How to Integrate NinjaOne with a SIEM
In this episode of NinjaOne01, Jeff Hunter, Field CTO at NinjaOne, walks through NinjaOne’s new SIEM Exporter App. The app is a dedicated place to set up and monitor the webhooks that send NinjaOne activity data to your third-party SIEM (Security Information & Event Management) system. Note: this is an early access feature, so contact your account manager to have it enabled for your account.
What this video covers:
Enabling the SIEM Exporter app under Administration → Apps → Third-party apps
Creating a webhook, naming the connection, and choosing which NinjaOne event types to send to cut down on noise
Setting the destination URL, typically an HTTP collector in your SIEM (webhook.site is used in the demo for testing)
Choosing organization access: all organizations or a select group, which lets MSPs send only a particular client’s activities
Adding request headers, including when to use generic headers (non-sensitive metadata) versus secure headers (secrets and authentication tokens, such as the Authorization header most major SIEM vendors require)
Testing the connection and verifying that the webhook and its headers arrived at the destination
Using the new “Configure SIEM Exporter” system role permission. Technicians without it keep read-only access to the app
Tracking new system activities for SIEM webhook creation, deletion, disabling, dispatch failures, and updates
Key takeaway: Once configured, the SIEM Exporter app streams NinjaOne activity data to your SIEM and gives you visibility into the health of each webhook, with secure header handling and permission controls built in.
Documentation: https://see.ninjaone.com/utjAZ
Blog: https://see.ninjaone.com/utjBj
Chapter Markers
00:00 - Intro
00:36 - Set Up
03:08- Permissions and Notifications