For the complete documentation index, see llms.txt. This page is also available as Markdown.

ManageEngine OpManager

Integration Guide for ManageEngine OpManager with BluSapphire SIEM

Overview

This guide explains how to configure ManageEngine OpManager to forward network events, audit logs, access logs, and alarms to BluSapphire SIEM in real time using UDP Syslog (RFC 5424).

Prerequisites

  • OpManager version 12.x or later with administrator access.

  • UDP connectivity from the OpManager server to the BluSapphire DataStreamer.

  • BluSapphire DataStreamer static private IP address and UDP port (provided by the BluSapphire team).

Configuration steps

This configuration enables OpManager to forward audit and access logs to BluSapphire SIEM.

Step 1 – Open the SIEM Integration Settings

  1. Log in to OpManager using an Administrator account.

  2. Navigate to Settings → General Settings → Integrations → SIEM.

  3. Click Configure.

Step 2 – Enter BluSapphire SIEM Connection Details

  1. SIEM Application Name: BluSapphire SIEM

  2. Hostname / IP Address: Enter the BluSapphire DataStreamer static private IP address.

  3. Port Number: Enter the UDP listener port provided by the BluSapphire team.

Note: OpManager forwards logs using UDP Syslog (RFC 5424). Ensure the BluSapphire SIEM listener is configured to accept UDP traffic on the configured port.

Step 3 – Select Log Types and Save

  1. Enable Send Access Logs to forward user access activity.

  2. Select the required Audit Modules (for example: Device Management, User Management, Alerts, and Configuration Changes).

  3. Accept the privacy policy and click Save.

  4. Verify that the connector status is displayed as Active.

Troubleshooting

  • Issue: Test syslog not received in BluSapphire.

  • Possible Cause: Firewall blocking UDP traffic on the configured port.

  • Resolution: Allow UDP traffic from the OpManager server to the BluSapphire DataStreamer on the configured port.

Last updated