SecOps

SIEM Integration

CoreLink forwards audit events to external SIEM platforms using syslog (RFC 5424) and CEF (Common Event Format). Supported output modes: UDP syslog, TCP syslog with TLS, and HTTP webhook. Multiple endpoints can be configured simultaneously with independent format settings.

Events are tagged with facility and severity per RFC 5424 and include the full CoreLink audit payload as structured data. Tested integrations: Splunk (HEC + syslog), IBM QRadar (syslog CEF), Microsoft Sentinel (HTTP Data Connector).

SIEM Integration screenshot

Key Configuration

  • Output mode (UDP / TCP-TLS / webhook)
  • Endpoint hostname and port
  • Format (syslog / CEF / JSON)
  • Authentication token (for webhook / HEC)
  • Event filter by action type
  • Batch size and flush interval
All documentation Question about this? Talk to us