Console</span>**

1. Navigate to **"Logging" &gt; "Log Router" &gt; "Create Sink"**.
2. Provide a **Sink name** and description.
3. For **Sink destination**, select **"Cloud Pub/Sub topic"**. Choose an existing topic or create a new one.
4. If a new topic is created, you must also **create a subscription** for it.
5. Under **"Choose logs to include in sink"**, use a filter like: logName:"cloudaudit.googleapis.com"

#### **<span style="color: rgb(53, 152, 219);">Enable API Service</span>**  


The client can enable their API through the **APIs &amp; Services** section. To access it, click the **☰ (navigation menu)** icon to open the **sidebar**, then hover over **APIs &amp; Services** and select **Enabled APIs &amp; Services**. Alternatively, the client can locate it using the **search bar** at the top of the page. Next, click **Library**, search for the required API services, and enable them.

- **Cloud Asset API:** Provides metadata inventory and history of GCP resources and IAM policies for security analysis, audit, and compliance.
- **Cloud SQL Admin API:** Enables programmatic management of Cloud SQL instances, including creation, configuration, and backups.
- **Memorystore for Redis API:** Allows automated management of Redis instances on Memorystore, including provisioning, scaling, and configuration.

---

#### **<span style="color: rgb(53, 152, 219);">Service Account Key</span>**

1. Go to **IAM &amp; Admin &gt; Service Accounts** in the GCP Console.
2. Click the service account you created.
3. Under the **"Keys"** section, click **"Add Key" &gt; "Create new key"**.
4. Choose **JSON** as the key type.
5. **Download and securely store** the generated private key (it cannot be retrieved again from GCP if lost).

<p class="callout danger">**Please provide the following information to CyTech:**</p>

- <span class="TextRun SCXW124724174 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US">**<span class="NormalTextRun SCXW124724174 BCX0">Project </span>**<span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW124724174 BCX0">**ID** -</span> </span><span class="TextRun SCXW124724174 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW124724174 BCX0">The Project ID is the Google Cloud project ID where your resources exist. </span></span>
- <span class="TextRun SCXW124724174 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW124724174 BCX0">**Credentials File** - </span></span><span class="TextRun SCXW124724174 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW124724174 BCX0">Save the JSON file with the private key in a secure location of the file system, and make sure that the Log Collector Agent has at least read-only privileges to this file.</span><span class="NormalTextRun SCXW124724174 BCX0"> </span></span><span class="TextRun SCXW124724174 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW124724174 BCX0">Specify the file path in the Log Collector Agent integration UI in the "Credentials File" field. For example: /home/ubuntu/</span><span class="NormalTextRun SpellingErrorV2Themed SCXW124724174 BCX0">credentials.json</span><span class="NormalTextRun SCXW124724174 BCX0">.</span></span>
- <span class="TextRun SCXW124724174 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US">**<span class="NormalTextRun SCXW124724174 BCX0">Pub/</span><span class="NormalTextRun SCXW124724174 BCX0">Sub Topic</span>**<span class="NormalTextRun SCXW124724174 BCX0"> </span><span class="NormalTextRun SCXW124724174 BCX0">- </span></span><span class="TextRun SCXW124724174 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW124724174 BCX0">Name of the topic where the logs are written to.</span></span>
- <span class="TextRun SCXW124724174 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US">**<span class="NormalTextRun SCXW124724174 BCX0">Subscription</span>**<span class="NormalTextRun SCXW124724174 BCX0"> - </span></span><span class="TextRun SCXW124724174 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW124724174 BCX0">Use the short subscription name here, not the full-blown path with the project ID. You can find it as "Subscription ID" on the Google Cloud Console.</span></span><span class="EOP SCXW124724174 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}"> </span>

*<span class="TextRun SCXW71272603 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0">If you need further </span><span class="NormalTextRun SCXW71272603 BCX0">assistance</span><span class="NormalTextRun SCXW71272603 BCX0">, kindly contact </span></span>**<span class="TextRun SCXW71272603 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0">support@cytechint.com</span></span>**<span class="TextRun SCXW71272603 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0"> for prompt </span><span class="NormalTextRun SCXW71272603 BCX0">assistance</span><span class="NormalTextRun SCXW71272603 BCX0"> and guidance.</span></span><span class="EOP SCXW71272603 BCX0" data-ccp-props="{}"></span>*

# NG SIEM - GCP Integration

<span style="color: rgb(52, 73, 94);">**Google Cloud Platform** **(GCP)** is Google’s suite of cloud computing services that lets businesses and developers build, deploy, and scale applications on **Google’s infrastructure**. It offers a wide range of services, including computing power (like **virtual machines** and **Kubernetes**), **storage, databases**, **machine learning**, **networking**, and **analytics**. **GCP** is known for its global reliability, security, and integration with **Google’s data** and **AI tools**, making it suitable for everything from simple websites to complex enterprise applications.</span>

---

#### <span style="color: rgb(53, 152, 219);">**Authentication**</span>

To use the **Google Cloud Platform (GCP)** integration, the client must configure a **Service Account (SA)** that represents a non-human identity requiring access to **GCP** resources.

---

#### <span style="color: rgb(53, 152, 219);">**Service Account**</span>

First, you need to [create a Service Account](https://cloud.google.com/iam/docs/creating-managing-service-accounts). A Service Account (SA) is a particular type of Google account intended to represent a non-human user who needs to access the GCP resources.

The AQUILA Agent uses the SA to access data on Google Cloud Platform using the Google APIs.

---

#### **<span style="color: rgb(53, 152, 219);">IAM Service Account Roles</span>**

##### <span style="color: rgb(52, 73, 94);">**For GCP Integration**</span>  


- **Cloud Memorystore Redis Viewer:** Read-only access to Redis instances and related resources.
- **Cloud SQL Viewer:** Read-only access to Cloud SQL resources.
- Compute Viewer: Read-only access to get and list information about all Compute Engine resources, including instances, disks, and firewalls. Allows getting and listing information about disks, images, and snapshots, but does not allow reading the data stored on them.
- **Logs Viewer:** Access to view logs, except for logs with private contents.
- **Monitoring Viewer:** Read-only access to get and list information about all monitoring data and configuration.
- **Private Logs Viewer:** Access to view all logs, including logs with private contents.
- **Pub/Sub Subscriber:** Consume messages from a subscription, attach subscriptions to a topic, and seek to a snapshot.
- **Service Account Key Admin:** Create and manage (and rotate) service account keys.
- **Viewer:** View most Google Cloud resources. See the list of included permissions.

# NG SIEM - GitHub Integration

### **<span style="color: rgb(53, 152, 219);">Introduction</span>**

Elastic’s GitHub integration allows you to ingest GitHub logs, alerts, and developer activities into the Elastic Stack for centralized analysis. This supports use cases like vulnerability management, compliance auditing, and DevSecOps monitoring.

<p class="callout info">Note: This integration is only compatible with **GitHub Enterprise Cloud** and is **not supported on GitHub Enterprise Server**.</p>

---

### **<span style="color: rgb(53, 152, 219);">Option 1: GitHub Audit Logs</span>**  


**Description:**  
Audit logs contain records of all administrative and security events within a GitHub organization.

#### Requirements

- GitHub Enterprise Cloud
- You must be an organization owner
- Use a Personal Access Token (PAT) with `read:audit_log` scope

#### What It Does

- Captures repository creation, permission changes, team updates, and more
- Helps detect suspicious or non-compliant behavior

#### Setup Steps

1. **Create a PAT**
    
    
    - Go to GitHub → Developer Settings → Personal Access Tokens
    - Click "Generate new token"
    - Select `read:audit_log` scope
    - Save the token securely
2. **Configure Integration in Elastic**
    
    
    - Navigate to Integrations in Kibana
    - Search for "GitHub" and click "Add GitHub integration"
    - Select the "Audit Logs" data stream
    - Enter your organization name and paste your PAT
3. **Test and Deploy**
    
    
    - Click "Test integration" to verify connectivity
    - Choose a data stream name and index settings
    - Click "Save and Deploy"
4. **Verify in Kibana**
    
    
    - Navigate to Discover
    - Use the index pattern `logs-github.audit-*`
    - Filter using fields such as `actor`, `action`, or `created_at`

---

### **<span style="color: rgb(53, 152, 219);">Option 2: Code Scanning Alerts</span>**

**Description:**  
Collect static code analysis results from GitHub Advanced Security Code Scanning.

#### Requirements

- Code Scanning must be enabled per repository
- Use either:
    
    
    - GitHub App with `security_events` read permission
    - PAT with:
        
        
        - `security_events` (for private repositories)
        - `public_repo` (for public repositories)

#### What It Does

- Ingests vulnerabilities and insecure code patterns
- Supports SARIF format scan results

#### Setup Steps

1. **Enable Code Scanning in GitHub**
    
    
    - Go to your repository → Security → Code scanning alerts
    - Enable GitHub Advanced Security
    - Configure workflows such as CodeQL
2. **Generate PAT or GitHub App**
    
    
    - If using a PAT, ensure it includes `security_events` or `public_repo` scope
3. **Configure Integration in Elastic**
    
    
    - Open Integrations in Kibana
    - Add GitHub integration and select "Code Scanning"
    - Input organization name and credentials
4. **Test and Configure**
    
    
    - Test the integration
    - Set polling frequency (e.g., every 5 minutes)
    - Save and deploy
5. **Monitor in Kibana**
    
    
    - Use Discover with the index pattern `logs-github.code_scanning-*`
    - Filter by fields such as `severity`, `rule_id`, or `repository.name`

---

### **<span style="color: rgb(53, 152, 219);">Option 3: Secret Scanning Alerts</span>**

**Description:**  
Detect and alert on exposed secrets in source code repositories.

#### Requirements

- Secret Scanning must be enabled in repository settings
- You must be a repository or organization administrator
- Use either:
    
    
    - GitHub App with `secret_scanning_alerts` read permission
    - PAT with:
        
        
        - `repo` or `security_events` (for private repos)
        - `public_repo` (for public repos)

#### What It Does

- Flags exposed API keys, tokens, and credentials
- Helps prevent credential leaks

#### Setup Steps

1. **Enable Secret Scanning**
    
    
    - Go to GitHub repo → Settings → Code Security and Analysis
    - Enable "Secret scanning alerts"
2. **Generate Access**
    
    
    - Create a PAT with appropriate scopes
    - Or set up a GitHub App with necessary permissions
3. **Configure in Elastic**
    
    
    - Go to the GitHub integration in Kibana
    - Enable the "Secret Scanning" stream
    - Provide token and repository/org details
4. **Test and Save**
    
    
    - Test the connection
    - Select desired polling interval (e.g., 10 minutes)
    - Save and deploy
5. **Analyze Alerts**
    
    
    - Open Discover and use `logs-github.secret_scanning-*`
    - Use filters such as `alert_type`, `secret_type`, and `state`

---

### **<span style="color: rgb(53, 152, 219);">Option 4: Dependabot Alerts</span>**

**Description:**  
Monitor dependency vulnerabilities in GitHub repositories using Dependabot.

#### Requirements

- Dependabot must be enabled in repository settings
- You must be a repository or organization administrator
- Use either:
    
    
    - GitHub App
    - PAT with:
        
        
        - `repo`, `security_events`, or `public_repo` scope

#### What It Does

- Identifies and alerts on known insecure packages
- Includes CVE metadata and suggested fixes

#### Setup Steps

1. **Enable Dependabot in GitHub**
    
    
    - Go to Repository → Settings → Code Security and Analysis
    - Enable "Dependency Graph" and "Dependabot alerts"
2. **Generate GitHub App or PAT**
    
    
    - Ensure scopes include `repo`, `security_events`, or `public_repo`
3. **Configure in Elastic**
    
    
    - Go to GitHub integration
    - Enable "Dependabot"
    - Enter org/repo and credentials
4. **Test and Deploy**
    
    
    - Test the integration
    - Select polling interval
    - Save settings
5. **Monitor in Kibana**
    
    
    - Use Discover → `logs-github.dependabot-*`
    - Filter by `dependency_name`, `ecosystem`, `severity`, etc.

