Zoho Vault's integration with popular SIEM tools will allow organizations to manage all their Vault audit logs from the SIEM service of their choice. You can create custom alerts and receive instant or periodic notifications based on the configurations available in your SIEM service, to stay informed of all activities in your password manager.
Prerequisite
- Super admin of Zoho Vault
- Valid subscription with the relevant SIEM tools
SIEM integration
Integrating with the SIEM services commonly involve two steps:
- Generating a token
- Identifying the collector hostname
Currently, we offer integration with seven SIEM solutions:
- Loggly
- Logz.io
- Sematext
- Sumo Logic
- Timber
- Microsoft Sentinel
- Datadog
![Notes](https://img.zohostatic.com/zde/static/images/file.png)
Note
- By default, all audits captured in Zoho Vault will be sent to your SIEM service. To filter the audits sent, select Manage Syslog Configurations from SIEM Integrations in Vault.
- We support only the HTTPS protocol at the moment.
- You can send logs only to one service at once.
Integration with Loggly
- Log in to your Loggly account, then select Source Setup from the menu bar.
![](https://desk.zoho.com/DocsDisplay?zgId=4241905&mode=inline&blockId=7u6xe7c21eea5f01244e098c4a91d4ccace07)
- Select Customer Tokens from the submenu.
- A customer token is created by default. Copy this token for later use, or click Add New to use a new token with Zoho Vault.
![](https://desk.zoho.com/DocsDisplay?zgId=4241905&mode=inline&blockId=7u6xe0c6a61dba5a2406ca11f09a1f602bdb0)
- To find out the Collector Hostname, select Source Setup, then click HTTP/S Event Endpoint.
- Logs-01.loggly.com will be the hostname by default. If you've modified it, you can find the current URL from the field highlighted in the screenshot below.
![](https://desk.zoho.com/DocsDisplay?zgId=4241905&mode=inline&blockId=7u6xeaae12cbeeecb4aff872dda1c1c8f8ef9)
Configuring Loggly details in Vault
- Log in to your Zoho Vault account as a super admin, then select Settings.
- Select SIEM Integration, then click Edit configurations under Loggly.
- Enter the Collector Hostname and token details, then click Save Configuration.
![](https://desk.zoho.com/DocsDisplay?zgId=4241905&mode=inline&blockId=7u6xe86cf1ad2a0bd425fbca6a56f28ba5714)
- Click Enable.
Accessing Zoho Vault logs from Loggly
To view all audit logs from Vault in Loggly:
- Log in to your Loggly account.
- Click Search, then search for the logs from Vault based on the time and date of the operation.
![](https://desk.zoho.com/DocsDisplay?zgId=4241905&mode=inline&blockId=7u6xee49a34237eec44cd9e14c832fa5f4ca4)
Integration with Sematext
- Log in to your account, then select Logs.
- Click Create logs app.
![](https://desk.zoho.com/DocsDisplay?zgId=4241905&mode=inline&blockId=7u6xe508eb62e36024fb28434a8afb26763b7)
- Enter the App Name, then click Continue.
![](https://desk.zoho.com/DocsDisplay?zgId=4241905&mode=inline&blockId=7u6xee408081a504f4fbfa4f407080bd4b644)
- Select Actions, then click Integrations.
- Scroll down to the section Where to send logs?.
- Copy the hostname and index (token) details for later use.
![](https://desk.zoho.com/DocsDisplay?zgId=4241905&mode=inline&blockId=7u6xed2710b53e637413bb4e55b69700f5d32)
Configuring Sematext details in Vault
- Log in to your Zoho Vault account as a super admin, then select Settings.
- Select SIEM Integration, then click Settings under SemaText.
- Enter the Collector Hostname and token details, then click Save Configuration.
![](https://desk.zoho.com/DocsDisplay?zgId=4241905&mode=inline&blockId=7u6xe3805c87d539c43ccaf6d2db8ba22ec3f)
- Click Enable.
Accessing Zoho Vault logs from Sematext
To view all audit logs from Vault in Sematext:
- Log in to your Sematext account.
- Select the app you configured under Logs.
![](https://desk.zoho.com/DocsDisplay?zgId=4241905&mode=inline&blockId=7u6xe3685eec06d584114ac18de19021a39d2)
- View the total number of logs generated from Log counts, and details of all the logs generated from Log Events.
- Click Search, then search for the logs from Vault based on the time and date of the operation.
![](https://desk.zoho.com/DocsDisplay?zgId=4241905&mode=inline&blockId=7u6xe3771ebb7fdab4202b46b07c161643f23)
Integration with Sumo Logic
- Log in to your account, then select Manage Data.
- Select Collections, then click Add Collector.
![](https://desk.zoho.com/DocsDisplay?zgId=4241905&mode=inline&blockId=7u6xea7c4cc1a4de04d7b80a5c0bd61d8f408)
- Select Hosted Collector as the Collector Type.
![](https://desk.zoho.com/DocsDisplay?zgId=4241905&mode=inline&blockId=7u6xed33a4e01c4144a1aaa118c3f2948f9bd)
- Enter a Name, then click Save.
