ManageEngine OpManager
Last updated
Integration Guide for ManageEngine OpManager with BluSapphire SIEM
This guide explains how to configure ManageEngine OpManager to forward network events, audit logs, access logs, and alarms to BluSapphire SIEM in real time using UDP Syslog (RFC 5424).
OpManager version 12.x or later with administrator access.
UDP connectivity from the OpManager server to the BluSapphire DataStreamer.
BluSapphire DataStreamer static private IP address and UDP port (provided by the BluSapphire team).
This configuration enables OpManager to forward audit and access logs to BluSapphire SIEM.
Log in to OpManager using an Administrator account.
Navigate to Settings → General Settings → Integrations → SIEM.
Click Configure.
SIEM Application Name: BluSapphire SIEM
Hostname / IP Address: Enter the BluSapphire DataStreamer static private IP address.
Port Number: Enter the UDP listener port provided by the BluSapphire team.
Note: OpManager forwards logs using UDP Syslog (RFC 5424). Ensure the BluSapphire SIEM listener is configured to accept UDP traffic on the configured port.
Enable Send Access Logs to forward user access activity.
Select the required Audit Modules (for example: Device Management, User Management, Alerts, and Configuration Changes).
Accept the privacy policy and click Save.
Verify that the connector status is displayed as Active.
Issue: Test syslog not received in BluSapphire.
Possible Cause: Firewall blocking UDP traffic on the configured port.
Resolution: Allow UDP traffic from the OpManager server to the BluSapphire DataStreamer on the configured port.
Last updated