Security Information and Event Management (SIEM) solutions help organizations collect, analyze, and correlate security-related logs and events from multiple systems to detect threats, meet compliance requirements, and support incident investigations.
Applications Manager supports forwarding audit and access logs, as well as alarm-generated Syslog messages, to external SIEM platforms using the standard Syslog protocol. This enables centralized visibility into monitoring activities, configuration changes, and security-related events.
Applications Manager supports the following SIEM integration options:

You can configure SIEM integration by navigating to: Settings → Product Settings → Integrations (Add-On Settings) → SIEM.
Use the Custom SIEM option to integrate Applications Manager with SIEM platforms that support Syslog.

Once saved, Applications Manager will start forwarding audit and access logs to the configured SIEM server.
Applications Manager provides native support for Splunk integration using UDP/Syslog.

Note: Ensure network connectivity and firewall rules allow UDP traffic between Applications Manager and the SIEM server.
After configuring the SIEM or Splunk integration, you must create the corresponding action and associate it with monitor attributes. This step enables Applications Manager to send Syslog messages when alarms are triggered.
You can manage the configured SIEM integration from the Integrations (Add-On Settings) page.
These management options help you maintain and adapt the SIEM integration as your monitoring and security requirements evolve.
It allows us to track crucial metrics such as response times, resource utilization, error rates, and transaction performance. The real-time monitoring alerts promptly notify us of any issues or anomalies, enabling us to take immediate action.
Reviewer Role: Research and Development