• Overview
  • Configuration

LogRhythm

Automate user provisioning and strengthen security with LogRhythm–ADManager Plus integration.

SIEM Log forwarding

LogRhythm is a leading security information and event management (SIEM) platform that helps organizations detect, respond to, and mitigate cybersecurity threats. By integrating LogRhythm with ManageEngine ADManager Plus, businesses can automate user provisioning in Active Directory (AD) whenever new user records are added to LogRhythm. This integration ensures seamless identity management, enhances security compliance, and reduces manual administrative workload.

 

User lifecycle management

When a new user record is added in LogRhythm, ADManager Plus automatically provisions a corresponding user account in AD. This ensures that security and IT teams have an up-to-date and synchronized user repository, minimizing manual intervention and improving operational efficiency.

 

How to integrate LogRhythm with ADManager Plus

Prerequisites

Please ensure to provide the Bearer token to retrieve desired information and perform tasks in LogRhythm. Refer to LogRhythm API references for more details.

Privileges

To import users (inbound action): Ensure the account used for authorization has permission to read all user accounts.

To perform any action or query in LogRhythm (outbound action): Ensure the account used for authorization has permission to perform the desired action.

Note: ADManager Plus comes with a preconfigured set of APIs that helps perform basic actions with the integration. If the action you require is not available, please gather the necessary API details from the LogRhythm API documentation to configure inbound and outbound webhooks to perform the required actions.

Authorization configuration

  • Log in to ADManager Plus and navigate to the Directory/Application Settings.
  • Select Application Integrations.
  • Under Enterprise Applications, search for and then click LogRhythm.
  • Toggle the Enable LogRhythm Integration button on.
  • In the LogRhythm Configuration page, click Authorization.
  • Perform the steps to generate a Bearer token in LogRhythm and paste the Bearer token in the Value field.
  • Click Configure.

Inbound webhook configuration

Inbound webhook enables you to fetch user data from LogRhythm to ADManager Plus. The attribute mapping configured in this section can be selected as the data source during automation configuration. To configure an inbound webhook for LogRhythm:

  • The endpoint URL will be pre-configured. However, if you would like to use a new endpoint to import users, you can configure one using the + Add API endpoint button and filling in the required fields as per LogRhythm's API references. Click here to learn how.
  • Note:

    • The API key-value pair is preconfigured as a header for authenticating API requests as configured during Authorization Configuration.
    • Macros: You can add macros to your endpoint configuration to dynamically change it as per your requirement using the macro chooser component.
    • Refer to LogRhythm's API references and configure additional headers and parameters, if required.
  • Once done, click Test & Save. A response window will display all the requested parameters that can be fetched using the API call. After verifying whether the requested parameters have been called to action, click Proceed.
  • Note:

    • Refer to LogRhythm's API references to see which parameters must be configured to fetch only specific parameters.
    • You can configure multiple endpoints for LogRhythm using the + Add API endpoint button. Click here to learn how.
  • Click Data Source - LDAP Attribute Mapping to match endpoints and to map AD LDAP attributes with the respective attributes in LogRhythm.
  • Click + Add New Configuration and perform the following:
    • Enter the Configuration Name and Description and select the Automation Category from the drop-down menu.
    • In the Select Endpoint field, select the desired endpoint and a Primary Key that is unique to a user (e.g. employeeIdentifier).
    • Note: When multiple endpoints are configured, this attribute must hold the same value in all the endpoints.
    • In the Attribute Mapping field, select the attribute from the LDAP Attribute Name drop-down menu and map it with the respective attribute in LogRhythm.
    • If you would like to create a new custom format for this, click Add New Format.
    • Click Save.

Outbound webhook configuration

Outbound webhooks enable you to send changes made in AD to LogRhythm and carry out tasks in LogRhythm—all from ADManager Plus. The webhooks configured in this section can be included in orchestration templates, which in turn can be used during event-driven and scheduled automations. They can also be applied directly to desired users to perform a sequence of actions on them (Management > Advanced Management > Orchestration). To configure outbound webhooks for LogRhythm:

  • Under Outbound Webhook, click LogRhythm Webhook Configuration.
  • Click + Add Webhook.
  • Enter a name and description for this webhook.
  • Decide on the action that has to be performed and refer to LogRhythm's API documentation for the API details, such as the URL, headers, parameters, and other requirements that will be needed.
  • Select the HTTP method that will enable you to perform the desired action on the endpoint from the drop-down menu.
  • Enter the endpoint URL.
  • Configure the Headers, Parameters, and Message Type in the appropriate format based on the API call that you would like to perform.
  • Click Test and Save.
  • A pop-up window will then display a list of AD users and groups to test the configured API call. Select the desired user or group over which this API request has to be tested and click OK. This will make a real-time call to the endpoint URL, and the selected objects will be modified as per the configuration.
  • The webhook response and request details will then be displayed. Verify them for the expected API behavior and click Save.