Advanced Search
Search Results
215 total results found
Google Workspace Integrations
Introduction Google Workspace (formerly G Suite) is a suite of cloud computing, productivity and collaboration tools, software and products developed and marketed by Google. It allows users to create, edit, and share documents, spreadsheets, presentations, a...
Jumpcloud Integrations
Introduction The JumpCloud integration allows you to monitor events related to the JumpCloud Directory as a Service via the Directory Insights API. You can find out more about JumpCloud and JumpCloud Directory Insights here https://jumpcloud.com/...
Mimecast Integrations
Introduction The Mimecast integration collects events from the Mimecast API. Assumptions The procedures described in Section 3 assumes that a Log Collector has already been setup. Requirements Configuration Authorization parameter...
MongoDB Integrations
Introduction This integration is used to fetch logs and metrics from MongoDB. Assumptions The procedures described in Section 3 assumes that a Log Collector has already been setup. Compatibility The log dataset is tested with logs from vers...
OKTA Integrations
Introduction The Okta integration collects events from the Okta API, specifically reading from the Okta System Log API. Logs System The Okta System Log records system events related to your organization in order to provide an audit trail that can be us...
VMware vSphere Integration
This integration periodically fetches logs and metrics from vSphere vCenter servers. Compatibility The integration uses the Govmomi library to collect metrics and logs from any Vmware SDK URL (ESXi/VCenter). This library is built for and tested against ESXi...
Pulse Connect Secure Integrations
Introduction This integration is for Pulse Connect Secure. https://www.ivanti.com/products/ivanti-neurons-zero-trust-access?psredirect Pulse Connect Secure Integration Procedures Please provide the following information to CyTech: C...
Slack Integrations
Introduction Slack is used by numerous organizations as their primary chat and collaboration tool. Please note the Audit Logs API is only available to Slack workspaces on an Enterprise Grid plan. These API methods will not work for workspaces on a Free, St...
System Integrations
Introduction The System integration allows you to monitor servers, personal computers, and more. Use the System integration to collect metrics and logs from your machines. Then visualize that data in Kibana, create alerts to notify you if something goes wr...
Team Viewer Integrations
Remote File Copy via TeamViewer Identifies an executable or script file remotely downloaded via a TeamViewer transfer session. Rule type: eql Rule indices: winlogbeat-* logs-endpoint.events.* logs-windows.* Severity:...
Z Scaler Integrations
Introduction This integration is for Zscaler Internet Access logs. It can be used to receive logs sent by NSS log server on respective TCP ports. The log message is expected to be in JSON format. The data is mapped to ECS fields where applicable and the re...
FAQ: What do I do if I have Cortex XDR which causes unsuccessful installation of the Log Collector?
Elastic Agent Main installation path (windows) When installing Elastic Agent on a Windows machine, the installation files are placed in specific directories. Below are the important paths to know for managing and troubleshooting the Elastic Agent. Temporaril...
SentinelOne Integrations
The SentinelOne integration collects and parses data from SentinelOne REST APIs. This integration also offers the capability to perform response actions on SentinelOne hosts directly through the Elastic Security interface Compatibility This module has been ...
How to Whitelist by IP Address in Office 365 and by Domain in Microsoft Defender for Office 365 Portal - OLD
Why Whitelist in Office 365? Whitelisting ensures the CyTech phishing simulation (PS) functions without issue and prevents PS emails from being automatically moved to the spam folder or notifying users about potential phishing emails. The Connection Filter Po...
Custom Windows Event Logs - Integration
Custom Windows Event Logs Collect and parse logs from any Windows event log channel with Elastic Agent. The custom Windows event log package allows you to ingest events from any Windows event log channel. You can get a list of available event log channels by...
Windows Event Forwarding to Linux server using Nxlog
Introduction Windows Event Forwarding (WEF) allows the collection of event logs from multiple Windows machines and their forwarding to a centralized server. Using Nxlog, you can send these logs to a Linux server for storage and analysis. This documentation pr...
Windows Event Forwarding to Linux server using Powershell script
Overview This PowerShell script forwards Windows event logs to a Linux server using the syslog protocol. It captures specific event logs, sends them to the specified syslog server, and ensures that duplicate events are not sent. Prerequisites PowerShell o...
Sophos Integration
Overview The Sophos Central integration allows you to monitor Alerts and Events logs. Sophos Central is a cloud-native application with high availability. It is a cybersecurity management platform hosted on public cloud platforms. Each Sophos Central account ...
Log Collector Installation Old - Windows
Log Collector Installation in CISO Workplace This guide provides step-by-step instructions for installing the Elastic Agent as a log collector in the CISO Workplace environment. By following these steps, you’ll set up a secure, automated method for gathering ...
Atlassian Bitbucket Integrations (New)
Introduction The Bitbucket integration collects audit logs from the audit log files or the audit API. Reference: https://developer.atlassian.com/server/bitbucket/reference/rest-api/ Assumptions The procedures described in Section 3 assume that a Log ...