Connect your Security Information and Event Management (SIEM) solution to Miro, and enable real-time monitoring and analysis of activity inside your Enterprise subscription.
Currently available with IBM QRadar and Splunk.
How to set up SIEM
The following procedure explains how to set up SIEM.
Prerequisites
Ensure that you enable SIEM, and generate and copy a Miro SIEM access token.
Follow these steps:
- Go to Admin console.
- Select Enterprise integrations.
- Under Single sign-on, toggle SIEM to the on position.
- For Access Token on the right, select Generate new token.
An access token is generated.
You have successfully enabled SIEM, and generated and copied a Miro SIEM access token.
IBM QRadar
Connect IBM QRadar to Miro Enterprise to monitor activity data from users, network devices, host assets and operating systems, applications, and detect vulnerabilities.
✏️ The Miro app for IBM QRadar uses the Audit Logs API (Miro Developer Platform) to fetch Miro Enterprise audit logs.
Procedure
Follow these steps:
- Download and install the Miro Audit Logs connector for IBM QRadar.
- Install the Universal Cloud REST API protocol.
More information: See Universal Cloud Rest API protocol configuration documentation (external).
- In IBM QRadar, add Miro as a log source. Follow the instructions for Adding a log source to receive events in the IBM QRadar documentation.
You have successfully configured IBM QRadar as your SIEM solution in Miro.
Splunk
Connect Splunk to Miro Enterprise to monitor and visualize user and security activity derived from Miro audit logs.
Procedure
Follow these steps:
- In Splunk, install Miro App for Splunk.
The app is now available on your Splunk dashboard. - On the dashboard, select Miro App for Splunk.
- Under Configuration > Logging, ensure that Log level is set to INFO.
- Under Inputs, select Create new input.
The Add Miro Audit Logs modal opens. - Add metadata for your new input, including the SIEM access token you created in Miro.
- Select Add.
You return to the Inputs tab. - Ensure your new input is Enabled.
You have successfully configured Splunk as your SIEM solution in Miro.
More information:
-
Miro app for Splunk
Learn more about searching and visualization in Splunk. -
Splunk documentation (external)
Learn more about Splunk.