Skip to content

Reports, notifications and event delivery to SIEM

The appliance does not try to replace your security operations centre. It delivers events where they are already collected, and writes directly to whoever is on duty today.

default syslog port
514default syslog port
report formats
3report formats
minimum notification interval
5 minminimum notification interval
Administration · Export settings
Настройка экспорта событий в SIEM: конфигурации выгрузки по syslog и JSON с адресом и портом сервера сбора
Export configurations: format, module list, collector address and port, connection state. There can be several configurations, each with its own set of modules.

How it works

To deliver events to a collection system you create an export configuration: syslog or JSON format, a list of modules, and the address and port of the receiver. The connection state is visible right in the table, so a broken channel does not go unnoticed.

Operation with Wazuh is documented and verified in practice. For MaxPatrol SIEM the collection is configured on the SIEM side through its own collector, which pulls data from the appliance over HTTP in JSON format.

Direct delivery works in parallel. The appliance sends notifications to email and to a Telegram chat, and it is configured not as all or nothing but per specific event type of every module: critical network activity alerts, new hosts, high severity Wi-Fi threats and so on.

What goes where

Delivery channels
  • syslog to a collector, port 514 by default
  • JSON to a collector, verified with Wazuh
  • Collection by MaxPatrol SIEM over HTTP
  • Email over SMTP, SMTP TLS or IMAP
  • Messages to a Telegram chat through a bot
Report formats
  • HTML for quick review and forwarding
  • XLSX for analysis and pivot tables
  • JSON for loading into other systems
  • PCAP for handing raw traffic to an engineer
Analysis · Events from all modules
Модуль «Анализ»: события всех модулей комплекса за последние сутки на одном экране со счётчиками непрочитанных
If there is no security operations centre, the Analysis module fills that role: events from every module over the last 24 hours on one screen.
Administration · Notification settings
Настройка уведомлений по электронной почте и в Telegram с периодичностью отправки
Email and Telegram are configured separately, with a choice of delivery interval and a connection state indicator.

Per module notification settings

Network activity

Critical events, warnings, notices and other are enabled separately. Usually only critical ones go to the duty officer.

Network monitor

New host found, port change, connection to a host lost.

Wi-Fi and vulnerability scanner

Separately by level: high, medium, low. The vulnerability scanner adds informational records.

Infrastructure integrity and honeypot

Errors, warnings and notices of integrity control, events from both decoys.

We will prepare a quote for your network

Tell us about your infrastructure: how many sites, which switch sits in the core, whether you already run a SIEM. We will pick the edition and the connection scheme, and calculate the cost.

  • We reply within one business day
  • We design the connection scheme for your topology
  • We show the interface on a live demo unit

Request a quote

Leave a phone number or an email so we can reply.

By submitting this form you agree to our privacy policy.