---

### **<span style="color: rgb(53, 152, 219);">Option 5: Issues &amp; Pull Requests</span>**

**Description:**  
Ingest GitHub issues, pull requests, comments, labels, milestones, and other metadata.

#### Requirements

- Use a GitHub App or PAT with:
    
    
    - `repo` (for private repositories)
    - `public_repo` (for public repositories)
    - Optional: `read:org` for org-wide access

#### What It Does

- Collects all issue and PR activity
- Enables filtering of pull requests with `github.issues.is_pr = true`

#### Setup Steps

1. **Create or Use PAT / GitHub App**
    
    
    - Ensure appropriate access to repositories
2. **Enable GitHub Integration in Elastic**
    
    
    - Choose "Issues" as the data stream
    - Enter credentials and repository/organization name
3. **Customize Settings**
    
    
    - Set state filter (e.g., `state=open` for open issues only)
    - Configure sync interval
4. **Test and Activate**
    
    
    - Verify GitHub API connectivity
    - Deploy integration
5. **View Data in Kibana**
    
    
    - Go to Discover → `logs-github.issues-*`
    - Use filters such as `assignees`, `labels`, `state`, or `is_pr`

---

### <span style="color: rgb(53, 152, 219);">**Comparison Table**</span>  


<table border="1" id="bkmrk-feature-github-app-p" style="border-collapse: collapse; width: 100%; border-width: 1px;"><colgroup><col style="width: 16.6915%;"></col><col style="width: 11.6841%;"></col><col style="width: 11.5648%;"></col><col style="width: 32.31%;"></col><col style="width: 14.1833%;"></col><col style="width: 13.7153%;"></col></colgroup><thead><tr><td class="align-center">Feature</td><td class="align-center">GitHub App</td><td class="align-center">PAT Support</td><td class="align-center">Required Scopes</td><td class="align-center">Public Repos</td><td class="align-center">Private Repos</td></tr></thead><tbody><tr><td>Audit Logs</td><td>No</td><td>Yes</td><td>`read:audit_log`  
</td><td>No</td><td>Yes</td></tr><tr><td>Code Scanning</td><td>Yes</td><td>Yes</td><td>`security_events`, `public_repo`

</td><td>Yes</td><td>Yes</td></tr><tr><td>Secret Scanning</td><td>Yes</td><td>Yes</td><td>`repo`, `security_events`, `public_repo`</td><td>Yes</td><td>Yes</td></tr><tr><td>Dependabot</td><td>Yes</td><td>Yes</td><td>`repo`, `security_events`, `public_repo`</td><td>Yes</td><td>Yes</td></tr><tr><td>Issues &amp; PRs</td><td>Yes</td><td>Yes</td><td>`repo`, `public_repo`, `read:org`</td><td>Yes</td><td>Yes</td></tr></tbody></table>

---

### **<span style="color: rgb(53, 152, 219);">Documentation References</span>**  


- Elastic GitHub Integration: [CyTech Docs](https://usdc-docs.cytechint.io/books/system-integrations/page/github-integration#bkmrk-to-use-this-integrat-4)
- GitHub Official Docs: 
    - [Code Scanning](https://docs.github.com/en/code-security/code-scanning)
    - [Secret Scanning](https://docs.github.com/en/code-security/secret-scanning)
    - [Dependabot](https://docs.github.com/en/code-security/supply-chain-security)
    - [Issues API](https://docs.github.com/en/rest/issues/issues?apiVersion=2022-11-28)

*If you need further assistance, kindly contact our support at [support@cytechint.com](mailto:info@cytechint.com) for prompt assistance and guidance.*

# NG SIEM - GoogleWorkspace Integration

##### **Introduction**

The Google Workspace integration collects and parses data from various **[Google Workspace audit reports APIs ](https://developers.google.com/admin-sdk/reports/reference/rest)**<span class="TextRun Highlight SCXW11705193 BCX8" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW11705193 BCX8" data-ccp-charstyle="eop">using a service account authorized via the **Admin SDK API**.</span></span>

##### **Requirements**

To ingest data from the Google Reports API, the following must be completed:

- An **administrator account** in Google Workspace.
- Enable the **Admin SDK API** in GCP.
- Create and configure a **Service Account**.
- Enable **Domain-Wide Delegation** for the service account.
- Configure the **OAuth Consent Screen**.

<p class="callout info">Note this is only applicable for Administrator Account in Google Workspace. Thank you and have a nice day.</p>

---

##### **Enable Admin SDK API**

Complete the following steps:

- Select the Google Cloud navigation menu &gt; **APIs &amp; Services** &gt; **Enabled APIs &amp; Services**
- Search and enable “**Admin SDK API**” from the **API library page**

##### **Configure OAuth Consent Screen**

Complete the following steps:

- Select the Google Cloud navigation menu &gt; **APIs &amp; Services** &gt; **Enabled APIs &amp; Services** &gt; **OAuth Consent Screen**
- User Type &gt; Internal &gt; Create
- Fill out the following information in subsequent steps
- App name:
- User support email:
- Authorized domains:
- Developer contact information:
- Save and Continue
- Save and Continue
- Back to Dashboard

---

##### **Create a Service Account**

To create a service account, do the following:

- Select the navigation menu in Google Cloud &gt; **APIs &amp; Services** &gt; **Credentials** &gt; **Create Credentials** &gt; **Service Account**
- Enter the following information:
- Service account name: a
- Service account ID:
- Leave the rest blank and continue
- Select your new **Service Account** &gt; **Keys** &gt; **Add Key** &gt; **Create New Key** &gt; **JSON**

---

##### **Enable Domain-wide Delegation**

- In your GW Admin Console select &gt; **Navigation Menu** &gt; **Security** &gt; **Access and data control** &gt; **API controls**
- Select **Manage Domain Wide Delegation** &gt; **Add New**
- Client ID: OAuth ID from Service Account in GCP
- Google Cloud Console &gt; **IAM &amp; Admin** &gt; **Service Accounts** &gt; **OAuth 2 Client ID** (copy to clipboard)
- **OAuth Scopes**: [https://www.googleapis.com/auth/admin.reports.audit.readonly](https://www.googleapis.com/auth/admin.reports.audit.readonly)

<p class="callout info">Please provide the following information to CyTech Support. Thank you</p>

- <span class="TextRun SCXW11705193 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US">**<span class="NormalTextRun SpellingErrorV2Themed SCXW11705193 BCX8" data-ccp-charstyle="eop">Delegated Account - </span>**<span class="NormalTextRun SpellingErrorV2Themed SCXW11705193 BCX8" data-ccp-charstyle="eop">the email of the administrator account, and not the email of the ServiceAccount.</span></span>
- <span class="TextRun SCXW11705193 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US">**<span class="NormalTextRun SpellingErrorV2Themed SCXW11705193 BCX8" data-ccp-charstyle="eop">Jwt</span><span class="NormalTextRun SCXW11705193 BCX8" data-ccp-charstyle="eop"> JSON</span>** </span><span class="TextRun SCXW11705193 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW11705193 BCX8" data-ccp-charstyle="eop">- The JSON credentials file downloaded from GCP. </span><span class="NormalTextRun SCXW11705193 BCX8" data-ccp-charstyle="eop">Raw contents of the JWT file. Useful when hosting a file along with the agent is not possible. NOTE: Please use either JWT File or JWT JSON parameter</span><span class="NormalTextRun SCXW11705193 BCX8" data-ccp-charstyle="eop">.</span></span><span class="EOP SCXW11705193 BCX8" data-ccp-props="{"201341983":0,"335559739":160,"335559740":259}"> </span>

<span class="EOP SCXW11705193 BCX8" data-ccp-props="{"201341983":0,"335559739":160,"335559740":259}">  *Reference link: [https://www.elastic.co/security-labs/google-workspace-attack-surface-part-two](https://www.elastic.co/security-labs/google-workspace-attack-surface-part-two)*</span>

<span class="EOP SCXW11705193 BCX8" data-ccp-props="{"201341983":0,"335559739":160,"335559740":259}">*<span class="TextRun SCXW71272603 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0">If you need further </span><span class="NormalTextRun SCXW71272603 BCX0">assistance</span><span class="NormalTextRun SCXW71272603 BCX0">, kindly contact our support at </span></span>**<span class="TextRun SCXW71272603 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0">support@cytechint.com</span></span>**<span class="TextRun SCXW71272603 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW71272603 BCX0"> for prompt </span><span class="NormalTextRun SCXW71272603 BCX0">assistance</span><span class="NormalTextRun SCXW71272603 BCX0"> and guidance.</span></span><span class="EOP SCXW71272603 BCX0" data-ccp-props="{}"></span>*</span>

# NG SIEM - Microsoft 365 Integration

#### **<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 3">Overview</span></span>**

<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 3">This integration with Microsoft Office 365 supports the ingestion of user, administrator, system, and policy-related events. It leverages the Office 365 Management Activity API to retrieve activity logs from both Office 365 and Azure Active Directory (Azure AD).</span></span>

This guide outlines the required steps to integrate with **Microsoft Office 365 and Azure AD** using the **Office 365 Management Activity API**. It covers application registration, permission setup, audit log configuration, and retrieval of key credentials for secure API access.

---

#### **Requirements**

**Summary of Actions Required:**

1. **Register an Application** in Microsoft Entra ID (formerly Azure AD) to establish identity and enable API access.
2. **Configure API Permissions** for Microsoft Graph and Office 365 Management APIs to authorize required data access.
3. **Grant Admin Consent** to ensure permissions are applied tenant-wide.
4. **Collect Key Credentials** such as Application ID, Tenant ID, and Client Secret for use in your integration.
5. **Verify if Unified Audit Logging is Enabled** in Microsoft 365 to ensure activity data is available via the API.

**Action Items Before Proceeding:**

- Ensure you have **Global Admin** access to your Azure/Microsoft 365 tenant.
- Prepare to create or use an existing **App Registration** in Microsoft Entra ID.
- Confirm that **Unified Audit Logging** is enabled; otherwise, prepare to activate it via the Microsoft 365 portal or PowerShell.
- Take note of your **admin email address** for PowerShell commands if using CLI to manage audit log settings.

---

#### **Steps to Configure Office 365 Integration for the Client**

##### **<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 4">Step 1: Microsoft Entra ID</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335559738":319,"335559739":319}"> - App Registration</span>**

**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Register Your Application in Microsoft Entra ID:</span></span>**

<div class="SCXW264382529 BCX0" id="bkmrk-log-in-to-your-azure"><div class="ListContainerWrapper SCXW264382529 BCX0">- <span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Log in to your Azure Account, click here - </span></span>**[Azure Portal Link](https://portal.azure.com/#home)**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">.</span></span>
- <span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Navigate to </span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Azure Active Directory</span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0"> &gt; </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">App registrations</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">.</span></span>
- <span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Click </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">New Registration</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">.</span></span>
- <span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Provide a </span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Name</span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0"> for the application, we can suggest "**CyTechAQUILA-Monitoring**".</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>
- <span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Click </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Register</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">.</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</div></div>---

##### **<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 4">Step 2: API Permissions</span></span>**

**<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 4"><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}">Microsoft Graph API Permissions:</span></span></span>**

If **User.Read** permission under **Microsoft Graph** tile is not added by default, add this permission.

<div class="SCXW264382529 BCX0" id="bkmrk-navigate-to-app-regi"><div class="ListContainerWrapper SCXW264382529 BCX0">- <span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Navigate to </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">App registrations</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0"> in the Azure Portal.</span></span>
- <span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Select the App you just created, then go to </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">API Permissions</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">.</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>
- <span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}">Search for **Microsoft Graph.**</span>
- <span class="NormalTextRun SCXW264382529 BCX0">Click </span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Add </span><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW264382529 BCX0">a permission</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">.</span></span>
- <span class="NormalTextRun SCXW264382529 BCX0">Select </span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Microsoft Graph</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0"> **&gt;** </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Delegated permissions</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">.</span></span>
- <span class="NormalTextRun SCXW264382529 BCX0">Search for and add </span>**<span class="NormalTextRun SpellingErrorV2Themed SCXW264382529 BCX0">User.Read</span>**<span class="NormalTextRun SCXW264382529 BCX0">.</span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</div></div>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Office 365 Management API Permissions:</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"> </span>**

<div class="SCXW264382529 BCX0" id="bkmrk-how-to-locate%3A%C2%A0-in-a"><div class="ListContainerWrapper SCXW264382529 BCX0">- <span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Search for </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Office 365 Management APIs</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0"> and add the required permissions.</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>
- <span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">In </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Application Permissions</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">, look for permissions.</span></span>
- <span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SpellingErrorV2Themed SCXW264382529 BCX0">Under ActivityFeed select: </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SpellingErrorV2Themed SCXW264382529 BCX0">ActivityFeed.Read</span></span>**
- Optionally, select **ActivityFeed.ReadDLP** to read DLP policy events.

</div></div>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Grant Admin Consent:</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"> </span>**

<div class="SCXW264382529 BCX0" id="bkmrk-in-api-permissions%2C-"><div class="ListContainerWrapper SCXW264382529 BCX0">- <span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">In </span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">API Permissions</span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">, click </span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">**Grant admin consent** for &lt;tenant name&gt;</span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">.</span></span>
- <span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">**Confirm** the action.</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</div></div>---

##### **<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 4">Step 3: Integration Requirements for Office 366</span></span>**

**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Application (Client) ID:</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"> </span>**

<div class="SCXW264382529 BCX0" id="bkmrk-how-to-locate%3A%C2%A0-go-t"><div class="ListContainerWrapper SCXW264382529 BCX0">- <span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Go to </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">App registrations</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0"> &gt; **Select your application**.</span></span>
- <span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Copy the </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Application (client) ID</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0"> from the overview page.</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</div></div>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Directory (Tenant) ID:</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"> </span>**

<div class="SCXW264382529 BCX0" id="bkmrk-in-the-azure-portal%2C"><div class="ListContainerWrapper SCXW264382529 BCX0">- <span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">In the Azure Portal, navigate to </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Azure Active Directory</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0"> &gt; </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Overview</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">.</span></span>
- <span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Copy the </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Directory (tenant) ID</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">.</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</div></div>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Create New Client Secret (Value):</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"> </span>**

<div class="SCXW264382529 BCX0" id="bkmrk-in%C2%A0app-registrations"><div class="ListContainerWrapper SCXW264382529 BCX0">- <span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">In </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">App registrations &gt; Select your application</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">, go to </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Certificates &amp; secrets</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">.</span></span>
- <span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Click </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">New client secret</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">.</span></span>
- <span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Add a description and </span><span class="NormalTextRun SCXW264382529 BCX0">expiration</span><span class="NormalTextRun SCXW264382529 BCX0"> period, then click </span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Add</span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">.</span></span>
- <span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Copy the </span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Value</span></span>**<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0"> **(displayed only once)**.</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</div></div>---

##### **<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 3">Step </span><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 3">4:</span><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 3"> Verify Unified Audit Logging</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335559738":281,"335559739":281}"> is Enabled</span>**

<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Unified Audit Logging must be enabled before accessing data via the Office 365 Management Activity API.</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"> </span>

**<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 3">Method 1: Using Microsoft 365 Security &amp; Compliance Center</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335559738":281,"335559739":281}"> </span>**

<div class="SCXW264382529 BCX0" id="bkmrk-sign-in-to-microsoft"><div class="ListContainerWrapper SCXW264382529 BCX0">1. <span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Sign in to Microsoft 365:</span></span>
    
