Configure Multicloud Defense log forwarding profiles to send security events, traffic logs, and gateway metrics to SIEM systems such as AWS S3, Datadog, GCP Logging, Microsoft Sentinel, Splunk, Sumo Logic, Syslog, and Webhooks. Create standalone or group profiles for event, traffic, or metrics logs and associate them with gateways or cloud accounts for comprehensive security monitoring and analysis.
Security Events and Traffic Logs
Learn about security events and traffic logs in Multicloud Defense and how they support investigation and monitoring. Find the available event categories, forwarding destinations, and profile requirements for sending log data to a SIEM.
Discovery Logs
Learn about discovery logs in Multicloud Defense and how they help you review cloud security activity. Find the supported log categories, forwarding destinations, and profile requirements for sending discovery data to a SIEM.
Gateway Metrics Forwarding Profile
Explains the purpose and capabilities of the Gateway Metrics Forwarding Profile.
Add an Event, Traffic Log Forwarding Profile, or Metrics Forward Profile to a Gateway
Associate an event, traffic log forwarding, or metrics forward profile with a Multicloud Defense gateway so the gateway sends its data to the selected destination.
Remove an Event, Traffic Log Forwarding Profile, or Metrics Forward Profile from a Gateway
Remove an event, traffic log forwarding, or metrics forward profile from a gateway when you no longer want the gateway to send data through that profile.