SIEM Exporter
by NinjaOne
Use Case

The SIEM Exporter App in NinjaOne configures webhooks for specific events like device alerts, policy conditions, or integration-specific notifications. The app separates SIEM alerts from the notifications channel, reducing noise in the notifications channel.
The app also introduces role-based access to webhooks, ensuring that technicians have appropriate read/write rights. Any SIEM that can receive, validate, and process automated HTTP messages sent by another application when a specific event occurs via webhooks works with this application. The webhook is monitored to ensure the webhook transaction succeeds.
Replaces manual API calls with a guided user interface for the HTTP Event Collector (HEC) setup.
Create a webhook connection to send activity data to your SIEM tool. Enter the webhook destination URL provided by your SIEM or integration vendor.
Hover over webhook error notifications to view the causes and options for remediation.
Decouple SIEM streams from generic notification Channels to apply stricter Role-Based Access Control (RBAC). Apply full permissions or read-only access.
Activities for the SIEM Exporter allow technician notification, update notification channels, or create tickets for certain events.
You might also like