- Select Add Source corresponding to the newly created Collector, then select HTTP Logs and Metrics.
- Enter a name for the source, then click Save.
- Copy the URL generated for later use.
- Click OK.
![](https://desk.zoho.com/DocsDisplay?zgId=4241905&mode=inline&blockId=7u6xe330b54afc47a4489a16041282b352ad4)
Configuring Sumo Logic details in Vault
- Log in to your Zoho Vault account as a super admin, then select Settings.
- Select SIEM Integration, then click Settings under Sumo Logic.
- Enter the Collector URL, then click Save Configuration.
![](https://desk.zoho.com/DocsDisplay?zgId=4241905&mode=inline&blockId=7u6xeea1d483c7f4249059f06abb9e1bc3352)
- Click Enable.
Accessing Zoho Vault logs from Sumo Logic
To view all audit logs from Vault in Sumo Logic:
- Log in to your Sumo Logic account.
- Select Manage Data, then click Collections.
- Select Open in Log Search from the newly created source to view the logs from Vault, based on the time and date of the operations.
![](https://desk.zoho.com/DocsDisplay?zgId=4241905&mode=inline&blockId=7u6xe589ddcad5a624e88b2337752562e2c58)
Integration with Logz.io
- Log in to your account, then select Send Your Data from the menu bar.
- Select Libraries, then click Bulk HTTP/S.
Under URL for HTTPS, you’ll find the Collector Hostname. Copy the hostname as shown in the screenshot below.
Note: By default, your hostname will be listener.logz.io. - Under Query string parameters, you’ll find the token details. Copy the token from the description.
![](https://desk.zoho.com/DocsDisplay?zgId=4241905&mode=inline&blockId=7u6xe4c3ddaa559604f96a371743c361c6930)
Configuring Logz.io details in Vault
- Log in to your Zoho Vault account as a super admin, then select Settings.
- Select SIEM Integration, then click Settings under Logz.io.
- Enter the Collector Hostname and token details, then click Save Configuration.
![](https://desk.zoho.com/DocsDisplay?zgId=4241905&mode=inline&blockId=7u6xe78536570ede949878a951b99af648404)
- Click Enable.
Accessing Zoho Vault logs from Logz.io
To view all audit logs from Vault in Logz.io:
- Log in to your Logz.io account.
- Select Kibana to view the logs based on the time and date of the operation.
![](https://desk.zoho.com/DocsDisplay?zgId=4241905&mode=inline&blockId=7u6xe5a7f1a8a6d67471b91a3a9bc46e99f51)
Integration with Timber
- Log in to your account, then select Sources.
- Click Add a New Source, then select Protocols.
![](https://desk.zoho.com/DocsDisplay?zgId=4241905&mode=inline&blockId=7u6xe103ec1dd1f044b0bbe7518ad1c833338)
- Select HTTP API.
![](https://desk.zoho.com/DocsDisplay?zgId=4241905&mode=inline&blockId=7u6xecf8a19dabf5f44ad8aefeabdc9d21bf0)
- Under HTTP API settings, enter a Source Name, then click Next Step.
![](https://desk.zoho.com/DocsDisplay?zgId=4241905&mode=inline&blockId=7u6xe535015975b754fffbc7024d2c6e1ec16)
- Copy the Source ID and API Key (Token) details for later use, then select Next Step.
![](https://desk.zoho.com/DocsDisplay?zgId=4241905&mode=inline&blockId=7u6xeaa342564008f48b39ead6c02705adb25)
Configuring Timber details in Vault
- Log in to your Zoho Vault account as a super admin, then select Settings.
- Select SIEM Integration, then click Settings under Timber.
- Enter the Source ID and token details, then click Save Configuration.
![](https://desk.zoho.com/DocsDisplay?zgId=4241905&mode=inline&blockId=7u6xe6317ba52b08a455eb5d37c81281a7efa)
- Click Enable.
Note: By default, the hostname will be logs.timber.io.
Accessing Zoho Vault logs from Timber
To view all audit logs from Vault in Timber:
- Log in to your Timber account, then select Console.
- Select the source name specified earlier from the dropdown box to view the logs from Vault, based on the time and date of the operation
Integration with Microsoft Sentinel
- Log in to your Microsoft Entra ID portal, then access the Microsoft Sentinel service.
- Select the Sentinel instance to which you want to forward Zoho Vault's Audit trails.
- On the left panel, select Settings under Configurations.
![](https://help.zoho.com/galleryDocuments/edbsn30acf1592e791604556ed886bc19d8e87b8221b5a8093f16d922e5ef005b0afcc20f95e9685279fd67c2d448a366c5e0?inline=true)
- Click Workplace Settings.
![](https://help.zoho.com/galleryDocuments/edbsn5534aaad2aff43b68a6dd52006bca7a638e449f7edd025079391f384568547ff0968b3a1cce9def7ec83f78085bd8919?inline=true)
- From the left panel, select Agent management, then click Log Analytics agent instructions.
