The SIEM integration allows you to send Poppulo platform events to your organization’s Security Information and Event Management (SIEM) solution for centralized monitoring and analysis.
The integration is provided as a managed integration.
Key capabilities
Send Poppulo platform events to your SIEM
Send available Poppulo platform events to a supported SIEM solution, such as Splunk.
Centralize monitoring
Bring Poppulo platform activity into your existing security monitoring environment alongside events from other applications and systems.
Manage events according to your requirements
Poppulo provides platform events without applying predefined security categories, severity levels, or alerting rules.
Your organization can categorize, filter, and prioritize the events within your SIEM according to your own security, compliance, and monitoring requirements.
Getting started
To use the SIEM integration, contact Poppulo Professional Services.
Poppulo will enable and configure the managed integration for your organization.
As part of the setup process, your organization will need to provide the required integration credentials and configuration details. These allow Poppulo to securely connect the integration and begin sending platform events to your SIEM.
Your Poppulo team will provide guidance on the information required during setup.
How the integration works
Once the integration has been configured, Poppulo platform events are sent to your organization’s SIEM.
Poppulo provides the available event stream. Your organization is responsible for configuring your SIEM to determine how those events should be processed.
This can include:
- Categorizing and filtering events
- Assigning severity or priority
- Configuring alerts
- Creating correlation rules
- Defining reporting and retention requirements
Learn more
For technical information about the SIEM integration and Poppulo platform events, visit the
Poppulo Developer Portal.