    
    - <span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Go to </span></span>[<span class="TextRun Underlined SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-charstyle="Hyperlink">https://admin.microsoft.com</span></span>](https://admin.microsoft.com/)<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0"> and sign in with your Global Admin credentials.</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</div></div><div class="SCXW264382529 BCX0" id="bkmrk-access-the-security-"><div class="ListContainerWrapper SCXW264382529 BCX0">2. <span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Access the Security &amp; Compliance Center:</span></span>
    
    
    - <span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">In the left-hand menu, under </span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Admin centers</span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">, click on </span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Security</span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0"> (or go directly to </span></span>[<span class="TextRun Underlined SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-charstyle="Hyperlink">https://security.microsoft.com</span></span>](https://security.microsoft.com/)<span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">).</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</div><div class="ListContainerWrapper SCXW264382529 BCX0">3. <span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Navigate to Audit Log Search:</span></span>
    
    
    - <span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">In the Security &amp; Compliance Center, go to </span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Search</span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0"> in the left-hand menu and click on </span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Audit log search</span></span><span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">.</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</div><div class="ListContainerWrapper SCXW264382529 BCX0">4. <span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Check Audit Log Status:</span></span>
    
    
    - <span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">If you see </span><span class="NormalTextRun SCXW264382529 BCX0">an option</span><span class="NormalTextRun SCXW264382529 BCX0"> to search the audit log, then audit logging is already enabled.</span></span>
    - <span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">If you see a banner that says "Start recording user and admin activity" or a prompt to enable auditing, it means that audit logging is not yet enabled.</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</div></div>5. <span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">Enable Audit Logging:</span></span>
    
    
    - <span class="TextRun SCXW264382529 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0">If audit logging is not enabled, you can click on the prompt to enable it. This will enable auditing for all activities within your Microsoft 365 environment. The process may take a few hours to be fully operational.</span></span><span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

<p class="callout info">**<span class="TextRun SCXW161465391 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW161465391 BCX8" data-ccp-charstyle="eop">Please provide the following information to </span><span class="NormalTextRun SpellingErrorV2Themed SCXW161465391 BCX8" data-ccp-charstyle="eop">CyTech</span><span class="NormalTextRun SCXW161465391 BCX8" data-ccp-charstyle="eop">:</span></span><span class="EOP SCXW161465391 BCX8" data-ccp-props="{"201341983":0,"335559685":720,"335559739":160,"335559740":259}"> </span>**</p>

- **<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 3">Directory (tenant) ID: </span></span>**
- **<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 3">Application (client) ID:</span></span>**
- <div aria-label="Client Secret" class="euiFlexItem css-kpsrin-euiFlexItem-growZero">**Client Secret Value:**<span class="EOP SCXW264382529 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></div>

# NG SIEM - Mimecast Integration

##### **Introduction**

The Mimecast integration collects events from the [Mimecast API](https://integrations.mimecast.com/documentation/).

Agentless integrations allow you to collect data without having to manage Elastic Agent in your cloud. They make manual agent deployment unnecessary, so you can focus on your data instead of the agent that collects it. For more information, refer to [Agentless integrations](https://www.elastic.co/guide/en/serverless/current/security-agentless-integrations.html) and the [Agentless integrations FAQ](https://www.elastic.co/guide/en/serverless/current/agentless-integration-troubleshooting.html). Agentless deployments are only supported in Elastic Serverless and Elastic Cloud environments. This functionality is in beta and is subject to change. Beta features are not subject to the support SLA of official GA features.

##### **Requirements**

- **API URL**
- **Client ID**
- **Client Secret**

---

##### **Creating an API 2.0 Application**:

- Log in to ***Mimecast Administration Console***
- Navigate to ***Integrations | API and Platform Integrations***
- Locate the following ***Mimecast API 2.0*** tile and click on ***Generate Keys.***
- <div>After reading the ***Terms &amp; Conditions***, complete the ***I accept*** check box to enable the ***Next*** button to progress onto the next step.</div>
- <div>Complete the ***Application Details*** section.</div>

> We highly recommend creating a dedicated custom role with ***only*** the permissions required for the Application to function.
> 
> Select the minimum set of Products the App needs to access to function.

- Should we need to contact you regarding this API application, please provide details for a ***Technical Point of Contact.***

> Mimecast recommends a group rather than an individual contact.

- Review the Summary information for the API application and click on ***Add*** if you are happy to proceed with creating the application.
- The wizard completes and displays a pop-up window including your Client ID and Client Secret key data, where you can copy and save the credentials for the API application.

---

##### **Base URL (Mimecast API v2)**

To transition from your current API 1.0 URLs to API 2.0, we provide three API gateway options tailored to fulfill your performance, compliance, and data residency requirements:

- **Global URL**: The global API URL <mark class="code">api.services.mimecast.com</mark> which serves traffic from the nearest instance ensuring reduced latency and enhanced performance.
- **UK Instance URL**: For compliance and data residency requirements, customers can choose to process traffic via the UK instance using the regional URL: <mark class="code">uk-api.services.mimecast.com</mark>. This ensures API traffic is only processed within the UK instance of the Apigee Gateway.
- **US Instance URL**: Similarly, customers with compliance or residency requirements in the US can use <mark class="code">us-api.services.mimecast.com</mark> to process API traffic exclusively through the US instance of the Apigee Gateway.

<p class="callout info">Please provide the following information to CyTech Support. Thank you</p>

- **API URL**
- **Client ID**
- **Client Secret**

*If you need further assistance, kindly contact our support at* ***support@cytechint.com*** *for prompt assistance and guidance.*

# NG SIEM - Salesforce Integration via JWT Authentication

### **<span style="color: rgb(0, 0, 0);">Introduction</span>**

The Salesforce integration enables you to monitor your [Salesforce](https://www.salesforce.com/) instance. Salesforce is a customer relationship management (CRM) platform that supports businesses in managing marketing, sales, commerce, service, and IT teams from a unified platform accessible from anywhere.

---

#### **<span style="color: rgb(0, 0, 0);">Recommendation - Username / Password Authentication Integration  
</span>**

##### **Create New User Account**

- Go to **Home** page of **Salesforce** and click **Setup** in the top right menu bar.
- In the left side you will see a **Quick Find** search textbox, type **Users**.
- Click **Users** and it will redirect you to the **Users setup** page.
- Click **New User** button and fill up the form: 
    - First Name
    - Last Name
    - Email
    - Set **User License** to "**Salesforce**"
    - Choose an appropriate **Profile** (see below) 
        - **Profile and Permission Set Configuration**
            - **Create a custom profile** or clone an existing minimal profile: 
                - Clone the **"Standard User"** profile and name it something like **"Log Extraction Service"** or whatever you prefer.
                - Remove unnecessary permissions, keeping only: 
                    - **API Enabled**
                    - **View Setup and Configuration**
                    - **Specific object permissions for logs you need to extract**
            - **Essential permissions** for log extraction: 
                - **API Enabled** - Required for programmatic access
                - **View All Data** - If you need comprehensive log access
                - **Read** access to specific objects containing log data
    - Scroll down to the bottom and **check** the box that says **Generate new password and notify user immediately.**
    - Click **Save**.
- Open the account and set a new password.

Please take note of the **Email Address,** **Username** and **Password** associated with this account, as they will be required during the API and integration setup process.

##### **Salesforce instance URL**

This is the URL of your Salesforce Organization.

- **Salesforce Classic:** Given the example URL https://na9.salesforce.com/home/home.jsp, the Salesforce Instance URL is extracted as https://na9.salesforce.com.
- **Salesforce Lightning:** The instance URL is available under your user name in the **View Profile** tab. Use the correct instance URL in case of Salesforce Lightning because it uses \*.lightning.force.com but the instance URL is \*.salesforce.com.

<p class="callout info">Ensure the **Instance URL** is noted, as it will be used in both API creation and integration steps.</p>

---

##### **Client Key and Client Secret for Authentication**

To use this integration, you need to create a new Salesforce Application using OAuth. Follow these steps to create a connected application in Salesforce:

- Log in to **Salesforce** with the user credentials you want to collect data with.
- Click **Setup** in the top right menu bar.
- In the **Quick Find textbox**, search for **App Manager** or you can scroll down to **PLATFORM TOOLS** and select **App Manager.**
- **In the upper right corner, choose the New External Client App.**
- Provide a name for the connected application. This name will be displayed in the App Manager and on its App Launcher tile.
- Enter the API name. The default is a version of the name without spaces. Only letters, numbers, and underscores are allowed. If the original app name contains any other characters, edit the default name.
- Enter the **email address** of the **new account** you created earlier.
- Under the **API (Enable OAuth Settings)** section, check the box for **Enable OAuth Settings**.
- In the **Callback URL** field, enter the instance URL as specified in **Salesforce instance URL.** Example URL: https://na9.salesforce.com
- Select the following OAuth scopes to apply to the connected app:
    
    
    - **Manage user data via APIs (api)**
    - **Perform requests at any time (refresh\_token, offline\_access)**
    - (Optional) If you encounter any permission issues during data collection, add the **Full access (full)** scope.
- Select **Require Secret for the Web Server Flow** to require the app's client secret in exchange for an access token.
- Select **Require Secret for Refresh Token Flow** to require the app's client secret in the authorization request of a refresh token and hybrid refresh token flow.
- **Then scroll up above the Callback URL on the App Settings you will see the Consumer Key and Secret button, click it.**
- **It will create another tab. Verify the user account by entering the Verification Code.**
- **Copy the `Consumer Key` and `Consumer Secret` from the Consumer Details section. These values should be used as the Client ID and Client Secret, respectively, in the integration.**
- **Close that tab and go back to the External Client App Manager. Click Save.**

**Username**

- Provide the **Username** of the new account that you created earlier.

**Password**

- Please provide the **password** you set upon accessing the new account.

<p class="callout info">**Note:** When using a Salesforce instance with a security token, append the token directly to your password without spaces or special characters. For example, if your password is **Password** and your security token is **12345** enter: **Pasword12345**</p>

---

##### **Token URL:**

- Use the token URL to obtain authentication tokens for API access.
- For most Salesforce instances, the token URL follows this format: [https://login.salesforce.com/services/oauth2/token](https://login.salesforce.com/services/oauth2/token).
- If you're using a Salesforce sandbox environment, use [https://test.salesforce.com/services/oauth2/token](https://test.salesforce.com/services/oauth2/token) instead.
- For custom Salesforce domains, replace `login.salesforce.com` with your custom domain name. For example, if your custom domain is `mycompany.my.salesforce.com`, the token URL becomes [https://mycompany.my.salesforce.com/services/oauth2/token](https://mycompany.my.salesforce.com/services/oauth2/token). This applies to Sandbox environments as well.
- In the Salesforce integration, we internally append `/services/oauth2/token` to the URL. Make sure that the URL you provide in the Salesforce integration is the base URL without the `/services/oauth2/token` part. For example, if your custom domain is `mycompany.my.salesforce.com`, the complete token URL would be [https://mycompany.my.salesforce.com/services/oauth2/token](https://mycompany.my.salesforce.com/services/oauth2/token), but the URL you provide in the Salesforce integration should be [https://mycompany.my.salesforce.com](https://mycompany.my.salesforce.com/). In most cases, this is the same as the Salesforce instance URL.

<p class="callout info">**NOTE:** Salesforce Lightning users must use URL with \*.salesforce.com domain (similar to the Salesforce instance URL) instead of \*.lightning.force.com because the Salesforce API does not work with \*.lightning.force.com.</p>

---

#####  **API Version**

To find the API version:

- Go to the search textbox and type **Api Version**. Click the first **Api Version** on the list.

***Reference**: [https://www.integrate.io/blog/salesforce-rest-api-integration/](https://www.integrate.io/blog/salesforce-rest-api-integration/)*

<p class="callout info"><span style="color: rgb(0, 0, 0);">**Please provide these credentials and send it to CyTech Support:**</span></p>

- **Salesforce instance URL**
- **Client key and client secret for authentication**
- **Username**
- **Password**
- **Token URL**
- **API version (Optional)**

---

### <span style="color: rgb(0, 0, 0);">**Recommendation - JWT Integration**</span>

This guide provides a step-by-step process for setting up a secure integration between Salesforce and AQUILA. The focus is on using JWT (JSON Web Token) Bearer authentication, which is recommended for server-to-server communication as it avoids sharing passwords. We'll cover preparing Salesforce (where you generate and upload required credentials) and entering those into AQUILA configuration fields.

#### **Prerequisites**

- **Salesforce Account**: Admin access to create users and apps. Ensure your org supports API access (most do).
- **AQUILA Setup**: Access to Aquila (for managed agents).
- **Tools Needed**: OpenSSL (free, install via your OS: e.g., apt install openssl on Linux, or download for Windows/Mac).
- **Dedicated Integration User**: Create a Salesforce user specifically for this (not your personal account) with minimal permissions: 
    - License: Salesforce Integration (API-only).
    - Permissions: "API Enabled" (required); add "View Event Log Files" if ingesting logs.

---

##### **Create a Connected App in Salesforce**

This app generates the Client ID and links your certificate for JWT trust.

1. Log in to Salesforce &gt; Click the gear icon &gt; **Setup**.
2. Search for <span data-teams="true">Setup &gt; External Client Apps&gt; Enable and click button **New Connected Apps.**</span>
3. Fill in: 
    - **Connected App Name**: e.g., "AQUILA JWT Integration".
    - **API Name**: Auto-fills (edit if needed).
    - **Contact Email**: Your integration user's email.
4. Under **API (Enable OAuth Settings)**: 
    - Check **Enable OAuth Settings**.
    - **Callback URL**: Enter http://localhost (placeholder; not used in JWT).
    - **Selected OAuth Scopes**: Add api, refresh\_token, offline\_access. (Optional: Add full for broader access if needed.)
    - Check **Use digital signatures** &gt; Upload salesforce\_cert.crt.
5. Do **not** check any "Require Secret" options (no secret needed for JWT).
6. Click **Save** (wait 2-10 minutes for activation).
7. On the app page, copy the **Consumer Key**—this is your **Client ID**.
8. Click **Manage** &gt; **Edit Policies** &gt; Set **Permitted Users** to "Admin approved users are pre-authorized".
9. Assign the app to your integration user: Under **Profiles** or **Permission Sets**, add your user's profile.

