Your security events, in your SIEM
Native export of authentication and security events to your SIEM is on the LoginMaster roadmap. Three integration modes and compatibility with leading SIEM platforms are planned.
Why integrate LoginMaster with your SIEM
Sending identity and access management events to your Security Operations Center is a best practice required by NIS2, ISO 27001 and the leading enterprise cybersecurity frameworks. LoginMaster's SIEM integration — on the roadmap — will let you correlate authentication logs with signals from firewalls, endpoints and applications.
Unifying IAM data inside your SOC reduces mean time to detect (MTTD) and mean time to respond (MTTR), makes correlation rules more effective, and maintains a complete audit trail ready for review by auditors and regulators.
- Fast detection of credential stuffing, brute force and anomalous access
- Complete audit trail for GDPR, NIS2 and ISO 27001 compliance
- Threat intelligence enrichment with IAM context
- Correlation between IAM events and SOC signals for reduced MTTR
Which logs and audit evidence do you need for ISO 27001 certification
For ISO 27001:2022 certification the access-management audit trail has to be complete and demonstrable: who accessed what, when, with which authentication method and with what outcome. In practice you need login and logout logs, failed access attempts with automatic anti brute-force lockouts, second-factor activations and changes, account creation, modification and deactivation, role and permission changes, and logins from new devices. LoginMaster records these event categories and forwards them to your SIEM in real time, so the evidence is already correlated and retained in the system auditors actually review.
- 5.15 — Access control
- Evidence of roles, permissions and project access for every identity, with assignments and revocations tracked.
- 8.15 — Logging
- Recording of authentication events, successful and failed logins, account lockouts and administrative actions, exportable to the SIEM.
- 8.24 — Use of cryptography
- Dedicated cryptographic keys per tenant and project, dual-signed tokens and credentials protected with Argon2 and split-salt.
- 5.14 — Information transfer
- Encrypted channels between all components and towards the SIEM: Webhook over HTTPS, Syslog CEF over TLS, REST API over HTTPS with API key.
Three integration methods
Three modes toward the leading SIEM communication standards are planned, to fit any infrastructure.
Webhook JSON
Coming soon: LoginMaster will push events to your SIEM in real time over HTTPS by configuring your endpoint URL.
- Real-time push via HTTPS
- Structured JSON payload
- Single URL configuration
- Automatic retry on failure
Syslog CEF/TLS
Coming soon: event delivery in the standard CEF (Common Event Format) over an encrypted TLS connection, compatible with most enterprise SIEMs.
- Industry-standard CEF format
- Encrypted TLS connection
- Native SIEM compatibility
- Automatic event parsing
REST API
Coming soon: your SIEM will query LoginMaster to retrieve events on demand, ideal for pull-based platforms or custom integrations.
- On-demand pull model
- Event filtering by type and date
- Pagination and rate limiting
- API key authentication
Compatible with leading SIEMs
We aim to support the most widely used SIEM platforms on the market. If your SIEM is not listed, contact us to share your requirements.
Splunk
Enterprise Security and SOAR
IBM QRadar
SIEM and threat intelligence
Microsoft Sentinel
Cloud-native SIEM on Azure
Elastic SIEM
SIEM on Elastic Stack (ELK)
Google Chronicle
SecOps and threat detection
Micro Focus ArcSight
Enterprise SIEM and compliance
LogRhythm
SIEM and SOC automation
Wazuh
Open source SIEM and XDR
Sumo Logic
Cloud SIEM and analytics
Datadog Security
Monitoring and security analytics
Event catalog
LoginMaster logs all security-relevant events; native export to your SIEM is on the roadmap. Here are the main planned event categories.
Authentication
Login, logout, failed attempts, account lockouts, password resets, and access from new devices.
2FA Verification
2FA activation and deactivation, successful and failed verifications, backup code generation.
Sessions
Session creation, renewal, revocation, and expiration. Multiple sessions and sessions from anomalous IPs.
Administration
User modifications, role assignments, project configuration updates, and API key management.
Security
Detected brute-force attempts, access from suspicious IPs, access pattern anomalies, and policy violations.
How it works
Integrating LoginMaster with your SIEM takes three simple steps.
Configure the connector
From the LoginMaster dashboard, choose the integration method (Webhook, Syslog, or API) and enter your SIEM parameters.
LoginMaster sends the events
Once available, LoginMaster will automatically send security events to your SIEM in the chosen format.
Your SIEM receives them
Events appear in your SIEM ready to be correlated, analyzed, and used in your detection and alerting rules.
Frequently Asked Questions
LoginMaster is compatible with Splunk, IBM QRadar, Microsoft Sentinel, Elastic SIEM, Google Chronicle, ArcSight, LogRhythm, Wazuh, Sumo Logic, and Datadog Security. Thanks to standard protocols (Webhook JSON, Syslog CEF, REST API), it can integrate with any SIEM that supports these formats.
SIEM export is on the roadmap. The goal is to send events directly to your SIEM via standard protocols, with no agents, collectors or additional software to install.
Yes. All integration methods use encrypted connections. Webhooks travel over HTTPS, Syslog uses TLS, and REST APIs are protected by HTTPS and API key authentication.
Yes. Once available, from the LoginMaster dashboard you will be able to configure which event categories to send to your SIEM: authentication, 2FA, sessions, administration, security.
Basic configuration takes just a few minutes: choose the integration method, enter your SIEM parameters, and activate the connector. Our team is available to support you with more complex configurations.
LoginMaster implements an automatic retry mechanism with exponential backoff. Events are buffered and re-sent as soon as the SIEM becomes reachable again, ensuring no event is lost.
ISO 27001:2022 auditors ask you to demonstrate who accessed what and with what outcome: login and logout logs, failed access attempts and automatic lockouts, second-factor activations and changes, account creation, modification and deactivation, role and permission changes, and logins from new devices. LoginMaster tracks these event categories (authentication, 2FA, sessions, administration, security) and sends them to your SIEM, covering control 5.15 on identity management, 8.15 on logging, 8.24 on the use of cryptography and 5.14 on information transfer.
Events are forwarded to your SIEM in real time via Webhook over HTTPS, Syslog in CEF format over TLS or REST API in pull mode, so retention happens in the system auditors already review. If the SIEM is unreachable, events are buffered and re-sent with exponential-backoff retry, so no gaps appear in the audit trail. You can also filter which event categories to send by severity or by specific project, documenting that choice in your logging policy.
Ready to connect LoginMaster to your SIEM?
Request a personalized demo and we'll show you how to integrate LoginMaster with your SIEM in minutes.
In-depth guides
Step-by-step procedures, request examples and explicit comparisons between the available options.