Menlo Security Collector
Overview
This collector fetches logs from Menlo Security APIs.
Devo collector features
Feature | Details |
---|---|
Allow parallel downloading (multipod) | not allowed |
Running environments | collector server |
Populated Devo events | table |
Flattening preprocessing | no |
Requires IP Whitelisting | yes |
Data sources
Data source | Description | API endpoint | Collector service name | Devo table | Available from release |
---|---|---|---|---|---|
Menlo Security API | Get all the web type logs | api/rep/v2/fetch/client_select | web | v1.2.0 | |
Menlo Security API | Get all the audit type logs | api/rep/v2/fetch/client_select | audit | rbi.menlo.audit | v1.2.0 |
Menlo Security API | Get all the email type logs | api/rep/v2/fetch/client_select | rbi.menlo.email | v1.2.0 | |
Menlo Security API | Get all the smtp type logs | api/rep/v2/fetch/client_select | smtp | rbi.menlo.smtp | v1.2.0 |
Menlo Security API | Get all the attachment type logs | api/rep/v2/fetch/client_select | attachment | rbi.menlo.attachment | v1.2.0 |
Flattening preprocessing
Data source | Collector service | Optional | Flattening details |
---|---|---|---|
Menlo Security API | All the services |
| not required |
Minimum configuration required for basic pulling
Although this collector supports advanced configuration, the fields required to retrieve data with basic configuration are defined below.
This minimum configuration refers exclusively to those specific parameters of this integration. There are more required parameters related to the generic behavior of the collector. Check setting sections for details.
Setting | Details |
---|---|
token | The Token for Menlo API. |
See the Accepted authentication methods section to verify what settings are required based on the desired authentication method.
Accepted authentication methods
Authentication method | token |
---|---|
token | REQUIRED |
Run the collector
Once the data source is configured, you can either send us the required information if you want us to host and manage the collector for you (Cloud collector), or deploy and host the collector in your own machine using a Docker image (On-premise collector).
Collector services detail
This section is intended to explain how to proceed with specific actions for services.
web service
Change log for v1.x.x
Release | Released on | Release type | Details | Recommendations |
---|---|---|---|---|
v1.2.0 | 30 Oct 2024 | NEW FEATURE Bug Fixes | New features:
Bug fixes:
| Recommended Version |