Important Update: Archer Community Scheduled Maintenance on November 23–24 - New Community Launching Soon! Learn More..

cancel
Showing results for 
Search instead for 
Did you mean: 

Archer integration with Microsoft Sentinel (SIEM)

mykgang1
Contributor III

Hi All,

Our client wants to integration Microsoft Sentinel SIEM solution with Archer. Please let me know if this is possible and how?

Thanks

 

6 REPLIES 6

DavidPetty
Archer Employee
Archer Employee

@mykgang1 it depends on how you can get the data out of Microsoft Sentinel SIEM.  What data export options does it have; APIs, database, file export, etc.?  Depending on the how, you can use a data feed to ingest the data.

 Advisory Consultant

Thanks @DavidPetty . Also, is there any way to export or push Archer (SaaS) logs to Microsoft Sentinel (SIEM)?

Anytime : D

Unfortunately, no.

 Advisory Consultant

@DavidPetty then I think there is only on way to do this by leveraging Archer API. Is my understanding correct?

Without knowing the whole use case, it hard to tell.

If it's Archer to SIEM it would probably be a JS transport data feed.

If it's SIEM to Archer, yes it would be leveraging Archer's APIs.

Alternatively, you could have middleware that talks between the two.

 Advisory Consultant