Skip to main content

Connecting your SIEM to Kolleno

The endpoint, format, authentication, and polling details your security team needs to connect a SIEM to Kolleno's audit event feed.

Connecting your SIEM

This article is for the person configuring your SIEM tool. Before you start, make sure the SIEM add-on is active and you've created an API key (see Creating and managing your SIEM API keys).



​

The feed endpoint

Go to Settings > SIEM. Under SIEM status you'll find the endpoint to poll, alongside a Copy button. Configure your SIEM to poll this endpoint. Events are returned in OCSF version 1.6.0 JSON.



​

Authentication

Each request must include an Authorization header built from your API key's ID and secret:

Authorization: SIEM <key-id>:<secret>

Requests are scoped to the company the key belongs to, so a key only ever returns your own company's events.



​

Collecting events incrementally

The feed is time-ordered and paginated. You can narrow and page through results with these query parameters:

  • since: return events from this time onwards (ISO 8601, inclusive).

  • until: return events up to this time (ISO 8601, exclusive).

  • limit: number of events per page (default 500, maximum 1000).

  • cursor: the pagination cursor returned with each page.

A typical setup polls on a fixed schedule, pages through all results using cursor, then advances since to the time of the last event collected so each poll only fetches what's new.



​

Rate limits

The feed applies a per-company rate limit. Polling on a sensible interval (rather than continuously) keeps you comfortably within it.

Did this answer your question?