Important Update: Archer Community Scheduled Maintenance on November 23–24 - New Community Launching Soon! Learn More..
2024-09-17 08:47 AM
Hi All,
Our client wants to integration Microsoft Sentinel SIEM solution with Archer. Please let me know if this is possible and how?
Thanks
2024-09-17 09:30 AM
@mykgang1 it depends on how you can get the data out of Microsoft Sentinel SIEM. What data export options does it have; APIs, database, file export, etc.? Depending on the how, you can use a data feed to ingest the data.
Advisory Consultant
2024-09-18 05:50 AM
Thanks @DavidPetty . Also, is there any way to export or push Archer (SaaS) logs to Microsoft Sentinel (SIEM)?
2024-09-18 09:35 AM
Anytime : D
Unfortunately, no.
Advisory Consultant
2024-09-18 10:22 AM
@DavidPetty then I think there is only on way to do this by leveraging Archer API. Is my understanding correct?
2024-09-18 11:30 AM
Without knowing the whole use case, it hard to tell.
If it's Archer to SIEM it would probably be a JS transport data feed.
If it's SIEM to Archer, yes it would be leveraging Archer's APIs.
Alternatively, you could have middleware that talks between the two.
Advisory Consultant