Now Salesforce is ready—note your Instance URL (e.g., from your Salesforce homepage: https://your-instance.my.salesforce.com).

<div id="bkmrk-issue-possible-cause"><div dir="auto">*References:*  
*[OAuth 2.0 JWT Bearer Flow for Server-to-Server Integration](https://help.salesforce.com/s/articleView?id=sf.remoteaccess_oauth_jwt_flow.htm&type=5)*  
*[OAuth Authorization Flows](https://help.salesforce.com/s/articleView?id=sf.remoteaccess_oauth_flows.htm&type=5)*  
*[Salesforce input | Beats](https://www.elastic.co/docs/reference/beats/filebeat/filebeat-input-salesforce)*  
*[Salesforce Connector - How to authenticate using JWT](https://help.salesforce.com/s/articleView?id=001116755&type=1)*  
  
</div></div><p class="callout info"><span style="color: rgb(0, 0, 0);">**Please provide these credentials and send it to CyTech Support:**</span></p>

- **Username**
- **Client ID**
- **JWT Authentication Audience URL**
- **JWT Authentication Client Key Path**


##### **Summary Table**  


<table id="bkmrk-field-username%E2%80%93passw"><thead><tr><th>Field</th><th>Username–Password</th><th>JWT</th></tr></thead><tbody><tr><td>Client ID</td><td>✔ required</td><td>✔ required</td></tr><tr><td>Client Secret</td><td>✔ required</td><td>❌ not used</td></tr><tr><td>Username</td><td>✔ required</td><td>✔ required</td></tr><tr><td>Password</td><td>✔ required</td><td>❌ not used</td></tr><tr><td>Private Key Path</td><td>❌</td><td>✔ required</td></tr><tr><td>Audience URL</td><td>❌</td><td>✔ required</td></tr><tr><td>Token URL</td><td>✔ required</td><td>❌ leave blank</td></tr><tr><td>API Version</td><td>optional</td><td>optional</td></tr></tbody></table>

*If you need further assistance, kindly contact our support at **support@cytechint.com** for prompt assistance and guidance.*

# NG SIEM - Sophos Central Integration

##### **Sophos Central Integration**

The Sophos Central integration allows you to monitor Alerts and Events logs. Sophos Central is a cloud-native application with high availability. It is a cybersecurity management platform hosted on public cloud platforms. Each Sophos Central account is hosted in a named region. Sophos Central uses well-known, widely used, and industry-standard software libraries to mitigate common vulnerabilities.

Use the Sophos Central integration to collect logs across Sophos Central managed by your Sophos account. Visualize that data in Kibana, create alerts to notify you if something goes wrong, and reference data when troubleshooting an issue.

##### **Step-by-Step: How to Get Your Sophos Central API Credentials (Client ID, Client Secret, Tenant ID, Request URL)**

1. 1. **Log in to Sophos Central Admin** Open your browser and go to: [https://central.sophos.com](https://central.sophos.com) Log in with your admin account.
    2. **Go to API Credentials Manager** On the left sidebar, click **Global Settings** (gear icon at the bottom). Then click **API Credentials Manager**.
    3. **Create a new credential** Click the blue button **+ Add Credential** (top right).
    4. **Fill in the details**
        
        
        - **Name**: Give it a clear name (e.g., “PowerShell Automation”, “SIEM Integration”, “My Script 2025”)
        - **Role**: Choose the role that matches what you need (usually “Admin” or “Read-Only” is fine)
        - Click **Save** (or **Add**)
    5. **Copy the four pieces of information immediately** A new window/pop-up will appear showing:
        
        <div><div><div>  
        </div></div><div dir="auto"><div>  
        </div><table dir="auto"><thead><tr><th data-col-size="md">What you need</th><th data-col-size="lg">Value shown in the portal</th><th data-col-size="sm">Action</th></tr></thead><tbody><tr><td data-col-size="md">Client ID</td><td data-col-size="lg">Long string (e.g., 12345678-abcd-1234-efgh-1234567890ab)</td><td data-col-size="sm">Copy it</td></tr><tr><td data-col-size="md">Client Secret</td><td data-col-size="lg">Long secret key</td><td data-col-size="sm">COPY THIS NOW – it will never be shown again!</td></tr><tr><td data-col-size="md">Tenant ID (Customer ID)</td><td data-col-size="lg">GUID like a1b2c3d4-e5f6-7890-g1h2-i3j4k5l6m7n8</td><td data-col-size="sm">Copy it</td></tr><tr><td data-col-size="md">Request URL</td><td data-col-size="lg">Use the Whoami endpoint first:</td><td data-col-size="sm">Always use this URL first:</td></tr><tr><td data-col-size="md"> </td><td data-col-size="lg">[https://api.central.sophos.com/whoami/v1](https://api.central.sophos.com/whoami/v1)</td><td data-col-size="sm"> </td></tr></tbody></table>
        
        <div>  
        </div></div></div>→ Click **Copy** buttons or select + Ctrl+C for each field. → Paste everything into a secure password manager or your script immediately.
    6. **Close the window** Once you’ve copied everything, click **Done** or close the pop-up.

<p class="callout info">**<span class="TextRun SCXW161465391 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW161465391 BCX8" data-ccp-charstyle="eop">Please provide the following information to </span><span class="NormalTextRun SpellingErrorV2Themed SCXW161465391 BCX8" data-ccp-charstyle="eop">CyTech</span><span class="NormalTextRun SCXW161465391 BCX8" data-ccp-charstyle="eop">:</span></span><span class="EOP SCXW161465391 BCX8" data-ccp-props="{"201341983":0,"335559685":720,"335559739":160,"335559740":259}"> </span>**</p>

- **Client ID:**
- **Client Secret:**
- **Tenant ID:**
- **Request URL:**

# NG SIEM- AWS CSPM Integration

##### **Introduction**

CSPM discovers and evaluates the services in your cloud environment, like storage, compute, IAM, and more, against hardening guidelines defined by the Center for Internet Security (CIS) to help you identify and remediate configurations risks like:

- Publicly exposed storage buckets
- IAM Users without MFA enabled
- Networking objects that allow ingress to remote server administration ports (22, 3389, etc.)

##### **Recommendation**

[](https://www.elastic.co/guide/en/security/current/cspm-get-started.html#cspm-set-up-cloud-access-section)**Set up cloud account access**

The CSPM integration requires access to AWS’s built-in [`SecurityAudit` IAM policy](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_job-functions.html#jf_security-auditor) in order to discover and evaluate resources in your cloud account. To provide access we need:

<div class="book" id="bkmrk-default-instance-rol" lang="en"><div class="section"><div class="ulist itemizedlist">- **IAM Role**
- **[Direct access keys](https://www.elastic.co/guide/en/security/current/cspm-get-started.html#cspm-use-keys-directly "Option 2 - Direct access keys")**

</div></div></div>[](https://www.elastic.co/guide/en/security/current/cspm-get-started.html#cspm-use-instance-role)**Create IAM User**

Follow AWS’s [IAM roles for Amazon EC2](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-roles-for-amazon-ec2.html) documentation to create an IAM role using the IAM console, which automatically generates an instance profile.

<div class="book" id="bkmrk-create-an-iam-role%3A-" lang="en"><div class="section"><div class="olist orderedlist">1. Create an IAM role:
    
    <div class="olist orderedlist">
    1. In AWS, go to your IAM dashboard. Click <span class="strong strong">**Roles**</span>, then <span class="strong strong">**Create role**</span>.
    2. On the <span class="strong strong">**Select trusted entity**</span> page, under <span class="strong strong">**Trusted entity type**</span>, select <span class="strong strong">**AWS service**</span>.
    3. Under <span class="strong strong">**Use case**</span>, select <span class="strong strong">**EC2**</span>. Click <span class="strong strong">**Next**</span>.
    4. On the <span class="strong strong">**Add permissions**</span> page, search for and select `SecurityAudit`. Click <span class="strong strong">**Next**</span>.
    5. On the <span class="strong strong">**Name, review, and create**</span> page, name your role, then click <span class="strong strong">**Create role**</span>.
    
    </div>
2. Attach your new IAM role to an EC2 instance:
    
    <div class="olist orderedlist">
    1. In AWS, select an EC2 instance.
    2. Select <span class="strong strong">**Actions &gt; Security &gt; Modify IAM role**</span>.
    3. On the <span class="strong strong">**Modify IAM role**</span> page, search for and select your new IAM role.
    4. Click <span class="strong strong">**Update IAM role**</span>.
    
    </div>
3. **Create Direct access keys**
    
    Access keys are long-term credentials for an IAM user or AWS account root user. To use access keys as credentials, you must provide the `Access key ID` and the `Secret Access Key`. After you provide credentials, [finish manual setup](https://www.elastic.co/guide/en/security/current/cspm-get-started.html#cspm-finish-manual "Finish manual setup").
    
    For more details, refer to [Access Keys and Secret Access Keys](https://docs.aws.amazon.com/general/latest/gr/aws-sec-cred-types.html).
    
    <div class="book" id="bkmrk-access-key-id%3A-the-f" lang="en"><div class="section"><div class="ulist itemizedlist">
    - `Access key ID`: The first part of the access key.
    - `Secret Access Key`: The second part of the access key.
    
    </div></div></div>

</div></div></div><p class="callout info"><span class="TextRun SCXW161465391 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW161465391 BCX8" data-ccp-charstyle="eop">Please provide the following information to </span><span class="NormalTextRun SpellingErrorV2Themed SCXW161465391 BCX8" data-ccp-charstyle="eop">CyTech</span><span class="NormalTextRun SCXW161465391 BCX8" data-ccp-charstyle="eop">:</span></span><span class="EOP SCXW161465391 BCX8" data-ccp-props="{"201341983":0,"335559685":720,"335559739":160,"335559740":259}"> </span></p>

- **Access Key ID**
- **Secret Access Key**

# NG SIEM – LastPass Integration

#### <span style="color: rgb(53, 152, 219);">**Overview**</span>

The **LastPass Elastic Integration** allows the ingestion of data from the LastPass Admin Console for enhanced monitoring and reporting.

This integration collects three main data streams:

- **Detailed Shared Folder Data** – provides detailed information about shared folders, sites within them, and associated access permissions.
- **Event Report Logs** – captures audit events and activities within the organization’s LastPass Business account (logins, password changes, sharing actions, admin activities, etc.).
- **User Logs** – gathers data about user accounts, including profile information and status.

These logs help monitor password management activities, access permissions, and user behavior for compliance and auditing purposes.

#### <span style="color: rgb(53, 152, 219);">**Prerequisites**</span>

Before configuring the integration, ensure that the following components and credentials are available.

##### **LastPass Business Account**

A **LastPass Business account** is required to use this integration.  
Free or personal accounts are not supported.

##### **Elastic Stack Requirements**

- **Elasticsearch** – Required to store and index collected data.
- **Kibana** – Required to visualize and manage data streams.  
    You can use Elastic Cloud (recommended) or a self-managed Elastic Stack deployment.

##### **API Credentials**

Two key credentials are required for Elastic to access the LastPass API:

1. **Account Number (CID)**  
    
    - Found in the **Admin Console → Dashboard tab**.
    - Displayed at the top of the page, preceded by the label *“Account Number”*.[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-10/scaled-1680-/TmN30MHXhaoncBZc-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-10/TmN30MHXhaoncBZc-image.png)
2. **Provisioning Hash**
    - Go to **Admin Console → Advanced → Enterprise API**.
    - If no hash exists: click **Create provisioning hash → OK**.
    - If forgotten: click **Reset your provisioning hash → OK** to generate a new one.
    - **Important:** Resetting invalidates the previous hash, requiring reconfiguration in all connected integrations. [![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-10/scaled-1680-/Rcm5TC0r3OMfPJNn-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-10/Rcm5TC0r3OMfPJNn-image.png)

<p class="callout info">*Keep both the CID and Provisioning Hash secure. These credentials grant access to your organization’s LastPass data.*</p>

#### <span style="color: rgb(53, 152, 219);">**Integration Configuration**</span>

##### **1. Access the Integrations Page**

1. Navigate to:  
    **Integrations → LastPass → Add LastPass**
2. Provide an identifiable integration name.

##### **2. Input Connection Settings**

Under **Configure integration**, fill in the required fields:

- ##### **Account Number:**
    
    
    - Enter the LastPass Business Account Number (CID) found in your LastPass Admin Console → Dashboard tab, at the top of the page.

- ##### **Provisioning Hash:**
    
    
    - Enter the Provisioning Hash generated in Admin Console → Advanced → Enterprise API. This serves as the API secret used for authentication.

- ##### **URL:**
    
    
    - Default API endpoint for LastPass Enterprise integration. This is automatically pre-filled in most cases.


##### **3. Select Data Streams**

Enable the data streams you want to collect. It can be enabled or disable specific data streams based on visibility needs:

- **Detailed Shared Folder Data**
- **Event Report Logs**
- **User Logs**

##### **4. Save and Deploy**

Once all required fields are configured:

1. Click **Save and continue**
2. Assign the integration to your Elastic Agent policy
3. Confirm deployment

##### <span style="color: rgb(53, 152, 219);">**Notes**</span>

- The integration **only supports LastPass Business** accounts via the **Enterprise API**.
- The **Provisioning Hash** must be updated in Elastic whenever it is regenerated in LastPass.
- **Multifactor authentication** may be required to access the Admin Console.
- The **LastPass API** does not manage pre-configured SSO (Cloud) app groups, these remain outside integration scope.

