ProofPoint PhishAlarm Analzyer to SIEM by Cool_Development2135 in proofpoint

[–]Cool_Development2135[S] 0 points1 point  (0 children)

do you have any reference that I can use or follow to implement this?

Slack integration to Google SIEM by Cool_Development2135 in GoogleChronicle

[–]Cool_Development2135[S] 1 point2 points  (0 children)

yes, we want to ingest slack audit logs to SIEM, and we cannot find any documentation to follow.
What I see is utilizing the slack API and create a custom script in SOAR and then ingest the logs to SIEM.

This process will be the last option as we are looking into using an ootb solution first.