Requesting SIEM integration
Learn how to request SIEM integration for your IBM Bob Enterprise organization and what information you must share when opening a case.
SIEM integration is available for your IBM Bob Enterprise organization if you need to route audit data into your existing security monitoring workflows.
You cannot configure SIEM integration directly on your Administration page.
This integration is not self-service. To request SIEM integration for your organization, open a case with IBM Support.
Logged events
The events forwarded to your SIEM are the same audit events available in the activity log. For the full list of what is captured, see What is logged.
Network requirements
Bob routes your audit events to the Splunk HEC endpoint you provide. If your Splunk instance is behind a firewall, you must ensure that Bob's servers can reach the endpoint. Work with your network team to either expose the HEC endpoint or allowlist Bob's outbound traffic.
For the domains and ports that Bob uses, see Configuring firewall rules for Bob.
Information to include in your request
To help the Bob team prepare the integration, include the following details in your case:
- Your subscription ID, or the list of your subscription IDs to include
- Your Splunk HEC endpoint
- Your Splunk HEC token
- Your Splunk index name
- Your CA certificate, if your Splunk instance uses a self-signed certificate
Splunk is the tested example today. Bob can also route your logs to other SIEM backends that use Vector integrations, but you must coordinate this setup with the Bob team through your support case.
What to expect
After you submit your request, the Bob team reviews your details and coordinates the setup with you.
In most cases, onboarding takes a few days. The exact timeline can vary depending on your environment and the information you provide in your case.