*If you need further assistance, kindly contact* <span style="color: rgb(53, 152, 219);">***support@cytechint.com***</span> *for prompt assistance and guidance.*

# NG SIEM - Apache Tomcat



# NG SIEM - Microsoft Defender ATP Logs

### <span style="color: rgb(53, 152, 219);">**Prerequisite**</span>

**Before starting, ensure you have the following ready:**

<div align="left" dir="ltr" id="bkmrk-requirement-details-"><div align="left" dir="ltr"><table><colgroup><col width="200"></col><col width="424"></col></colgroup><tbody><tr><td>Item

</td><td>Details

</td></tr><tr><td>OS

</td><td>Windows 10 / Windows Server 2016 or later

</td></tr><tr><td>Privileges

</td><td>Local Administrator access on the machine

</td></tr><tr><td>Network

</td><td>Outbound HTTPS (port 443) to our Elastic endpoint

</td></tr></tbody></table>

</div></div><div class="euiStep__content css-leysgr-euiStep__content-xs" id="bkmrk--1"><div></div></div>##### **Step 1. Connect local Kibana to a Cloud instance**

If you are running this Kibana instance against a hosted Elasticsearch instance, proceed with manual setup.

Save the **Elasticsearch** endpoint as `<es_url>` and the cluster **Password** as `<password>` for your records

##### **Step 2. Download and install Filebeat**

First time using Filebeat? See the [Quick Start](https://www.elastic.co/docs/reference/beats/filebeat/filebeat-installation-configuration.html).

<div class="euiStep__content css-leysgr-euiStep__content-xs" id="bkmrk-download-the-filebea"><div><div class="euiText euiMarkdownFormat css-ft7wu6-euiText-m-euiTextColor-default-euiMarkdownFormat-m-default">1. Download the Filebeat Windows zip file from the [Download](https://www.elastic.co/downloads/beats/filebeat) page.
2. Extract the contents of the zip file into `C:\Program Files`.
3. Rename the `filebeat-9.2.0-windows` directory to `Filebeat`.
4. Open a PowerShell prompt as an Administrator (right-click the PowerShell icon and select **Run As Administrator**). If you are running Windows XP, you might need to download and install PowerShell.
5. From the PowerShell prompt, run the following commands to install Filebeat as a Windows service.

</div></div></div>```
cd "C:\Program Files\Filebeat"
.\install-service-filebeat.ps1
```

Modify the settings under `output.elasticsearch` in the `C:\Program Files\Filebeat\filebeat.yml` file to point to your Elasticsearch installation.

##### **Step 3. Edit the configuration**

Modify `C:\Program Files\Filebeat\filebeat.yml` to set the connection information:

```
output.elasticsearch:
  hosts: ["<es_url>"]
  username: "elastic"
  password: "<password>"
  # If using Elasticsearch's default certificate
  ssl.ca_trusted_fingerprint: "<es cert fingerprint>"
setup.kibana:
  host: "<kibana_url>"
```

Where `<password>` is the password of the `elastic` user, `<es_url>` is the URL of Elasticsearch, and `<kibana_url>` is the URL of Kibana. To [configure SSL](https://www.elastic.co/guide/en/beats/filebeat/9.2/configuration-ssl.html#ca-sha256) with the default certificate generated by Elasticsearch, add its fingerprint in `<es cert fingerprint>`.

> ***Important:*** Do not use the built-in `elastic` user to secure clients in a production environment. Instead set up authorized users or API keys, and do not expose passwords in configuration files. [Learn more](https://www.elastic.co/docs/reference/beats/filebeat/securing-filebeat.html).

##### **Step 4. Enable and configure the microsoft module**

From the C:\\Program Files\\Filebeat folder, run:

Modify the settings in the `modules.d/microsoft.yml` file. You must enable at least one fileset.

```
filebeat.exe modules enable microsoft
```

##### **Step 5. Start Filebeat**

The `setup` command loads the Kibana dashboards. If the dashboards are already set up, omit this command.

```
.\filebeat.exe setup
Start-Service filebeat
```

##### **Step 6. Module status**

We will check that data is received from the Filebeat `microsoft` module

##### **Modules**

These are the modules that will be ingested after integrating Microsoft Defender ATP Logs

---

