How to integrate AUTOMY security events with your SIEM
Knowledge Center — Security & Privacy
By Carlos J Quintero ·
AUTOMY’s SIEM integration sends security events from product operations to an external platform for search, correlation, and retention.
This guide explains how to choose which events to receive and how to connect a destination in SIEM settings.
Subscriptions and destinations A subscription selects events by scope and, when needed, categories.
A destination determines where events are sent and which connector is used.
A subscription can have one or more destinations.
On the SIEM screen, first create a subscription with a name and scope.
Choose the company to include events across the company and its environments, or select a specific environment to limit the subscription to that environment. note The environment context shown in an event does not change its scope.
For example, an authentication event may mention Production in its context and still be global; a subscription limited to Production will not receive it.
Choose which events to receive Turn on All events to receive every available category, including categories added in the future.
To narrow the subscription, turn it off and select one or more categories.
Administration: administration, policy, and resource activity.
Users: user activity, excluding role events.