SIEM Exporter

by NinjaOne

Category

Use Case

Expedite threat handling by exporting endpoint events from NinjaOne to an external SIEM ​ 

NinjaOne SIEM Exporter

Overview

The SIEM Exporter App in NinjaOne configures webhooks for specific events like device alerts, policy conditions, or integration-specific notifications. The app separates SIEM alerts from the notifications channel, reducing noise in the notifications channel.

The app also introduces role-based access to webhooks, ensuring that technicians have appropriate read/write rights. Any SIEM that can receive, validate, and process automated HTTP messages sent by another application when a specific event occurs via webhooks works with this application. The webhook is monitored to ensure the webhook transaction succeeds. 

Features

Automate HEC setup

Replaces manual API calls with a guided user interface for the HTTP Event Collector (HEC) setup.

Utilize webhooks

Create a webhook connection to send activity data to your SIEM tool. Enter the webhook destination URL provided by your SIEM or integration vendor.

View webhook status

Hover over webhook error notifications to view the causes and options for remediation.

Fortify RBAC

Decouple SIEM streams from generic notification Channels to apply stricter Role-Based Access Control (RBAC). Apply full permissions or read-only access.

Configure SIEM activities

Activities for the SIEM Exporter allow technician notification, update notification channels, or create tickets for certain events.

Why integrate NinjaOne with your SIEM?

  • Easily and securely transfer endpoint log and event data
  • Enhance RBAC for webhooks
  • Identify problem webhook transactions