Setting up SIEM integration

Steps

  1. Create a new administrator contact for Forcepoint storage
    We strongly recommend that the log download process has its own user name and password to gain access to the Forcepoint Web Security Cloud service. This keeps the process separate from your other administration tasks and enables you to establish longer password expiration policies.
  2. Enable SIEM logging
  3. Schedule log file download for Forcepoint storage