Connect your Security Information and Event Management (SIEM) solution to Miro, and enable real-time monitoring and analysis of activity inside your Enterprise subscription.
Miro currently supports IBM QRadar and Splunk.
How to set up SIEM
The following procedure explains how to set up SIEM.
Prerequisites
Ensure that you enable SIEM, then generate and copy a Miro SIEM access token:
- In Admin console, go to Apps and integrations > Enterprise integrations.
- Toggle SIEM to the on position.
- For Access Token, click Generate new token.
An access token is generated. - Copy the SIEM access token.
IBM QRadar
Connect IBM QRadar to Miro Enterprise to monitor activity data from users, network devices, host assets and operating systems, applications, and detect vulnerabilities.
- Download and install the Miro Audit Logs connector for IBM QRadar.
- Install the Universal Cloud REST API protocol.
More information: See Universal Cloud Rest API protocol configuration documentation (external). - In IBM QRadar, add Miro as a log source. Follow the instructions for Adding a log source to receive events in the IBM QRadar documentation.
✏️ The Miro app for IBM QRadar uses the Audit Logs API (Miro Developer Platform) to fetch Miro Enterprise audit logs.
Splunk
Connect Splunk to Miro Enterprise to monitor and visualize user and security activity derived from Miro audit logs.
- In Splunk, install Miro App for Splunk.
The app is now available on your Splunk dashboard. - On the dashboard, select Miro App for Splunk.
- Under Configuration > Logging, ensure that Log level is set to INFO.
- Under Inputs, select Create new input.
The Add Miro Audit Logs modal opens. - Add metadata for your new input, including the SIEM access token you created in Miro.
- Select Add.
You return to the Inputs tab. - Ensure your new input is Enabled.
More information:
-
Miro app for Splunk
Learn more about searching and visualization in Splunk. -
Splunk documentation (external)
Learn more about Splunk.
Next: Conclusion
You have completed your Miro Enterprise configuration. For more information, see Ready for takeoff.