```
microsoft.defender_atp : Module for ingesting Microsoft Defender ATP.
microsoft.defender_atp.lastUpdateTime:  The date and time (in UTC) the alert was last updated. (type: date)
microsoft.defender_atp.resolvedTime: The date and time in which the status of the alert was changed to 'Resolved'. (type: date)
microsoft.defender_atp.incidentId: The Incident ID of the Alert. (type: keyword)
microsoft.defender_atp.investigationId: The Investigation ID related to the Alert. (type: keyword)
microsoft.defender_atp.investigationState: The current state of the Investigation. (type: keyword)
microsoft.defender_atp.assignedTo: Owner of the alert. (type: keyword)
microsoft.defender_atp.status: Specifies the current status of the alert. Possible values are: 'Unknown', 'New', 'InProgress' and 'Resolved'. (type: keyword)
microsoft.defender_atp.classification: Specification of the alert. Possible values are: 'Unknown', 'FalsePositive', 'TruePositive'. (type: keyword)
microsoft.defender_atp.determination: Specifies the determination of the alert. Possible values are: 'NotAvailable', 'Apt', 'Malware', 'SecurityPersonnel', 'SecurityTesting', 'UnwantedSoftware', 'Other'. (type: keyword)
microsoft.defender_atp.threatFamilyName: Threat family. (type: keyword)
microsoft.defender_atp.rbacGroupName: User group related to the alert (type: keyword)
microsoft.defender_atp.evidence.domainName: Domain name related to the alert (type: keyword)
```

That's everything needed on your end. Once the Filebeat service is running, logs will automatically begin forwarding to our Elastic instance in real time — no ongoing maintenance is required on your side. If the service ever stops for any reason (e.g. after a Windows update or restart), it will resume automatically as it is installed as a Windows service. If you run into any issues during setup, just reach out and we'll walk you through it.

# NG SIEM - Microsoft Defender for Cloud

#### <span style="color: rgb(53, 152, 219);">**Overview**</span>

The [Microsoft Defender for Cloud<svg aria-hidden="true" class="euiIcon css-1mv5qmp-euiIcon-s" height="16" role="presentation" viewbox="0 0 16 16" width="16" xmlns="http://www.w3.org/2000/svg"><path d="M11 2h2.293L6.646 8.646l.708.708L14 2.707V5h1V1h-4v1Z"></path><path d="M3 2a1 1 0 0 0-1 1v10a1 1 0 0 0 1 1h10a1 1 0 0 0 1-1V7h-1v6H3V3h6V2H3Z"></path></svg><span class="css-gb1zbv-euiScreenReaderOnly">(external, opens in a new tab or window)</span>](https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-cloud-introduction) integration allows you to monitor security alert events and assessments. When integrated with Elastic Security, this valuable data can be leveraged within Elastic for analyzing the resources and services that users are protecting through Microsoft Defender.

Use the Microsoft Defender for Cloud integration to collect and parse data from Azure Event Hub, Azure REST API, and then visualize that data in Kibana.

#### <span style="color: rgb(53, 152, 219);">**Compatibility**</span>

The Microsoft Defender for Cloud integration uses the Azure REST API. It uses the `2021-06-01` API version for retrieving assessments and the `2019-01-01-preview` API version for retrieving sub-assessments.

#### <span style="color: rgb(53, 152, 219);">**How it works**</span>

For the **assessment** data stream, the `/assessments` endpoint retrieves all available assessments for the provided scope, which can be a Subscription ID or a Management Group Name. For each assessment, if sub-assessments are available, we will make another call to collect them. We will aggregate the results from both calls and publish them.

#### <span style="color: rgb(53, 152, 219);">**What data does this integration collect?**</span>

This integration collects log messages of the following types:

- `Event`: allows users to preserve a record of security events that occurred on the subscription, which includes real-time events that affect the security of the user's environment. For further information connected to security alerts and type, refer to the [security alerts reference guide<svg aria-hidden="true" class="euiIcon css-1mv5qmp-euiIcon-s" height="16" role="presentation" viewbox="0 0 16 16" width="16" xmlns="http://www.w3.org/2000/svg"><path d="M11 2h2.293L6.646 8.646l.708.708L14 2.707V5h1V1h-4v1Z"></path><path d="M3 2a1 1 0 0 0-1 1v10a1 1 0 0 0 1 1h10a1 1 0 0 0 1-1V7h-1v6H3V3h6V2H3Z"></path></svg><span class="css-gb1zbv-euiScreenReaderOnly">(external, opens in a new tab or window)</span>](https://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-reference).
- `Assessment`: collect security assessments on all your scanned resources inside a scope from the [Assessments<svg aria-hidden="true" class="euiIcon css-1mv5qmp-euiIcon-s" height="16" role="presentation" viewbox="0 0 16 16" width="16" xmlns="http://www.w3.org/2000/svg"><path d="M11 2h2.293L6.646 8.646l.708.708L14 2.707V5h1V1h-4v1Z"></path><path d="M3 2a1 1 0 0 0-1 1v10a1 1 0 0 0 1 1h10a1 1 0 0 0 1-1V7h-1v6H3V3h6V2H3Z"></path></svg><span class="css-gb1zbv-euiScreenReaderOnly">(external, opens in a new tab or window)</span>](https://learn.microsoft.com/en-us/rest/api/defenderforcloud-composite/assessments/list?view=rest-defenderforcloud-composite-latest&tabs=HTTP) and [Sub Assessments<svg aria-hidden="true" class="euiIcon css-1mv5qmp-euiIcon-s" height="16" role="presentation" viewbox="0 0 16 16" width="16" xmlns="http://www.w3.org/2000/svg"><path d="M11 2h2.293L6.646 8.646l.708.708L14 2.707V5h1V1h-4v1Z"></path><path d="M3 2a1 1 0 0 0-1 1v10a1 1 0 0 0 1 1h10a1 1 0 0 0 1-1V7h-1v6H3V3h6V2H3Z"></path></svg><span class="css-gb1zbv-euiScreenReaderOnly">(external, opens in a new tab or window)</span>](https://learn.microsoft.com/en-us/rest/api/defenderforcloud-composite/sub-assessments/list?view=rest-defenderforcloud-composite-latest&tabs=HTTP) endpoints.

#### <span style="color: rgb(53, 152, 219);">**Requirements**</span>  


##### <span style="color: rgb(53, 152, 219);">**Collect logs from Azure Event Hub**</span>

- **Azure Event Hub** - Elastic recommends using one Azure Event Hub for each integration. Visit [Create an Azure Event Hub](https://docs.elastic.co/integrations/azure#create-an-event-hub) to learn more. Use Azure Event Hub names up to 30 characters long to avoid compatibility issues.
- **Consumer Group** - We recommend using a dedicated consumer group for the Azure Event Hub input. Reusing consumer groups among non-related consumers can cause unexpected behavior and possibly lost events.
- **Connection String** - The connection string required to communicate with Azure Event Hubs. See [Get an Azure Event Hubs connection string](https://docs.microsoft.com/en-us/azure/event-hubs/event-hubs-get-connection-string) to learn more.
- **Storage Account** - The name of the storage account where the consumer group's state/offsets will be stored and updated.
- **Storage Account Key** - The storage account key will be used to authorise access to data in your storage account.

##### <span style="color: rgb(53, 152, 219);">**Collect Microsoft Defender Cloud logs via API**</span>

- **Client ID -** The client ID related to creating a new application on Azure.
- **Client Secre**t - The secret related to the client ID.
- **Tenant ID** - The tenant ID related to creating a new application on Azure.
- **Management Group Name** - The name of the management group. Provide either `Subscription ID` or `Management Group Name` as the scope for the request. If both are provided, then `Management Group Name` will take precedence.
- **Subscription ID -** The unique identifier for the subscription. Provide either `Subscription ID` or `Management Group Name` as the scope for the request. If both are provided, then `Management Group Name` will take precedence.

#### <span style="color: rgb(53, 152, 219);">**Conclusion**</span>

Integrating Microsoft Defender for Cloud with Elastic Security provides a powerful way to centralize and analyze your cloud security posture. By leveraging Azure Event Hub for real-time security event streaming and the Azure REST API for assessment data, you gain comprehensive visibility into the threats and vulnerabilities affecting your Azure resources — all within Kibana.

With the `Event` data stream capturing live security alerts and the `Assessment` data stream continuously evaluating your scanned resources at both the assessment and sub-assessment level, your team can detect, investigate, and respond to risks more efficiently.

To get the most out of this integration, ensure your Azure environment is properly configured with dedicated Event Hub instances, isolated consumer groups, and the appropriate API credentials (Client ID, Client Secret, and Tenant ID). Choosing the right scope — whether a Subscription ID or Management Group Name — will also determine the breadth of coverage across your organization's Azure resources.

Once set up, this integration serves as a foundational component of a broader cloud security monitoring strategy, enabling your security operations team to act on meaningful, contextualized data rather than navigating siloed tools.

<div class="euiFormRow euiFormRow--hasLabel FormRow-sc-1xnkkrk-1 dClJVK css-1cb1ecx-euiFormRow-fullWidth" id="bkmrk-"><div class="euiFormRow__fieldWrapper"><div class="euiFormHelpText euiFormRow__text css-ns19v4-euiFormHelpText" id="bkmrk--1"></div></div></div><div class="euiFormRow euiFormRow--hasLabel FormRow-sc-1xnkkrk-1 dClJVK css-1cb1ecx-euiFormRow-fullWidth" id="bkmrk--2"><div class="euiFormRow__fieldWrapper"><div class="euiFormHelpText euiFormRow__text css-ns19v4-euiFormHelpText" id="bkmrk--3"></div></div></div>

# AQUILA - Microsoft Defender for Endpoint

### <span style="color: rgb(53, 152, 219);">**Overview**</span>

This guide walks through the full process of integrating Microsoft Defender for Endpoint (MDE) to centralize security telemetry, enrich alerts, and enable unified threat hunting across your environment.

This integration is for <span style="color: rgb(185, 106, 217);">[Microsoft Defender for Endpoint](https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/microsoft-defender-endpoint?view=o365-worldwide)</span> logs.

Microsoft Defender for Endpoint integration collects data for Alert, Machine, Machine Action, and Vulnerability logs using REST API.

This integration collects the following logs:

- <span style="color: rgb(185, 106, 217);">[Alert](https://learn.microsoft.com/en-us/defender-endpoint/api/get-alerts?view=o365-worldwide) </span>- Retrieves alerts generated by Microsoft Defender for Endpoint.
- <span style="color: rgb(185, 106, 217);">[Machine](https://learn.microsoft.com/en-us/defender-endpoint/api/get-machines?view=o365-worldwide)</span> - Retrieves machines that have communicated with Microsoft Defender for Endpoint.
- <span style="color: rgb(185, 106, 217);">[Machine Action](https://learn.microsoft.com/en-us/defender-endpoint/api/get-machineactions-collection?view=o365-worldwide)</span> - Retrieves logs of actions carried out on machines.
- <span style="color: rgb(185, 106, 217);">[Vulnerability](https://learn.microsoft.com/en-us/defender-endpoint/api/get-assessment-software-vulnerabilities#2-export-software-vulnerabilities-assessment-via-files)</span> - Retrieves logs of Vulnerability.

### <span style="color: rgb(53, 152, 219);">**Prerequisites**</span>

Before you begin, ensure the following are in place:

- An active Microsoft Defender for Endpoint license (Plan 1 or Plan 2, or Microsoft 365 Defender)
- Access to the Microsoft Entra ID (formerly Azure AD) portal to register an application
- Permissions to grant API permissions within your tenant (typically a Global Administrator or Security Administrator role)

### <span style="color: rgb(53, 152, 219);">**Azure App Registration**</span>

This integration authenticates to the MDE API using OAuth 2.0 client credentials. You need to register an application in Microsoft Entra ID and grant it the appropriate API permissions.

**Step 1:** Register a New Application

- Navigate to **portal.azure.com** and sign in with an account that has sufficient privileges.
- Go to **Microsoft Entra ID** &gt; **App registrations** &gt; **New registration**.
- Provide a descriptive name.
- Under Supported account types, select Accounts in this organizational directory only (Single tenant).
- Leave the Redirect URI blank. Click Register.
- Copy and save the **Application (client) ID** and **Directory (tenant) ID** from the overview page. You will need these later.

**Step 2**: Create a Client Secret

- In your newly created app registration, navigate to **Certificates &amp; secrets** &gt; **Client secrets** &gt; **New client secret**.
- Add a description and choose an expiry period appropriate for your organization.
- Click Add, then immediately copy the **secret Value**. This is the only time it is shown in full.

**Step 3:**

- In the app registration, go to **API permissions** &gt; **Add a permission**.
- Select APIs my organization uses, then search for and select WindowsDefenderATP.
- Choose Application permissions and grant the following minimum required scopes:

<div align="left" dir="ltr" id="bkmrk-permission-purpose-a"><table><colgroup><col width="200"></col><col width="424"></col></colgroup><thead><tr><th scope="col">Permission

</th><th scope="col">Purpose

</th></tr></thead><tbody><tr><td>Alert.Read.All

</td><td>Read all MDE alerts and incidents

</td></tr><tr><td>Machine.Read.All

</td><td>Read device inventory and health state

</td></tr><tr><td>Vulnerability.Read.All

</td><td>Read vulnerability and software inventory

</td></tr><tr><td>AdvancedQuery.Read.All

</td><td>Execute advanced hunting queries (optional)

</td></tr></tbody></table>

</div>**Step 4:**

- Click Add permissions, then click Grant admin consent for \[Your Tenant\]. Confirm when prompted.
- Verify the Status column shows Granted for \[tenant\] for all added permissions.

<div class="euiFlexGroup css-weekwv-euiFlexGroup-responsive-none-spaceBetween-flexStart-row" id="bkmrk-"><div class="euiFlexItem css-kpsrin-euiFlexItem-growZero"></div></div><p class="callout warning"><span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" style="color: rgb(224, 62, 45);" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 3">Please saved and provide this values:</span></span></p>

1. **<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 3">Directory (tenant) ID</span></span>**
2. **<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 3">Application (client) ID</span></span>**
3. <div aria-label="Client Secret" class="euiFlexItem css-kpsrin-euiFlexItem-growZero">**Client Secret Value**</div>

<span class="euiSwitch__label css-cxzz3-euiSwitch__label" id="bkmrk-microsoft-defender-f-1"></span>

*If you need further assistance, kindly contact our support at<span style="color: rgb(53, 152, 219);"> </span>*<span style="color: rgb(53, 152, 219);">***support@cytechint.com***</span> *for prompt assistance and guidance.*

# NG SIEM - Microsoft Defender XDR

### <span style="color: rgb(53, 152, 219);">**Overview**</span>

This guide covers the full integration of Microsoft Defender XDR with the Elastic Stack. Microsoft Defender XDR is a unified extended detection and response platform that correlates signals across endpoints, identities, email, cloud apps, and cloud workloads. Bringing its data into Elastic enables centralized threat hunting, cross-platform correlation, and unified SIEM workflows alongside your other log sources.

### <span style="color: rgb(53, 152, 219);">**Prerequisites**</span>

**Microsoft Requirements**

- An active Microsoft 365 Defender or Microsoft Defender XDR license
- Access to Microsoft Entra ID (Azure AD) to register an application
- Global Administrator or Security Administrator role to grant API permissions and admin consent
- (Optional) Microsoft Defender XDR Streaming API requires a Microsoft 365 E5 or equivalent license for real-time event streaming

### <span style="color: rgb(53, 152, 219);">**Azure App Registration**</span>

The Elastic Agent authenticates to the Microsoft Graph Security API using OAuth 2.0 client credentials. If you do not already have an app registration, follow the steps below.

Step 1: Register the Application

- Go to portal.azure.com and navigate to Microsoft Entra ID &gt; App registrations &gt; New registration.
- Name the app (e.g., elastic-xdr-integration) and select Single tenant under Supported account types.
- Leave the Redirect URI blank and click Register.
- On the overview page, copy and save the Application (client) ID and Directory (tenant) ID.

Step 2: Create a Client Secret

- Go to Certificates &amp; secrets &gt; Client secrets &gt; New client secret.
- Add a description and set an appropriate expiry period.
- Click Add and immediately copy the secret Value — it is only shown once.

<p class="callout info">**Important Secret Visibility**: Azure only displays the secret value immediately after creation. If the page is refreshed or the value was not saved, you will need to generate a new secret. If you regenerate, remember to update the secret in all Elastic integrations that reference this app registration to avoid breaking existing data pipelines.</p>

Step 3: Grant API Permissions

- Go to API permissions &gt; Add a permission &gt; Microsoft Graph.
- Select Application permissions and add the following:
- Click Add permissions.
- If also integrating Microsoft Defender for Endpoint data, additionally add WindowsDefenderATP &gt; Application permissions: Alert.Read.All and Machine.Read.All.
- Click Grant admin consent for \[Your Tenant\] and confirm. Verify all permissions show Granted status.

### <span style="color: rgb(53, 152, 219);">**Elastic Fleet Configuration**</span>

With the Azure application registered, the next step is to configure Elastic Fleet to deploy the MDE integration.

- Collect alerts and incidents using Microsoft Graph Security API 
    - Client ID
    - Client Secret
    - Tenant ID

