Note
- By default, all audits captured in Zoho Vault will be sent to your SIEM service. To filter the audits sent, select Manage Syslog Configurations from SIEM Integrations in Vault.
- We support only the HTTPS protocol at the moment.
- You can send logs only to one service at once.
Integration with Loggly
- Log in to your Loggly account, then select Source Setup from the menu bar.

- Select Customer Tokens from the submenu.
- A customer token is created by default. Copy this token for later use, or click Add New to use a new token with Zoho Vault.

- To find out the Collector Hostname, select Source Setup, then click HTTP/S Event Endpoint.
- Logs-01.loggly.com will be the hostname by default. If you've modified it, you can find the current URL from the field highlighted in the screenshot below.

Configuring Loggly details in Vault
- Log in to your Zoho Vault account as a super admin, then select Settings.
- Select SIEM Integration, then click Edit configurations under Loggly.
- Enter the Collector Hostname and token details, then click Save Configuration.

- Click Enable.
Accessing Zoho Vault logs from Loggly
To view all audit logs from Vault in Loggly:
- Log in to your Loggly account.
- Click Search, then search for the logs from Vault based on the time and date of the operation.

Integration with Sematext
- Log in to your account, then select Logs.
- Click Create logs app.

- Enter the App Name, then click Continue.

- Select Actions, then click Integrations.
- Scroll down to the section Where to send logs?.
- Copy the hostname and index (token) details for later use.

Configuring Sematext details in Vault
- Log in to your Zoho Vault account as a super admin, then select Settings.
- Select SIEM Integration, then click Settings under SemaText.
- Enter the Collector Hostname and token details, then click Save Configuration.

- Click Enable.
Accessing Zoho Vault logs from Sematext
To view all audit logs from Vault in Sematext:
- Log in to your Sematext account.
- Select the app you configured under Logs.

- View the total number of logs generated from Log counts, and details of all the logs generated from Log Events.
- Click Search, then search for the logs from Vault based on the time and date of the operation.

Integration with Sumo Logic
- Log in to your account, then select Manage Data.
- Select Collections, then click Add Collector.

- Select Hosted Collector as the Collector Type.

- Enter a Name, then click Save.
- Select Add Source corresponding to the newly created Collector, then select HTTP Logs and Metrics.
- Enter a name for the source, then click Save.
- Copy the URL generated for later use.
- Click OK.

Configuring Sumo Logic details in Vault
- Log in to your Zoho Vault account as a super admin, then select Settings.
- Select SIEM Integration, then click Settings under Sumo Logic.
- Enter the Collector URL, then click Save Configuration.

- Click Enable.
Accessing Zoho Vault logs from Sumo Logic
To view all audit logs from Vault in Sumo Logic:
- Log in to your Sumo Logic account.
- Select Manage Data, then click Collections.
- Select Open in Log Search from the newly created source to view the logs from Vault, based on the time and date of the operations.

Integration with Logz.io
- Log in to your account, then select Send Your Data from the menu bar.
- Select Libraries, then click Bulk HTTP/S.
Under URL for HTTPS, you’ll find the Collector Hostname. Copy the hostname as shown in the screenshot below.
Note: By default, your hostname will be listener.logz.io.
- Under Query string parameters, you’ll find the token details. Copy the token from the description.

Configuring Logz.io details in Vault
- Log in to your Zoho Vault account as a super admin, then select Settings.
- Select SIEM Integration, then click Settings under Logz.io.
- Enter the Collector Hostname and token details, then click Save Configuration.

- Click Enable.
Accessing Zoho Vault logs from Logz.io
To view all audit logs from Vault in Logz.io:
- Log in to your Logz.io account.
- Select Kibana to view the logs based on the time and date of the operation.

Integration with Timber
- Log in to your account, then select Sources.
- Click Add a New Source, then select Protocols.

- Select HTTP API.

- Under HTTP API settings, enter a Source Name, then click Next Step.

- Copy the Source ID and API Key (Token) details for later use, then select Next Step.

Configuring Timber details in Vault
- Log in to your Zoho Vault account as a super admin, then select Settings.
- Select SIEM Integration, then click Settings under Timber.
- Enter the Source ID and token details, then click Save Configuration.

- Click Enable.
Note: By default, the hostname will be logs.timber.io.
Accessing Zoho Vault logs from Timber
To view all audit logs from Vault in Timber:
- Log in to your Timber account, then select Console.
- Select the source name specified earlier from the dropdown box to view the logs from Vault, based on the time and date of the operation