ManageEngine AD Auditplus
Integration Guide for ManageEngine AD Auditplus with BluSapphire SIEM
Prerequisites
Before starting, confirm the following are in place:
Requirement
Detail
ManageEngine AD Auditplus console Access
Administrator login to the ManageEngine AD Auditplus management console.
Network connectivity
UDP port open from AD Auditplus server to BluSapphire DataStreamer
Information needed
BluSapphire DataStreamer’s static private IP and UDP port number (to be shared by BluSapphire team)
Forwarding ADAudit Plus data to DataStreamer
A. ManageEngine OpManager
1.
Log in to ADAudit Plus with an Administrator account.
2.
Click on 'Admin' Tab → 'SIEM Integration'.
3.
Tick the 'Enable' checkbox and choose the 'Syslog' radio button.
B. Enter BluSapphire SIEM Connection Details
1.
SIEM Application Name — enter: BluSapphire SIEM
2.
Hostname / IP Address — enter the BluSapphire DataStreamer’s static private IP.
3.
Port Number — enter the UDP listener port shared by BluSapphire team.
4.
Choose data format as Syslog standard.
5.
Save the configuration
Troubleshooting
Symptom
Likely Cause
Fix
Logs not received in BluSapphire DataStreamer
Firewall blocking UDP on the configured port
Open UDP port from ADAudit plus server IP to BluSapphire DataStreamer
Last updated