---
title: "Configure SIEM integration"
canonical: "https://docs.aryaka.com/space/KNOW/289505287/Configure%20SIEM%20integration"
format: markdown
---
The SIEM configuration page (located at Global Settings > SIEM) allows you to configure the real-time export of logs generated from various modules available in the data path across all Aryaka-connected sites to an external SIEM tool. Many organizations use SIEM as the centralized, real-time, security tracking component for their response team at their security operations center (SOC). There are four types of logs that you can export currently from MyAryaka to a SIEM tool: Security logs—Generated by Aryaka’s Pre-SSL and Post-SSL engines within the SASE stack. These logs are structured using the Open Cybersecurity Schema Framework (OCSF) in JSON to ensure standardized and seamless data exchange between MyAryaka and any OCSF-compatible security tools. While the OCSF framework provides a broad set of schemas tailored for different types of security telemetry, Aryaka has adopted the  Network Activity  schema to represent both Pre-SSL and Post-SSL logs. This schema was selected to align with the nature of traffic insights captured at these processing stages. These logs are generated only at the close of the connection or request (in case the traffic is HTTP). For a comprehensive breakdown of supported attributes, refer to the  Security log attributes for SIEM integration  topic. IPS Logs—Use the Suricata Event Log format in JSON to export Aryaka Intrusion Prevention System (IPS) logs. IPS is included in your Aryaka Unified SASE subscription. Note that these logs are also commonly known as Suricata logs and IDPS event logs. Flow Logs—Generated in a custom, Aryaka-specific JSON format, these logs capture connection activity at multiple stages: At the start and end of a connection in its Pre-SSL state. At one-minute intervals during the connection lifecycle, reporting differential Tx/Rx bytes on the connection. Flow logs are available by default and can be optionally enabled if required. For a comprehensive breakdown of supported attributes, refer to the  Flow log attributes for SIEM integration  topic. Private Access Logs—Generated in a custom, Aryaka-specific JSON format, these logs capture critical user events such as: Successful user connect and disconnect events. Login failures caused by incorrect credentials (for example, password mismatch) or IP pool exhaustion during VPN private IP allocation to the client. These logs help provide visibility into user access activity and connection issues within the Aryaka Private Access service. For a comprehensive breakdown of supported attributes, refer to the  Private Access log attributes for SIEM integration  topic. To export security log content to a SIEM tool If it is not already open, navigate to the SIEM page: Log into MyAryaka. The Home page appears. Click  Global Settings  in the left navigation pane. The Global Settings page appears and displays a series of tiles. Click  Manage  in the SIEM tile. The SIEM page appears. Click  Add SIEM Configuration . The Add SIEM Configuration page appears with the Status field set to Draft (New). Configure the following fields in the SIEM Details pane: Enter a name and description of this connection in the corresponding fields. Currently, the Vendor functionality defaults to Generic and cannot be edited. Configure the following fields in the Connectivity Details pane: Click the  SIEM Log Transport Method  drop-down list and select one of the following options: Network Port HTTP (Conditional) If you selected  Network Port  as your transport method, do the following: Enter the SIEM endpoint IP address or the domain name for the SIEM connection to use, for example: 179.17.27.89 or siem-endpoint.aryaka.com. Click the Protocol drop-down list and select one of the following options: TCP UDP Enter the listening port for this connection in the Port Number field. (Conditional) If you selected  HTTPS  as your transport method, do the following: Enter the URL for the HTTPS POST request. For example: https://collectors.sumologic.com/receiver/v1/http/ZdVdC4dhaV39Tn19 Note: Aryaka assumes the port number is 443 if not specified. If there is a custom port number, add it to the domain name in the URL, for example, if you are using port 8080: https://collectors.sumologic.com:8080/receiver/v1/http/ZdVdC4dhaV39Tn19 Transport Layer Security (TLS) is enabled on the transport regardless of what is specified in the URL. It is recommended that you specify HTTPS in the URL for consistency. Click the  Authentication Type  drop-down list and select whether you want to use basic authentication or an authentication header.  If you select  Basic Authentication , enter a username and password in the fields that appear. If you select  Authentication Header , enter a header and header value in the fields that appear. (Optional) In the Log Types pane, click the following toggles: Security Logs—Sends security logs from your Aryaka service. Logs include insights from SASE and Non-SASE security engines. IPS Event Logs—Send IPS logs from your Aryaka Unified SASE service.  Note:  this toggle is only displayed if you have the Aryaka Unified SASE service. Flow Logs—Send logs from your SD-WAN service. Logs contain basic connection details and traffic statistics. These logs do not contain any security engine related details. Private Access Logs—Send logs from your Private Access service.  Note:  this toggle is only displayed if you have at least one Private Access region enabled.  Click  Submit . A message warns that you cannot edit the SIEM configuration until after the Aryaka support team completes the configuration. Click  OK . A message confirms the request was submitted and the Status field is set to Provisioning. When the change request is complete, the SIEM page (at Config > Security > SIEM) displays a tile with the SIEM name, the vendor type (Generic), and the status of Configured. To edit or delete a SIEM configuration If it is not already open, navigate to the SIEM page: Log into MyAryaka. The Home page appears. Click  Global Settings  in the left navigation pane. The Global Settings page appears and displays a series of tiles. Click  Manage  in the SIEM tile. The SIEM page appears and displays a tile for each SIEM connection that is currently configured. Click the tile for the SIEM configuration you want to edit. The  <SIEM_name>  page appears. Do one of the following: Click the  Edit  icon to enter edit mode, edit one or more of the fields, and then click  Submit . Click the  Delete  icon. The SIEM configuration is deleted. Related topics SIEM Flow log attributes for SIEM integration Security log attributes for SIEM integration Private Access log attributes for SIEM integration Integrate with Sophos View security logs