13.3 How to setup SIEM

  1. Enable SIEM on Filr Admin Console. See SIEM Integration in Filr 4.3: Administrative UI Reference

  2. Ensure that Kafka and Zookeeper services are running. To do this, go to Admin Console > System > SIEM and click Check Services button.

  3. Setup the SIEM Solution or use an existing SIEM solution.

  4. Install the connector provided by your SIEM solution that can consume CEF events from Kafka or the database.