- Collect events using Azure Event Hub 
    - Event Hub
    - Consumer Group
    - Connection String
    - Storage Account
    - Storage Account Key

- Collect vulnerabilities using Microsoft Defender for Endpoint API 
    - Client ID
    - Client Secret
    - Tenant ID
    - Oauth2 Token URL

### <span style="color: rgb(53, 152, 219);">**Conclusion**</span>

Integrating Microsoft Defender XDR with Elastic unlocks a truly unified security operations experience, bringing together telemetry from endpoints, identities, email, cloud apps, and cloud workloads into a single platform for detection, investigation, and response. By connecting the Microsoft Graph Security API to Elastic's SIEM and search capabilities, security teams gain correlated, cross-workload visibility that goes far beyond what any single Defender product can offer on its own. Whether you're leveraging prebuilt detection rules, building custom threat hunting queries, or streaming real-time events via the XDR Streaming API, this integration gives your SOC the context and speed needed to tackle modern multi-stage attacks — all from one place.

# NG SIEM Microsoft Entra ID

### <span style="color: rgb(53, 152, 219);">**Overview**</span>

This guide walks you through connecting Microsoft Entra ID to Elastic so that your identity logs flow automatically into Elasticsearch. Once set up, you'll be able to search, visualize, and alert on Sign-in logs, Audit logs, and Identity Protection logs directly in Kibana.

The integration uses Azure Event Hub as the bridge — Entra ID pushes logs into Event Hub, and the Elastic Agent reads from it in real time. A Storage Account is used behind the scenes to checkpoint progress, so Elastic always picks up exactly where it left off.

### <span style="color: rgb(53, 152, 219);">**Prerequisite**</span>

Before you begin, ensure the following are in place:

- Active Azure subscription with a Microsoft Entra ID tenant
- An Elastic deployment (Cloud or self-managed 8.x) with Kibana accessible
- Microsoft Entra ID Free or P1 license for Sign-in and Audit logs
- Microsoft Entra ID P2 license if you want Identity Protection logs (UserRiskEvents, RiskyUsers)
- Azure permissions to create Event Hubs and Storage Accounts

**Part 1 — Set Up Azure Resources**

In this part you will create the Event Hub and Storage Account in Azure. These are the two Azure-side components that Elastic connects to.

**Step 1.1 Create an Event Hub Namespace and Hub**

The Event Hub is the channel that Entra ID will push logs into.

- In the Azure Portal (portal.azure.com), search for Event Hubs in the top search bar and click Create.
- Choose your Subscription and Resource Group (or create a new one).
- Set a Namespace Name — for example: entra-elastic-hub. This is the parent container.
- Choose a Region close to your Elastic deployment and set Pricing tier to Standard or above.
- Click Review + Create, then Create. Wait for the deployment to complete.
- Once deployed, open the namespace and click + Event Hub in the top toolbar.
- Name the hub — for example: entra-logs — and click Create.

**Step 1.2 Create a Consumer Group**

A consumer group is a named reader slot on the Event Hub. Elastic needs its own so it does not conflict with any other tools reading from the same hub.

- Inside your Event Hub (entra-logs), click Consumer Groups in the left sidebar.
- Click + Consumer Group.
- Name it elastic-consumer and click Save.
- Write this name down — you will paste it into Elastic in Part 3.

**Step 1.3 Copy the Connection String**

The connection string is how Elastic authenticates to your Event Hub Namespace.

- Navigate back to the Event Hub Namespace (the parent, not the individual hub).
- In the left sidebar, click Shared Access Policies.
- Click RootManageSharedAccessKey.
- Copy the Connection string–primary key. It starts with Endpoint=sb://

**Step 1.4 Create a Storage Account**

Elastic uses a Storage Account to checkpoint which events it has already read. This prevents duplicate ingestion if the agent restarts.

- In the Azure Portal, search for Storage Accounts and click Create.
- Choose the same Subscription and Resource Group as your Event Hub.
- Enter a Storage Account Name — for example: entraelascheckpoint. Names must be lowercase, 3–24 characters, no hyphens.
- Choose the same Region as your Event Hub and leave all other defaults.
- Click Review + Create, then Create.
- Once deployed, open the storage account and click Access Keys in the left sidebar.
- Click Show next to key1 and copy both the Storage account name and the Key value.

<p class="callout info">**Keep your Storage Account Key secure. Anyone with this key has full access to the storage account. You can rotate it later from the Access Keys page without breaking the integration — just update the key in Elastic too.**</p>

**Part 2 — Configure Entra ID Diagnostic Settings**

Now you will tell Entra ID which log categories to send and point them at the Event Hub you just created.

- In the Azure Portal, go to Microsoft Entra ID from the left sidebar or top search.
- Under Monitoring in the left sidebar, click Diagnostic settings.
- Click + Add diagnostic setting at the top.
- Give it a descriptive name such as: Stream to Elastic via Event Hub.
- Under Logs, check the categories you want to stream:

<div align="left" dir="ltr" id="bkmrk-signinlogs-free-all-"><table><colgroup><col width="213"></col><col width="80"></col><col width="331"></col></colgroup><tbody><tr><td>SignInLogs

</td><td>Free

</td><td>All interactive user sign-ins, MFA results, Conditional Access outcomes

</td></tr><tr><td>AuditLogs

</td><td>Free

</td><td>Directory changes — user creation, group changes, role assignments

</td></tr><tr><td>NonInteractiveUserSignInLogs

</td><td>Free

</td><td>Service and application sign-ins without user interaction

</td></tr><tr><td>UserRiskEvents

</td><td>P2 only

</td><td>Identity Protection risky sign-in detections

</td></tr><tr><td>RiskyUsers

</td><td>P2 only

</td><td>Users flagged as at-risk by Identity Protection

</td></tr></tbody></table>

</div>- Under Destination details, check Stream to an event hub.
- Set Event Hub Namespace to your namespace (entra-elastic-hub).
- Set Event Hub name to your hub (entra-logs).
- Leave Event Hub policy name as the default (RootManageSharedAccessKey).
- Click Save at the top of the page.

<p class="callout info">**Changes to Diagnostic Settings take effect immediately, but it can take 5–15 minutes before the first events begin appearing in the Event Hub — and then another minute or two before Elastic picks them up. This is normal.**</p>

### <span style="color: rgb(53, 152, 219);">**Elastic Fleet Configuration**</span>

With Azure fully configured, the final step is to install the Microsoft Entra ID integration in Kibana and enter the four connection details you collected.

<p class="callout success">To enable log collection from the Microsoft Entra ID, provide the following information to **CyTech Support**:</p>

- Consumer Group
- Connection String
- Storage Account
- Storage Account Key

### <span style="color: rgb(53, 152, 219);">**Conclusion**</span>

With the integration configured, Microsoft Entra ID logs are now streaming continuously into Elasticsearch via Azure Event Hub. Sign-in, Audit, and Identity Protection events will be indexed automatically and available for search, visualization, and alerting in Kibana.

To maintain the integration, ensure the Elastic Agent remains healthy in Fleet and rotate the Storage Account Key and Event Hub connection string in both Azure and the Elastic integration settings as part of your regular credential rotation cycle.

# NG SIEM - Microsoft Entra ID Entity Analytics

### <span style="color: rgb(53, 152, 219);">**Overview**</span>

This guide provides step-by-step instructions for integrating Microsoft Entra ID (formerly Azure Active Directory) Entity Analytics with the Elastic Security platform. By completing this integration, your security team will be able to ingest identity-based risk signals from Entra ID directly into Elastic, enabling enriched detection, investigation, and response workflows.

Entity Analytics in Elastic Security correlates user and host risk scores derived from your identity provider with security events, helping analysts prioritize high-risk entities and reduce alert fatigue.

### <span style="color: rgb(53, 152, 219);">**Prerequisite**</span>

Before beginning the integration, ensure the following requirements are met:

**Microsoft Entra ID Requirements**

- An active Microsoft Azure subscription with Entra ID (Azure AD) configured
- Global Administrator or Privileged Role Administrator permissions in Entra ID
- Microsoft Graph API access enabled for your tenant
- Entra ID Identity Protection license (P2) for risk signal data

### <span style="color: rgb(53, 152, 219);">**Azure App Registration**</span>

Elastic connects to Entra ID via the Microsoft Graph API using an Azure App Registration with appropriate permissions. Follow these steps to configure the application.

**Register a New Application**

- Sign in to the Azure Portal at portal.azure.com with administrative credentials.
- Navigate to Microsoft Entra ID &gt; App registrations.
- Click New registration.
- Provide the following details:

<div align="left" class="align-center" dir="ltr" id="bkmrk-field-value-name-ela"><table class=" align-center"><colgroup><col width="200"></col><col width="424"></col></colgroup><thead><tr><th class="align-left" scope="col">Field

</th><th class="align-left" scope="col">Value

</th></tr></thead><tbody><tr><td class="align-left">Name

</td><td class="align-left">Elastic-EntraID-EntityAnalytics

</td></tr><tr><td class="align-left">Supported account types

</td><td class="align-left">Accounts in this organizational directory only (Single tenant)

</td></tr><tr><td class="align-left">Redirect URI

</td><td class="align-left">Leave blank (not required for this integration)

</td></tr></tbody></table>

</div>- Click Register.

<p class="callout info">Note down the Application (client) ID and Directory (tenant) ID — these will be needed when configuring the Elastic integration.</p>

**Create a Client Secret**

1. - In your new App Registration, navigate to Certificates &amp; secrets &gt; Client secrets.
    - Click New client secret.
    - Set a description (e.g., "Elastic Entity Analytics") and choose an expiry period.
    - Click Add, then immediately copy the Value. This is shown only once.

**Grant API Permissions**

The application requires the following Microsoft Graph API permissions:

<div align="left" class="align-center" dir="ltr" id="bkmrk-user.read.all-applic"><table class=" align-center"><colgroup><col width="233"></col><col width="187"></col><col width="204"></col></colgroup><tbody><tr><td class="align-left">User.Read.All

</td><td class="align-left">Application

</td><td class="align-left">Read all user profiles

</td></tr><tr><td class="align-left">IdentityRiskEvent.Read.All

</td><td class="align-left">Application

</td><td class="align-left">Read identity risk events

</td></tr><tr><td class="align-left">IdentityRiskyUser.Read.All

</td><td class="align-left">Application

</td><td class="align-left">Read risky user data

</td></tr><tr><td class="align-left">AuditLog.Read.All

</td><td class="align-left">Application

</td><td class="align-left">Read audit log data

</td></tr><tr><td class="align-left">Directory.Read.All

</td><td class="align-left">Application

</td><td class="align-left">Read directory data

</td></tr></tbody></table>

</div>- In the App Registration, go to API permissions &gt; Add a permission.
- Select Microsoft Graph &gt; Application permissions.
- Search for and add each permission listed in the table above.
- Click Grant admin consent for \[Your Organization\] and confirm.

<p class="callout info">**Note**: **Admin consent must be granted by a Global Administrator. If you do not have this role, coordinate with your Azure administrator**</p>

### <span style="color: rgb(53, 152, 219);">**Elastic Fleet Configuration**</span>

With the Azure application registered, the next step is to configure Elastic Fleet to deploy the Microsoft Entra ID Entity Analytics integration.

<p class="callout success">To enable log collection from the Microsoft Entra ID, provide the following information to **CyTech Support**:</p>

<div align="left" class="align-center" dir="ltr" id="bkmrk-tenant-id-directory-"><table class=" align-center"><colgroup><col width="213"></col><col width="411"></col></colgroup><tbody><tr><td class="align-left">Tenant ID

</td><td class="align-left">Directory (Tenant) ID from App Registration

</td></tr><tr><td class="align-left">Client ID

</td><td class="align-left">Application (Client) ID from App Registration

</td></tr><tr><td class="align-left">Client Secret

</td><td class="align-left">Secret value created in Section 3.2

</td></tr><tr><td class="align-left">Dataset

</td><td class="align-left">azure.entityanalytics (auto-populated)

</td></tr><tr><td class="align-left">Sync Interval

</td><td class="align-left">Recommended: every 30 minutes (default)

</td></tr><tr><td class="align-left">Enable User Sync

</td><td class="align-left">Toggle ON

</td></tr><tr><td class="align-left">Enable Risk Sync

</td><td class="align-left">Toggle ON (requires P2 license)

</td></tr></tbody></table>

</div>### <span style="color: rgb(53, 152, 219);">**Conclusion**</span>

Integrating Microsoft Entra ID Entity Analytics with Elastic Security gives your team a significant advantage in identifying and responding to identity-based threats. By pulling user risk signals directly from Entra ID into Elastic, you gain a unified view of your security posture without having to switch between platforms.

Once the Elastic Agent is configured with the App Registration credentials, it handles everything automatically — authenticating to Microsoft Graph API, syncing user and risk data on your set interval, and feeding that data into Elastic's Entity Analytics engine. From there, detection rules can alert your team on risky sign-ins, elevated risk levels, and behavioral anomalies in real time.

For Elastic Cloud deployments specifically, the integration works out of the box with no additional network configuration needed. The main things to keep on top of after go-live are tuning your detection rules to fit your environment and rotating the Azure App Registration client secret before it expires to avoid any interruption in data collection.

# NG SIEM Microsoft Exchange Online Message Trace

### <span style="color: rgb(53, 152, 219);">**Overview**</span>

Microsoft Exchange Online Message Trace is a powerful diagnostic and security feature within Microsoft 365 that tracks the flow of email messages through your Exchange Online organization. Integrating Message Trace data into Elastic provides security operations teams with centralized visibility into email traffic, anomaly detection, and compliance monitoring.

This guide covers the end-to-end process of collecting, ingesting, parsing, and analyzing Exchange Online Message Trace data within the Elastic Stack, including configuration of the Microsoft 365 integration via Elastic Agent, index templates, field mappings, dashboards, and alerting

### <span style="color: rgb(53, 152, 219);">**Prerequisite**</span>

Before configuring the integration, ensure the following prerequisites are met:

**Microsoft 365 Requirements**

- An active Microsoft 365 or Office 365 subscription (Business Premium, E3, or E5 recommended)
- An Azure Active Directory (Azure AD) tenant with Global Administrator or Security Administrator privileges
- An Azure AD App Registration with appropriate API permissions
- Exchange Online Plan 1 or Plan 2 license for the service account used

### <span style="color: rgb(53, 152, 219);">**Azure App Registration**</span>

The Microsoft 365 integration authenticates using OAuth2 client credentials. You must create an App Registration in Azure AD and grant it the correct API permissions.

**Creating the App Registration**

- Sign in to the Azure portal at portal.azure.com with Global Administrator credentials.
- Navigate to Azure Active Directory &gt; App registrations &gt; New registration.
- Provide a descriptive name such as Elastic-M365-MessageTrace.
- Set the Supported account type to Accounts in this organizational directory only (Single tenant).
- Leave the Redirect URI blank and click Register.
- Note the Application (client) ID and Directory (tenant) ID from the Overview page.

**Configuring API Permissions**

Navigate to API permissions &gt; Add a permission &gt; Office 365 Management APIs and add the following application permissions:

<div align="left" class="align-center" dir="ltr" id="bkmrk-api-permission-type-"><table class="align-center"><colgroup><col width="200"></col><col width="200"></col><col width="224"></col></colgroup><thead><tr><th scope="col">API

</th><th scope="col">Permission

</th><th scope="col">Type

</th></tr></thead><tbody><tr><td>Office 365 Management APIs

</td><td>ActivityFeed.Read

</td><td>Application

</td></tr><tr><td>Office 365 Management APIs

</td><td>ActivityFeed.ReadDlp

</td><td>Application

</td></tr><tr><td>Microsoft Graph

</td><td>Reports.Read.All

</td><td>Application

</td></tr></tbody></table>

</div>After adding permissions, click Grant admin consent for \[your tenant\] to activate them. The status column should show a green checkmark.

**Creating a Client Secret**

- Navigate to Certificates &amp; secrets &gt; Client secrets &gt; New client secret.
- Set a meaningful description (e.g., Elastic Agent Secret) and an expiry period of 24 months.
- Click Add and immediately copy the secret Value. This value is only shown once.
- Store the secret securely in a secrets management system such as HashiCorp Vault or Elastic Keystore.

