Arctera™ Insight Management Console Help
- Getting started
- Archive Overview
- Working with Dashboard
- Managing Configurations
- About Provisioning
- About Managed Tags
- About Account Management
- Managing Archive Collectors
- About Exchange Online Archiving
- About Google Chat Archiving
- About Google Workspace Archiving
- About SCIM Archiving
- About Import Collector
- About Insight Capture Services Archiving
- About Audio-Video Archiving
- About Audio-Video Archiving using NTR-X Collectors
- About Dubber Speik SMS Archiving
- About Dubber Speik Recordings Archiving
- About Text-Delimited Archiving
- About XSLT-XML Archiving
- About JSON Archiving
- About iMessage Archiving
- About LinkedIn Archiving
- About Signal Archiving
- About Verint Archiving
- About WeChat Archiving
- About WhatsApp Archiving
- Managing Roles and Permissions
- Managing Policies
- Managing Authentication
- Managing Retention Policies
- Managing Email Continuity Services
- Managing Reports and Notifications
- Classification
- Managing Data Import
- AD FS Configuration Guide
Subscribing to receive SIEM/SOAR Logs
The SIEM/SOAR Logs feature allows customers to retrieve all logs and transfer them to other tools, such as Splunk, for further processing.
To receive SIEM/SOAR Logs, customers need to contact Arctera Support and request enabling the SIEM/SOAR Log shipping service for their environment. Customers must specify which of the following storage options they require:
[Access key, Secret key, Region name, S3 bucket name]
[Blob connection string, container name]
[SFTP server hostname, port, username, password]
This service collects the following details:
Search logs from the Arctera Insight Management Console
Message logs, Activity logs, and Browser logs (including Mobile Browser, Discovery Browser, and Personal Browser) from the Insight eDiscovery portal
The SIEM/SOAR service identifies the collected logs by their name and creation date, and generates a separate CSV file for each log. If the customer has subscribed to this service, these CSV files are securely uploaded to their storage managed by the customer. The service employs the following components:
APIs provided by Amazon/Microsoft Azure/SFTP for uploading the CSV files.
Advanced Encryption Standard (AES-256) for secured data transmission. Each object is encrypted with a unique data key, providing additional protection for the data.
Refer to the following related knowledge base article to see sample SIEM/SOAR sample log reports in CSV format.
Note:
To ensure seamless and secured data transmission, customers are recommended to set up the necessary firewall rules to accomplish secure data upload to their storage of choice