- Make a note of the Workspace ID and Primary key details to be configured in Zoho Vault.
![](https://help.zoho.com/galleryDocuments/edbsn2d2f185cfccd2bec0f2d0b446814be9d68fb1c3f790607adfeedb92642f5e734288c496c954c1c69837a722c702f3503?inline=true)
Configuring MS Sentinel details in Vault
Accessing Zoho Vault logs from MS Sentinel
To view all audit logs from Vault in Sentinel:
- Log in to your Microsoft Entra ID portal, then access the Microsoft Sentinel service.
- Select the Sentinel instance from which you want to see Zoho Vault's Audit trails.
![](https://help.zoho.com/galleryDocuments/edbsnea18fa850c130f3cd17c05ab347cd98bf00e711c3b5019a1c268386a4e0c0bb89faa8c516e7c3f48630928309b13d33d?inline=true)
- On the left panel, select Settings under Configurations.
![](https://help.zoho.com/galleryDocuments/edbsne1446c5544170c0ee9cd85513e0e0ab03211aa715362add81f5ed051ff28a8c14caa199152523d41cbe8e79b52d5a9fa?inline=true)
- Click Workplace Settings.
![](https://help.zoho.com/galleryDocuments/edbsnddadcb21ed93d1be3adf432e747ad89b9895f40221eaa8063e2cd45bec2849893329825b19dee8bcb8e45d5c651a850d?inline=true)
- From the left panel, select Logs.
![](https://help.zoho.com/galleryDocuments/edbsn02cb371f894cf310658ea6d8777c4f97cb4e15ba50c55d66b2c121e36d562151d90b09f85a374dc3bc549206ac2dc89a?inline=true)
- Close the Queries menu.
![](https://help.zoho.com/galleryDocuments/edbsn0f57171ac30c086236d1ac86ccedc775211ed4a81eb7a87389c1f00158f93ea737610e88bf7f6e78e9c0674db25aa6e3?inline=true)
- Run this query.
![](https://help.zoho.com/galleryDocuments/edbsne2eb71782ea6fd4c1dd0149c8907ebc1c25f26bbf35a22f64736a30b334ee79a2f9814337321f0e1e926b48a19084d4d?inline=true)
- View Logs from the Results section.
![](https://help.zoho.com/galleryDocuments/edbsnc49b658053b70165c4b58596e7312a74e2e98fdb8eca75ec96939ef40c83ae2e735e1ef254d48419e56ff17b1cc1b096?inline=true)
Integration with Datadog
- Log in to your Datadog account.
- Navigate to the Settings menu in the left sidebar.
Under Organization Settings, select
API Keys.
![](https://help.zoho.com/galleryDocuments/edbsn673135f9c2cc1d5c6c13cc920f570f68c6b13fcb5f46e83481a1628b9bb737907a2968a7188bf960f033f182cca1b4f4?inline=true)
- You’ll see a default API key already created. Copy this key to use later, or, if you prefer, click New Key to generate a new one for Zoho Vault.
![](https://help.zoho.com/galleryDocuments/edbsn58feef470ecf1ffda077c766fe3ec7100d89fe38ce3ef97daa0e4ff04fd7d2ca55b682ddf3145eb02e54e6cc93e853e1?inline=true)
Configuring Datadog details in Vault
- Log in to your Zoho Vault account as a super admin.
![](https://help.zoho.com/galleryDocuments/edbsna24f091a7eb5b75418ebdfd24052372488788c2fb07e2d33cb4c699704ec11039d286599ca9fefd5f5824393c0e8e351?inline=true)
- In the settings menu, select SIEM Integration, then click Edit Configurations under Datadog.
- Enter the Collector Hostname and Token details provided by Datadog, then click Save Configuration.
![](https://help.zoho.com/galleryDocuments/edbsncffa7652f0c22543ca4e94eea947aa9c000b3a0308294193911201e3035f0448559af45034086dbc42fd5c94c5bb61d2?inline=true)
- Click Enable to activate the integration.
- Select the list of audit trails to be sent to your SIEM service from Zoho Vault under Manage Syslog Configuration.
![](https://help.zoho.com/galleryDocuments/edbsnaaaac110430c9c307c44ba1efed5b40232d754a190cc2e4497ff13f837a6743c3656e460138c104b91b6969c65a31ed6?inline=true)
![Notes](https://static.zohocdn.com/zoho-desk-editor/static/images/file.png/)
Enter the domain as the hostname in Zoho Vault for configuration. For example, if the URL is
https://app.datadoghq.com, the hostname should be
datadoghq.com.
Accessing Zoho Vault logs from Datadog
To view all Zoho Vault audit logs in Datadog:
- Log in to your Datadog account.
- In the search bar, use the filter "source:zohovault" to locate Vault logs.
![](https://help.zoho.com/galleryDocuments/edbsnaba57be73ec2276caf4e8348443c283b491d8a10538ead36da65beaba1ba81af458531b55c3d4a931d9715b98dd48077?inline=true)