SIEM connector integration
- Чтение
- 1 мин.
- Категория
- Proton VPN for Business
With a Proton VPN professional plan, you can stream your organization’s VPN connection metadata and organization audit trails to external SIEM (Security Information and Event Management) platforms for centralized security monitoring and compliance reporting.
SIEM connector integration is available for Proton VPN for Business customers on a VPN Professional, VPN and Pass Professional plan, and Workspace Standard plans.
What you get
With our SIEM connector integration, your organization can receive real-time connection events from activity monitor and Gateway monitor (if enabled). These include:
Activity monitor
- User’s name
- Event type with a timestamp
- The user’s device name and app version
- IP address of the Proton VPN server used (or the user’s real IP address if a VPN isn’t used), and ISP(новое окно) the IP address belongs to.
- The user’s approximate location (based on their IP address).
Gateway monitor
Every time a user connects or disconnects to a Gateway server, or changes the network they’re connecting to your gateway servers from, you’ll see:
- The user’s email address
- The specific server they connected to or disconnected from
- The user’s origin (their actual location and IP address)
- What time the event took place
- The device’s name
This data supports critical enterprise requirements around security monitoring, threat detection, incident response, and regulatory compliance.
Supported endpoints
We support integration with many popular endpoints, including:
- AWS S3
- Azure Blob Storage
- Azure Sentinel
- Custom webhooks
- Elastic SIEM / Elasticsearch
- GCP Cloud Storage
- HTTPS endpoints
- IBM QRadar
- Splunk
- Syslog servers
We also support many endpoints not listed here. Please get in touch for further details.
How to request a SIEM connector
To enable SIEM connector integration for your organization, please contact our Sales or Support(новое окно) teams to discuss your needs.