Skip to main content

What is SIEM audit logging in Kolleno?

An overview of Kolleno's SIEM audit-logging add-on: what it does, who it's for, and how the security event feed works.

What is SIEM audit logging?

A SIEM (Security Information and Event Management) tool is the system your security team uses to collect, store, and monitor security logs from across your organisation. Kolleno's SIEM audit-logging add-on lets you feed a stream of security-relevant events from your Kolleno account straight into your own SIEM.

Once enabled, Kolleno records events such as sign-ins, permission changes, payment-configuration changes, and file downloads, and makes them available to your SIEM in the industry-standard OCSF (Open Cybersecurity Schema Framework) version 1.6.0 format.



How it works

SIEM audit logging is a pull feed: Kolleno exposes a secure endpoint, and your SIEM polls it on a schedule to collect new events. Kolleno does not push data into Splunk, syslog, or any specific tool. Any SIEM that can read an OCSF or JSON feed over HTTPS can connect.

A few things to know up front:

  • It is a paid add-on and is switched on by the Kolleno team at your request.

  • Logging only covers activity that happens after it is turned on, so there is no backfill of past activity.

  • Events are held for a limited retention period, so your SIEM should poll regularly and becomes your long-term record.



Who can see and manage it

The SIEM area lives under Settings > Security. It is only visible to company admins.

Did this answer your question?