Skip to main content
SIEM export sends a copy of your audit log to your security team’s collector. A SIEM (the tool a security team uses to gather and watch logs from every application) then keeps and analyses these events on your side. SIEM export settings page with the collector, delivery and delivery status sections

What It Does For You

  • Your security team sees Reelevant logins, provisioning, and permission changes next to your other applications.
  • Events reach them about a minute after happening, without anyone exporting anything by hand.
  • Your team keeps the events as long as your own policy requires, beyond the Reelevant retention period.
  • Nothing changes in Reelevant: the audit log stays available as before.
The export only covers your own company. Every event carries a stable identifier and the time it happened, so your team can spot duplicates safely.

Before You Begin

  • You need permission to update company settings in Reelevant.
  • Ask your security team for the collector URL and, if they use one, the secret that authorises Reelevant to send events.
  • Ask them which format they prefer: Reelevant JSON (the events as they appear in the audit log) or Splunk HEC (see Choosing the format).

Enabling The Export

1

Open the SIEM export settings

Go to the account administration section and open SIEM export.Collector section with the Enable SIEM export switch, Collector URL, Format and Authorization header fields
2

Fill in the collector

Enter the Collector URL given by your security team. It must be a public, secure address.Paste the secret in Authorization header if your team gave you one. It is stored encrypted and never shown again.
3

Choose the format and the categories

Pick the Format your security team asked for.Tick the Categories you want to send. Only events in these categories are exported, from the moment you save.
4

Save and check the connection

Switch on Enable SIEM export and click Save.Click Test connection to check Reelevant can reach the collector with your settings. Nothing from the audit log is sent by this test.
5

Send a first batch

Click Send pending events now. The Delivery status shows the last successful delivery, and your security team should see the events arrive.
Ask your security team to confirm they received this first batch. It is the simplest proof that the integration works.

Choosing The Format

Both formats send the same information: the time, the category, the action, the author, what it affected, and whether it succeeded. Passwords and secrets are never included, as in the audit log itself.

Settings

Following Deliveries

The Delivery status section tells you how the export is doing: Delivery status section showing a Healthy badge with the delivered up to and last successful delivery dates Delivery status section showing a Paused badge and the error returned by the collector Once you fix a paused export, deliveries resume exactly where they stopped.

Good To Know

  • Events are sent a minute or so after they happen, once they are final in the audit log.
  • If the collector is unavailable for a while, events wait in Reelevant and are sent later in order. Your security team may see an event twice in rare cases, never lose one.
  • Events wait for as long as your audit log retention period. Fix a paused export before that period passes.
  • Adding a category later sends its events from that moment on. Past events of that category are not sent.
  • Every change to these settings is itself recorded in the audit log.
Do not leave the export paused past your retention period. The oldest waiting events are then removed with the audit log and can no longer be sent.

What’s Next?

Audit log

See exactly which events are exported.

Roles

Control who can change company settings, and therefore this export.

Single sign-on

Understand the login events your security team will see.

Automatic provisioning

Understand the provisioning events your security team will see.