> For the complete documentation index, see [llms.txt](https://docs.blusapphire.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.blusapphire.io/log-forwarding/03_log-forwarding-guide/log-forward/manageengine/manageengine-ad-auditplus.md).

# ManageEngine AD Auditplus

Integration Guide for **ManageEngine AD Auditplus** with **BluSapphire SIEM**

**Prerequisites**

Before starting, confirm the following are in place:

| **Requirement**                              | **Detail**                                                                                          |
| -------------------------------------------- | --------------------------------------------------------------------------------------------------- |
| **ManageEngine AD Auditplus console Access** | Administrator login to the ManageEngine AD Auditplus management console.                            |
| **Network connectivity**                     | UDP port open from AD Auditplus server to BluSapphire DataStreamer                                  |
| **Information needed**                       | BluSapphire DataStreamer’s static private IP and UDP port number (to be shared by BluSapphire team) |

**Forwarding ADAudit Plus data to DataStreamer**

**A. ManageEngine OpManager**

<table data-header-hidden><thead><tr><th width="77.54296875"></th><th></th></tr></thead><tbody><tr><td><strong>1.</strong></td><td>Log in to <strong>ADAudit Plus</strong> with an Administrator account.</td></tr><tr><td><strong>2.</strong></td><td>Click on '<strong>Admin</strong>' Tab → '<strong>SIEM Integration'</strong>.</td></tr><tr><td><strong>3.</strong></td><td>Tick the <strong>'Enable'</strong> checkbox and choose the '<strong>Syslog</strong>' radio button.</td></tr></tbody></table>

**B. Enter BluSapphire SIEM Connection Details**

<table data-header-hidden><thead><tr><th width="85.421875"></th><th></th></tr></thead><tbody><tr><td><strong>1.</strong></td><td>SIEM Application Name — enter: BluSapphire SIEM</td></tr><tr><td><strong>2.</strong></td><td>Hostname / IP Address — enter the BluSapphire DataStreamer’s static private IP.</td></tr><tr><td><strong>3.</strong></td><td>Port Number — enter the UDP listener port shared by BluSapphire team.</td></tr><tr><td><strong>4.</strong></td><td>Choose data format as Syslog standard.</td></tr><tr><td><strong>5.</strong></td><td>Save the configuration</td></tr></tbody></table>

**Troubleshooting**

| **Symptom**                                   | **Likely Cause**                             | **Fix**                                                               |
| --------------------------------------------- | -------------------------------------------- | --------------------------------------------------------------------- |
| Logs not received in BluSapphire DataStreamer | Firewall blocking UDP on the configured port | Open UDP port from ADAudit plus server IP to BluSapphire DataStreamer |
