Kaseya SIEM integration with SaaS Alerts

Follow a step-by-step guide outlining essential tasks and considerations necessary for successfully deploying Kaseya's SIEM capabilities via SaaS Alerts.

Getting started

Before integrating Kaseya SIEM with SaaS Alerts, ensure you have provider access to SaaS Alerts and the appropriate administrative permissions for the products you plan to connect.

Step 1: Complete SaaS Alerts onboarding prerequisites

Confirm the following SaaS Alerts setup steps are completed:

Step 2: Establish RocketCyber connection

After completing SaaS Alerts prerequisites, establish a connection to RocketCyber.

Establishing connection with RocketCyber

Once you have signed up for Kaseya SIEM, you will be recognized in our database as a SIEM client. One of the most important onboarding steps is to establish a connection with RocketCyber in SaaS Alerts for the organization of your choice (RocketCyber can only be attached once per tenant). To accomplish this, follow these steps:

  • Click Organizations in the side navigation menu.
  • Click the edit organization icon for the organization you want to connect.
  • Click + New Application. If the organization already has other connected applications, you will see the + New Application button on the right. If there are no connected apps for the organization, you will also find the button in the center of the page.

  • Make sure the I have customer's global admin credentials option is selected.

  • Scroll down to the bottom of the page, where you will find the option to enable the connection with RocketCyber. Click the tile to proceed.

  • After clicking, you will be directed to the RocketCyber Connection Wizard. Please follow these steps:
    • Set Credentials: This is the first step of the wizard. You will see two items:
      • RocketCyber Region: You will see your RocketCyber region displayed. Please make sure that the RocketCyber and SaaS Alerts regions match.
      • API Token: Enter your RocketCyber API token to establish an API connection. If you need assistance accessing your RocketCyber API token, please refer to this article. You can click the eye icon to temporarily unmask the token for verification. Once you’ve entered the token, click Next to continue.
      Once the application connection is successful, a confirmation message will appear in the upper-right corner.

    • Product Selection: In Step 2 of the wizard, you will complete the Product Selection section. This is where you can choose from a range of products available for activation. This area serves as the global control panel, allowing you to enable various functionalities:
      • Under Available Products, select the checkboxes for the products you want to activate—typically, those that the partner will use for the vast majority of their organizations—and click + Add.

      • The products you select will then appear under Globally Assigned.

      • Here, you also have the option to select the checkbox next to a product and click Remove.

      • A warning message will pop up, informing you that removing a product means it will be taken off the global product list for all organizations using it, but it will not be removed from organizations that have a custom product list. Please choose either Cancel or Confirm.

      • Next, you can set the default state of these products for each organization. By default, the products are turned off, which means they can be connected but are not actively monitored. As a result, these products will not be displayed in the application list, but they will be available to connect when clicking + New Application. When you toggle a product on, the switch will turn green, indicating that the product is assigned and its monitoring will start once you map the organization in the next step. This information also applies to the toggles on the Organization Mapping screen. Finally, click Apply & Continue Editing or Next to proceed.

    • Organization Mapping: Additionally, there is an option to map customers from SaaS Alerts to RocketCyber:
      • Click the dropdown menu under SAAS ALERTS ORG to select the appropriate organization.

      • In the event that a new SaaS Alerts organization needs to be created, the system allows for a straightforward command (Create) to facilitate this process. Alternatively, if it is determined that a SaaS Alerts organization will not be utilized, there is an option to disregard it (Ignore), which will then move the organization to the designated Ignored tab.

      • Once you choose a SaaS Alerts organization, you can decide whether to enable certain features for specific clients. By default, the toggle in the middle is displayed in gray, indicating that the organization is currently using globally assigned apps.

      • To activate the toggle, simply slide it until it turns green. This indicates that you are no longer using the global list you previously established, nor are you applying the global toggle settings. Instead, you can start from the base settings and customize as needed. Everything you do here will now be specific to this particular organization.

      • Next, click Apply and Map to apply organization mapping, product assignments, and their activation statuses.

      • The organization will then be moved to the Mapped tab. Click Apply & Continue Editing to save your current mapping selections and continue making additional changes in the Organization Mapping screen, or click Finish to complete the organization mapping process and exit the wizard, saving all changes.

      • If you need to adjust your connection to RocketCyber, just click the RocketCyber tile and then select Edit in the lower-right corner. You will be taken to Step 2 (Product Selection) of the RocketCyber Connection Wizard.

      • To disconnect from RocketCyber, click the RocketCyber tile and select Disconnect Application. Deleting the application connection will keep the historical data will remain on the platform. Once you disconnect, data imports will stop, and the organization will no longer contribute to your billable count.

      • A Delete App pop-up message will ask you to confirm the deletion of the application or to Cancel.

      Customer apps

      After completing the RocketCyber Connection Wizard, the Customer Apps section will be visible. Essentially, these applications extract information from RocketCyber and integrate it into SaaS Alerts, providing a significant advantage as SaaS Alerts operates more quickly and efficiently.

      For instance, in the area of event data filtering, Kaseya SIEM offers the capability to filter and search for event data within SaaS Alerts. This feature enhances data management and allows for faster identification of relevant information when compared to RocketCyber. To use this feature, click Analysis in the side navigation menu. From there, you can select appropriate filters and click Run Report.

      In SaaS Alerts, you can filter and search for data similarly to how you would in RocketCyber, but a significant advantage is the ability to set up indicators of compromise.

      Response rules

      We will push out effective response rules to Kaseya SIEM clients automatically, focusing on detecting malicious activity. Instead of overwhelming Kaseya SOC with numerous events—potentially millions—our system allows clients to filter and curate these events through our indicators of compromise. This ensures they only receive events that matter to them, making their response efforts more efficient. Furthermore, our automation will support this process. If our system identifies malicious activity, it can take action without waiting for manual approval. For more information, refer to The Respond module.

      This automation is one of the significant benefits of using a security information management (SIEM) system and running RocketCyber through SaaS Alerts.

      In summary, successfully integrating RocketCyber in SaaS Alerts is a crucial step that significantly enhances your organization's cybersecurity strategy. This integration enables a more efficient and streamlined approach to monitoring and managing security incidents, allowing for quicker identification and response to potential threats. By following the outlined steps in the RocketCyber Connection Wizard, users can activate and customize various products to suit their specific needs, ensuring that they have the right tools in place for comprehensive protection. Moreover, the ability to leverage Customer Apps not only enhances data management but also provides powerful insights through advanced filtering and reporting mechanisms.