> For the complete documentation index, see [llms.txt](https://learn.netmaker.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://learn.netmaker.io/features/telemetry-and-logging/activity/siem-integration.md).

# SIEM Integration

Netmaker can stream audit and network activity events to supported Security Information and Event Management (SIEM) platforms, enabling centralized monitoring, alerting, compliance reporting, and security investigations.

Supported SIEM platforms include:

* Datadog
* Splunk
* Microsoft Sentinel
* Elastic Security

## Overview

The SIEM integration allows Netmaker to export platform events to an external security monitoring solution. Exported events can be correlated with logs and telemetry from other systems to provide greater visibility into network operations and administrative activity.

## Configure a SIEM Integration

1. Navigate to **Settings → Integrations**.<br>

<figure><img src="/files/uF8538MAlO4Z4bQ2HkNN" alt=""><figcaption></figcaption></figure>

1. Connect the desired SIEM provider.
2. Enter the provider-specific connection details and credentials.
3. Test the connection.
4. Save the integration.

Once configured, Netmaker will begin forwarding supported audit and activity events to the selected SIEM platform.

## Provider-Specific Configuration

Refer to the following guides for configuration details:

### Datadog

1. Create a Datadog API key<br>

   <figure><img src="/files/MmukCHWA0CYQumu8Ea69" alt=""><figcaption></figcaption></figure>
2. Enter the API key in Netmaker.<br>

   <figure><img src="/files/VuwTodYgAkyCq1fzhj5o" alt=""><figcaption></figcaption></figure>
3. In the **Datadog Site** field, select the region/site where your Datadog organization is hosted.
4. If your Datadog URL is [**https://us5.datadoghq.com**](https://us5.datadoghq.com), select **`us5.datadoghq.com (US5)`** from the dropdown.<br>

   <figure><img src="/files/DTttndQ5RG7s2Hjuc8Za" alt=""><figcaption></figcaption></figure>
5. Test and save the integration.<br>

   <figure><img src="/files/9eOEuYxkwTppunp3tmdR" alt=""><figcaption></figcaption></figure>

### Splunk

#### Step 1: Open HTTP Event Collector

1. Click **Settings** (top-right of the Splunk interface).

   <figure><img src="/files/BVUqWhTwEHq0HOoNMdUF" alt=""><figcaption></figcaption></figure>
2. Select **Data Inputs**.<br>

   <figure><img src="/files/CYMIcFPTKy5UcuObYYWB" alt=""><figcaption></figcaption></figure>
3. Click **HTTP Event Collector**.<br>

   <figure><img src="/files/wMCbvdKFGBGvclJxRSs4" alt=""><figcaption></figcaption></figure>
4. If HEC is disabled, enable it under **Global Settings**.<br>

   <figure><img src="/files/225XtSKwf3Y9cWvNPwgG" alt=""><figcaption></figcaption></figure>

   <figure><img src="/files/l0wyf14r0g718Gk5QwbV" alt=""><figcaption></figcaption></figure>

#### Step 2: Create a HEC Token

1. Click **New Token**.<br>

   <figure><img src="/files/5OqkQNqpIrvYapyhElC6" alt=""><figcaption></figcaption></figure>
2. Give it a name, such as **Netmaker SIEM**.
3. Choose the destination index (for example, `main`).<br>

   <figure><img src="/files/gfuPobZIvspObxtRHZKO" alt=""><figcaption></figcaption></figure>
4. Complete the wizard and click **Submit**.
5. Copy the generated **HEC Token**.

#### **Step 3: Copy the HTTP Event Collector (HEC) Endpoint**

Enter your Splunk Cloud instance URL as the **HEC Endpoint URL**.

For example, if your Splunk Cloud instance is:

```
https://prd-p-wvklf.splunkcloud.com
```

then enter:

```
https://prd-p-wvklf.splunkcloud.com
```

#### Step 4: Configure Netmaker

<figure><img src="/files/efV5PlZiXIdEt9gb7ZBV" alt=""><figcaption></figcaption></figure>

Enter the following values:

* **HEC Endpoint URL**

  ```
  https://http-inputs-prd-p-wvklf.splunkcloud.com/services/collector/event
  ```
* **HEC Token**
  * Paste the token you created in Splunk.
* **Test and save the integration.**

### Microsoft Sentinel

1. Create a Data Collection Endpoint (DCE) and Data Collection Rule (DCR).
2. Obtain the ingestion endpoint and credentials.
3. Enter the endpoint and credentials in Netmaker.
4. Test and save the integration.

### Elastic

#### 1. Check if You Already Have a Deployment

* Go to <https://cloud.elastic.co> and log in
* On the home screen, check **“Deployments”**

#### If you already have a deployment:

* Skip to **Step 3 (Open Deployment)**

#### If you don’t have a deployment:

* Click **“Create deployment”** and continue below

***

#### 2. Create a Deployment&#x20;

Click **“Create deployment”**, then configure:

* **Name:** e.g. `netmaker-security`
* **Cloud Provider:** AWS / GCP / Azure
* **Region:** closest to your Netmaker instance
* **Version:** latest Elasticsearch
* **Template:** Security or General Purpose

Optional settings

* Adjust sizing/resources if needed (defaults are usually fine)

**Finish setup**

* Click **“Create Deployment”**
* Wait until status becomes **Healthy**
* IMPORTANT: Save credentials:
  * Username: `elastic`
  * Password (shown only once)

***

#### 3. Open Your Deployment

* From the deployments list, click **“Manage”** on your deployment\ <br>

  <figure><img src="/files/fiEvuQS642VE0QvBoeGv" alt=""><figcaption></figcaption></figure>

***

#### 4. Get Elasticsearch Endpoint

* In the deployment overview, locate:

  <figure><img src="/files/pSBMY6PobUYRGHNufRLD" alt=""><figcaption></figcaption></figure>
* Click the **copy icon**&#x20;

***

#### 5. Create API Key (via Kibana)

#### Open project

* Click **“Open project”**<br>

  <figure><img src="/files/jOQTqhscwuOLz88pUaA2" alt=""><figcaption></figcaption></figure>

#### Create API key

* Click the **Settings (⚙️) icon** in the left sidebar

  <figure><img src="/files/fRBYqSd5JzW6x5rSV0wz" alt=""><figcaption></figcaption></figure>
* **Click API Keys**

  <figure><img src="/files/RZpQNBwhgzGUKT7bmCXH" alt=""><figcaption></figcaption></figure>
* Click **“Create API key”**<br>

  <figure><img src="/files/iYCsrvhfzL5EyWjURwdI" alt=""><figcaption></figcaption></figure>
* Name: `netmaker-integration`
* Copy and save it immediately (it won’t be shown again)

***

#### 6. Configure Netmaker Integration

Use the following values:

* **Elasticsearch Endpoint**
* **API Key**
* **Index name** (e.g. `netmaker-events` or custom)

***

#### 7. Final Step

Enter these values into your **Netmaker SIEM integration settings** and save.

## Verify the Integration

1. Click **Test Connection**.\ <br>

   <figure><img src="/files/srbPAW77hcUrTT9m2PVn" alt=""><figcaption></figcaption></figure>
2. Save the integration.
3. Generate a test event in Netmaker.
4. Confirm the event appears in your SIEM platform.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://learn.netmaker.io/features/telemetry-and-logging/activity/siem-integration.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
