johnmath99
7 years agoLevel 3
Forward Audit Logs to SIEM
I have a requiremennt to have audit logs sent to a SIEM (in this case IBM QRadar) which detail the "who", "what" and "when" of admin activities. I know audit details are held in the EMM and can be interogated using audit cmds but how can I either redirect a log version to a SIEM or regularly extract detail into a log format and forward that, presumably by email.
Thanks