How-To: Export your EZCMS Logs to Huntress
Prerequisites
How To Export Your EZCMS Audit Logs To Huntress
How To Enable Log Export in EZCMS Portal
-
Go to your EZCMS portal.
-
Click on Settings.

-
Scroll down to SIEM Connection Settings and enable the Send Alerts to SIEM option.

How To Configure the Huntress Exporter in the Huntress Portal
-
In another tab, go to your Huntress instance.
-
Click on the SIEM menu. Then, click Source Management.

-
Click Add Source. Then, click Generic HEC (HTTP Event Collector).

-
Click + Add to add a new HEC.

-
Add an Organization, Name, and optional Description. Then, click Save.

-
After the HEC is created, copy the HTTP Event Collector URL and the HTTP Event Collector Token.

How To Configure the Huntress SIEM in EZCMS Portal
-
Now go back to the EZCMS Portal.
-
Select Huntress as the SIEM Provider.

-
Input the values that you copied from the Huntress portal. Then, click Test Connection. This will create a test log in your Huntress SIEM (please allow a few minutes for the log to show up in the Huntress portal).

-
If the connection test is successful, click Save Changes.

-
EZCMS will now send your security alerts to your SIEM. If an error occurs it will email your subscription administrators.