### <span style="color: rgb(53, 152, 219);">**Elastic Fleet Configuration**</span>

With the Azure application registered, the next step is to configure Elastic Fleet to deploy the Microsoft Exchange Online Message Trace integration.

Collect Microsoft Exchange Online Message Trace logs from Graph API

<p class="callout success">**To enable log collection from the Microsoft Entra ID, provide the following information to **CyTech Support**:**</p>

- **Collect Microsoft Exchange Online Message Trace logs from Graph API**
    - **Tenant ID**
    - **Client ID**
    - **Client Secret**

- **Collect Microsoft Exchange Online Message Trace logs via file**
    - **Local Domains**
    - **Paths**

### <span style="color: rgb(53, 152, 219);">**Conclusion**</span>

Integrating Microsoft Exchange Online Message Trace into Elastic is straightforward when using the Graph API collection method. The client is only required to complete the Azure AD App Registration, grant the necessary API permissions, and securely share three credentials — Tenant ID, Client ID, and Client Secret — with the Elastic team.

Once those credentials are entered into the Microsoft 365 integration in Kibana, Elastic Cloud handles the rest. Data will begin flowing into the platform within 5 to 30 minutes, and the built-in dashboards provide immediate visibility into email traffic, delivery status, and suspicious activity.

No backend configuration, file paths, or command-line access is required for this setup. The alternative file-based collection method available in the Elastic UI is not applicable here, as logs are pulled directly from Microsoft's Graph API.

The only ongoing maintenance required is coordinating with the client to renew the Client Secret before it expires, typically every 24 months.

# NG SIEM - Microsoft Exchange Server

### <span style="color: rgb(53, 152, 219);">**Overview**</span>

The Microsoft Exchange Server integration for Elastic enables you to monitor Exchange Server installations by collecting and indexing server log data into Elasticsearch. With Kibana, you can visualize, search, and alert on Exchange activity in real time.

This integration is part of the Elastic integrations library and is deployed via Elastic Agent. It is designed for on-premises Exchange Server environments (versions 2013, 2016, and 2019) and supports the following log streams:

- Exchange HTTPProxy Logs
- Exchange IMAP4 / POP3 Logs
- Exchange Message Tracking Logs
- Exchange SMTP Logs (Send/Receive)

### <span style="color: rgb(53, 152, 219);">**Prerequisite**</span>

Before setting up the integration, ensure the following components are in place:

- **Exchange Server Requirements**
    - Microsoft Exchange Server 2013, 2016, or 2019
    - Local or remote access to Exchange log directories
    - Administrative privileges to enable SMTP protocol logging (if required)
    - Windows Server 2012 R2 or later

**Permissions**

The Elastic Agent service account (or the user running Filebeat) must have read access to the Exchange log directories. Default log paths require local administrator or at minimum read access to:

- C:\\Program Files\\Microsoft\\Exchange Server\\V15\\Logging\\
- C:\\Program Files\\Microsoft\\Exchange Server\\V15\\TransportRoles\\Logs\\

**Log Streams and File Paths**

The integration collects the following log streams. Below are the default file paths for Exchange Server V15 (2013/2016/2019):

**Enabling SMTP Protocol Logging**

SMTP Send and Receive logs are not enabled by default on Exchange Server. Follow these steps to enable them using the Exchange Management Shell (EMS).

**Enable SMTP Send Logging (Hub Transport)**

- Open the Exchange Management Shell as Administrator.
- Run the following command to enable protocol logging for the Hub Send connector:

**Set-TransportService -Identity &lt;ServerName&gt; -SendProtocolLogPath "C:\\Program Files\\Microsoft\\Exchange Server\\V15\\TransportRoles\\Logs\\Hub\\ProtocolLog\\SmtpSend" -SendProtocolLogMaxAge 30.00:00:00 -SendProtocolLogMaxDirectorySize 250MB**

- Enable protocol logging on the Send connector: 
    - **Set-SendConnector -Identity "&lt;ConnectorName&gt;" -ProtocolLoggingLevel Verbose**
- Enable SMTP Receive Logging (Frontend Transport)

- Run the following command to enable logging on the Frontend Receive connector: 
    - **Set-ReceiveConnector -Identity "&lt;ServerName&gt;\\&lt;ConnectorName&gt;" -ProtocolLoggingLevel Verbose**

- Verify that the log path is configured: 
    - **Get-TransportService &lt;ServerName&gt; | Select ReceiveProtocolLogPath**

**Verify SMTP Logging is Active**

After enabling, you can verify log files are being written to the configured path. Wait a few minutes for mail flow to generate entries, then check the directory for new .LOG files.

**Enable SMTP Receive Logging (Frontend Transport)**

- Run the following command to enable logging on the Frontend Receive connector: 
    - Set-ReceiveConnector -Identity "&lt;ServerName&gt;\\&lt;ConnectorName&gt;" -ProtocolLoggingLevel Verbose

- Verify that the log path is configured:
    
    
    - Get-TransportService &lt;ServerName&gt; | Select ReceiveProtocolLogPath

**Verify SMTP Logging is Active**

After enabling, you can verify log files are being written to the configured path. Wait a few minutes for mail flow to generate entries, then check the directory for new .LOG files.

<div align="left" dir="ltr" id="bkmrk-log-stream-default-f"><table><colgroup><col width="160"></col><col width="267"></col><col width="197"></col></colgroup><tbody><tr><td>Log Stream

</td><td>Default File Path

</td><td>Notes

</td></tr><tr><td>HTTPProxy

</td><td>...\\Logging\\HttpProxy\\{ECP,OWA,EWS,RPC}\\\*.LOG

</td><td>Enabled by default

</td></tr><tr><td>IMAP4

</td><td>...\\Logging\\Imap4\\\*.LOG

</td><td>Enabled by default

</td></tr><tr><td>POP3

</td><td>...\\Logging\\Pop3\\\*.LOG

</td><td>Enabled by default

</td></tr><tr><td>Message Tracking

</td><td>...\\TransportRoles\\Logs\\MessageTracking\\\*.LOG

</td><td>Enabled by default

</td></tr><tr><td>SMTP Send

</td><td>...\\TransportRoles\\Logs\\Hub\\ProtocolLog\\SmtpSend\\\*.LOG

</td><td>Must be enabled manually

</td></tr><tr><td>SMTP Receive

</td><td>...\\TransportRoles\\Logs\\FrontEnd\\ProtocolLog\\SmtpReceive\\\*.LOG

</td><td>Must be enabled manually

</td></tr></tbody></table>

</div>### <span style="color: rgb(53, 152, 219);">**Elastic Fleet Configuration**</span>

With the Azure application registered, the next step is to configure Elastic Fleet to deploy the Microsoft Exchange Server integration.

<p class="callout success">**To enable log collection from the Microsoft Entra ID, provide the following information to **CyTech Support**:**</p>

**Collect Microsoft Exchange Server Logs from file**

- <span class="euiSwitch__label css-cxzz3-euiSwitch__label" id="bkmrk-exchange-httpproxy-l-2">Exchange HTTPProxy Logs</span>
    - <span class="euiSwitch__label css-cxzz3-euiSwitch__label">Paths: eg: C:\\Program Files\\Microsoft\\Exchange Server\\V15\\Logging\\HttpProxy\\\*\\\*.LOG</span>

<div class="euiFlexGroup css-weekwv-euiFlexGroup-responsive-none-spaceBetween-flexStart-row" id="bkmrk-exchange-server-imap"><div class="euiFlexItem css-kpsrin-euiFlexItem-growZero"><div class="euiSwitch css-v6tkiw-euiSwitch">**<span class="euiSwitch__label css-cxzz3-euiSwitch__label" id="bkmrk-exchange-server-imap-1">Exchange Server IMAP4 POP3 Logs</span>**</div></div></div><div class="euiSpacer euiSpacer--s css-78drzl-euiSpacer-s" id="bkmrk-">  
</div>- Collect Exchange Server IMAP4 POP3 logs 
    - Paths: C:\\Program Files\\Microsoft\\Exchange Server\\V15\\Logging\\Imap4\\IMAP\*.LOG
    - Paths: C:\\Program Files\\Microsoft\\Exchange Server\\V15\\Logging\\Pop3\\POP\*.LOG

<div class="euiFlexGroup css-weekwv-euiFlexGroup-responsive-none-spaceBetween-flexStart-row" id="bkmrk-exchange-messagetrac"><div class="euiFlexItem css-kpsrin-euiFlexItem-growZero"><div class="euiSwitch css-v6tkiw-euiSwitch">**<span class="euiSwitch__label css-cxzz3-euiSwitch__label" id="bkmrk-exchange-messagetrac-1">Exchange Messagetracking Logs</span>**</div></div></div><div class="euiSpacer euiSpacer--s css-78drzl-euiSpacer-s" id="bkmrk--1">  
</div>- Collect Exchange Messagetracking logs 
    - Paths: C:\\Program Files\\Microsoft\\Exchange Server\\V15\\TransportRoles\\Logs\\MessageTracking\\\*.LOG

<div class="euiFlexGroup css-weekwv-euiFlexGroup-responsive-none-spaceBetween-flexStart-row" id="bkmrk-exchange-smtp-logs"><div class="euiFlexItem css-kpsrin-euiFlexItem-growZero"><div class="euiSwitch css-v6tkiw-euiSwitch">**<span class="euiSwitch__label css-cxzz3-euiSwitch__label" id="bkmrk-exchange-smtp-logs-1">Exchange SMTP logs</span>**</div></div></div><div class="euiSpacer euiSpacer--s css-78drzl-euiSpacer-s" id="bkmrk--2">  
</div>- Collect Exchange SMTP logs 
    - Paths: C:\\Program Files\\Microsoft\\Exchange Server\\V15\\TransportRoles\\Logs\\Hub\\ProtocolLog\\SmtpSend\\\*.LOG
    - Paths: C:\\Program Files\\Microsoft\\ExchangeServer\\V15\\TransportRoles\\Logs\\FrontEnd\\ProtocolLog\\SmtpReceive\\\*.LOG

### <span style="color: rgb(53, 152, 219);">**Conclusion**</span>

The Microsoft Exchange Server integration for Elastic is a practical and well-structured solution for organizations that need visibility into their on-premises email infrastructure. By leveraging Elastic Agent to collect and index Exchange log data — covering HTTPProxy, IMAP4/POP3, Message Tracking, and SMTP streams — teams gain centralized observability without having to build custom pipelines from scratch.

The integration's strength lies in its alignment with the Elastic Common Schema (ECS), which makes Exchange logs immediately searchable and compatible with Kibana's pre-built dashboards and alerting tools. This significantly reduces the time-to-value for security and operations teams who need to monitor mail flow, detect anomalies, or audit user activity.

That said, it does require some upfront effort — particularly around enabling SMTP protocol logging manually on the Exchange side and ensuring Elastic Agent has proper file system access. Organizations running non-standard Exchange installations will also need to adjust default file paths accordingly.

Overall, it's a solid community-supported integration that fits well into broader SIEM or observability strategies built on the Elastic Stack. For teams already invested in Elastic, adding Exchange Server monitoring is a natural and low-friction extension of their existing setup.

# NG SIEM Microsoft Graph Activity Logs

### <span style="color: rgb(53, 152, 219);">**Overview**</span>

Microsoft Graph Activity Logs capture API-level interactions with Microsoft Graph — including the identity of the caller, the resources accessed, permissions used, and the outcome. Forwarding these logs to Elastic gives security and operations teams a centralized platform for detection, alerting, and long-term retention.

### <span style="color: rgb(53, 152, 219);">**Prerequisite**</span>

Azure Requirements

- An active Microsoft Azure subscription
- Microsoft Entra ID (Azure AD) tenant with at least one application registered
- Global Administrator or Security Administrator role to configure diagnostic settings
- Azure Event Hub namespace and Event Hub instance (Standard tier recommended)
- A dedicated Azure AD application for Elastic with appropriate API permissions

Required Azure AD Permissions

<div align="left" class="align-center" dir="ltr" id="bkmrk-parameter-descriptio"><table class=" align-center"><thead><tr><th scope="col">Parameter

</th><th scope="col">Description

</th></tr></thead><tbody><tr><td>AuditLog.Read.All

</td><td>Read all audit log data from Microsoft Graph

</td></tr><tr><td>Directory.Read.All

</td><td>Read directory data associated with activity records

</td></tr><tr><td>User.Read.All

</td><td>Resolve user display names and UPNs in enrichment

</td></tr><tr><td>Policy.Read.All

</td><td>Read conditional access and authorization policies

</td></tr></tbody></table>

</div>### <span style="color: rgb(53, 152, 219);">**Azure App Registration**</span>

**Register an Azure AD Application**

- In the Azure Portal, navigate to Microsoft Entra ID &gt; App registrations &gt; New registration.
- Set the name (e.g., elastic-graph-logs-reader) and choose "Accounts in this organizational directory only".
- Click Register. Note the Application (client) ID and Directory (tenant) ID.
- Under Certificates &amp; secrets, create a new client secret. Copy the secret value immediately.
- Under API permissions, add the permissions listed in Section 3.3 above, then grant admin consent.

**Create an Azure Event Hub**

- In the Azure Portal, navigate to Event Hubs &gt; Create.
- Create a namespace (Standard tier) in your preferred region.
- Inside the namespace, create an Event Hub named insights-logs-microsoftgraphactivitylogs.
- Under Shared access policies, create a new policy with Listen permission for Elastic.
- Note the connection string — you will need this in Elastic Fleet.

**Configure Diagnostic Settings in Entra ID**

1. In the Azure Portal, go to Microsoft Entra ID &gt; Diagnostic settings &gt; Add diagnostic setting.
2. Name the setting (e.g., elastic-graph-activity-stream).
3. Under Logs, check MicrosoftGraphActivityLogs.
4. Under Destination, select Stream to an event hub and choose the namespace and Event Hub created above.
5. Click Save. Logs will begin flowing within 5–15 minutes.

<p class="callout info">**Note: The MicrosoftGraphActivityLogs category may appear as a preview feature. Ensure the feature is enabled for your tenant under Entra ID &gt; User settings &gt; Manage what information is shown.**</p>

### <span style="color: rgb(53, 152, 219);">**Elastic Fleet Configuration**</span>

**With the Azure application registered, the next step is to configure Elastic Fleet to deploy the Microsoft Graph Activity Logs integration.**

<p class="callout success">**To enable log collection from the Microsoft Entra ID, provide the following information to **CyTech Support**:**</p>

- **Event Hub Name**
- **Consumer Group**
- **Connection String**
- **Storage Account**
- **Storage Account Key**

### <span style="color: rgb(53, 152, 219);">**Conclusion**</span>

Integrating Microsoft Graph Activity Logs into Elastic gives your security and operations teams a powerful, centralized view of every API interaction occurring across your Microsoft 365 and Entra ID environment. What was previously a siloed audit stream within Azure becomes a first-class signal in your Elastic security ecosystem — queryable, correlatable, and actionable alongside all your other data sources.

By following this guide, you have established a reliable log pipeline from Microsoft Entra ID through Azure Event Hub into Elasticsearch, mapped raw Graph API telemetry to ECS fields for out-of-the-box detection compatibility, and laid the groundwork for long-term retention, compliance reporting, and threat hunting in Kibana.

As Microsoft continues to expand the Graph Activity Logs preview with richer metadata, this pipeline will grow in value without requiring significant re-architecture. The Event Hub ingest pattern is inherently scalable, and Elastic's data stream model ensures index management stays efficient as log volume increases.

Security visibility is only as strong as the signals feeding it. Microsoft Graph Activity Logs are one of the highest-fidelity sources of identity and access telemetry available in the modern enterprise — and with Elastic, you now have the tools to make the most of them.

# NG SIEM - CISCO DUO

### <span style="color: rgb(53, 152, 219);">**Overview**</span>

This guide provides step-by-step instructions for integrating Cisco DUO multi-factor authentication (MFA) with Elastic Fleet for centralized log collection and security monitoring.

Cisco DUO is a cloud-based access security platform that provides multi-factor authentication, device health checks, and zero-trust access policies. Elastic Fleet, part of the Elastic Stack (ELK), provides a centralized management interface for deploying and managing Elastic Agents across your infrastructure.

By integrating DUO authentication logs into Elastic Fleet, security teams gain:

- Real-time visibility into authentication events across all users and devices
- Centralized log aggregation from DUO's Admin API into Elasticsearch
- Pre-built dashboards for authentication analytics and anomaly detection
- Correlation of DUO events with other security telemetry in the Elastic SIEM

### <span style="color: rgb(53, 152, 219);">**Prerequisite**</span>

Before beginning the integration, ensure all of the following prerequisites are met. Incomplete prerequisites are the most common cause of integration failures.

**Cisco DUO Requirements**

- Verify Admin API credentials: 
    - Hostname: exactly the Duo Admin API host (e.g., api-XXXXXXXX.duosecurity.com) as shown in Duo Admin Panel &gt; **Applications** &gt; **Protect an Application** &gt; **Admin API**.
    - Integration key and Secret key: copy/paste fresh to rule out typos.
- Ensure the Admin API application has the required permissions: 
    - “**Grant read information**” and “**Grant read log**” must be enabled for activity logs.
- Duo IP allowlist: 
    - If you have IP whitelisting in Duo, add this egress IP - 50.250.130.122(es-ui.cytechint.io)

<p class="callout success">To enable log collection from the **Cisco DUO**, provide the following information to CyTech Support:</p>

<div align="left" dir="ltr" id="bkmrk-api-hostname-%28e.g.%2C-">- **API Hostname** (e.g., api-XXXXXXXX.duosecurity.com)
- **Integration Key (ikey)**
- **Secret Key (skey)**

</div>### <span style="color: rgb(53, 152, 219);">**Conclusion**</span>

The Cisco DUO integration with Elastic Fleet enables centralized visibility into authentication events across your environment. By leveraging DUO's Admin API alongside Elastic's log collection and SIEM capabilities, security teams can monitor, analyze, and respond to authentication activity in real time — all from a single platform.