You can configure Omnissa Access Cloud to automatically forward audit log data such as login events to Security Information and Event Management (SIEM) systems and syslog servers. SIEM systems primarily collect logs and other events from multiple sources to support analysis, compliance and security management. Integrating SIEM systems allows you to improve compliance around data retention and improve operational efficiency with centralized logging.
Omnissa Access includes SIEM adapters for sending Omnissa Access audit events to Splunk, CrowdStrike Falcon Next-Gen SIEM, and syslog servers. You can configure only one SIEM adapter per tenant, and only new audit events will be sent once the adapter is enabled. The SIEM adapters include a retry mechanism for event delivery, attempting up to four times with a 15-minute delay. Historical data will not be sent; only events generated after enabling the feature will be available, with existing APIs available for older data retrieval.
Omnissa Access supports the following SIEM adapters:
- Syslog: Stream audit events to external syslog servers using mutual TLS (mTLS) on port 6514.
- Splunk: Stream audit events to Splunk using an HTTP Event Collector (HEC).
- CrowdStrike Falcon Next-Gen SIEM: Stream audit events to CrowdStrike using an HTTP Event Collector (HEC).
If you configure the syslog adapter and the connection fails, see Troubleshooting TLS Encrypted Message Transfer for common TLS error messages and their resolutions.
Was this page helpful?