Configure Aurora Endpoint Security syslog forwarding

You can configure Aurora Endpoint Security to forward security events to a SIEM solution or syslog server for centralized monitoring.

The forwarded alert data also appears in the Aurora Endpoint Security console de sécurité de point de terminaison. The sign-in URL for your region determines the source IP addresses for the forwarded data. For more information about source IP addresses, see Syslog forwarding source IP addresses.

  1. Sign in to the Aurora Endpoint Security console de sécurité de point de terminaison as an administrator.
  2. Click Settings > Application.
  3. Select the Syslog/SIEM checkbox.
  4. Select the events that you want to send to the SIEM solution or syslog server.
    For more information about the different types of events, see:
  5. Configure the settings for your SIEM solution or syslog server.
    • SIEM — Select the SIEM solution or syslog server.
    • Protocol — Select the protocol. If you select TCP, also select the TLS/SSL checkbox to encrypt the forwarded data in transit. Verify that your SIEM solution or syslog server is configured to listen for messages and supports TLS 1.2 or newer versions.
    • (Optional) Allow messages over 2 KB — Select this option to include the full contents of fields with command line values. This setting is only available for Aurora Focus. If not selected, the filepath in the Instigating Process Command Line field in Aurora Focus detection events is truncated at 120 characters to keep the size of messages under 2 KB.
    • IP/Domain — Enter the FQDN or IP address of the SIEM solution or syslog server.
    • Port — Enter the port number for the SIEM solution or syslog server to listen on for messages. The port number must be between 1 and 65535.
    • Severity — Select the severity level of the messages to forward. This value does not change the messages sent to the SIEM solution or syslog server.
    • Facility — Select the type of application that is logging the message. This value categorizes the messages that the SIEM solution or syslog server receives.
    • (Optional) Custom Token — Enter the custom token that your organizational log management service requires for SIEM or syslog messages.
    • Include tenant identifiers — Select whether to include the tenant ID, name, or both in the syslog messages. This value identifies the source tenant in a multi-tenant environment. By default, this option is disabled.
  6. Click Test Connection to verify that your settings are correct.
  7. Click Save.