Forum Discussion
DJB
Sep 07, 2021Copper Contributor
MCAS Impossible Travel alert AND original O365 Impossible Travel alert
Hello, we have O365 security center sending alerts to our 3rd party SIEM through the management API. MCAS sees the same O365 alert - when MCAS is integrated with the SIEM, will both alerts be s...
pvanberlo
Steel Contributor
DJB This probably depends on the SIEM solution. Usually what happens is that both services are being ingested with different connectors or whatever they're called for your SIEM. In that sense, the SIEM needs to be able to determine that it's the same alert if both alerts come in via a different route.
DJB
Sep 08, 2021Copper Contributor
Thanks for the reply! Appreciated.
Our MCAS deployment is in the early stages - will do some further analysis on what the SIEM ingests and how it's presented.
Our MCAS deployment is in the early stages - will do some further analysis on what the SIEM ingests and how it's presented.