SIEM export for youremail security gateway.No data silo.
Phishing, malware, DLP, quarantine and mailflow events from MailGuard stream into your SIEM as a normalized feed. Via pull API, in CEF, LEEF, ECS or JSON, to Splunk, Microsoft Sentinel, IBM QRadar or Elastic.
Why email security events belong in the SIEM
Email is the most common attack path. Without correlating gateway verdicts, the attack surfaces too late.
Threats stay in the gateway silo
Phishing, BEC and malware are caught at the gateway, but without export they never reach the central SOC dashboard. Correlation with endpoint, firewall and identity logs is missing.
NIS2 and GDPR require evidence
NIS2 mandates logging and provability of security-relevant events, GDPR a record under Art. 30. Without continuous event export the evidence stays incomplete.
Proprietary exports or costly add-ons
Many gateways provide logs only through paid enterprise tiers, incomplete formats or a US cloud detour. That complicates integration and data residency.
Push syslog is fragile
Plain syslog push over UDP drops events under load and is hard to route through firewalls. A cursor-based pull is more robust and complete.
How Conbool gets events into your SIEM
An append-only event stream that any SIEM collects. No data silo, no vendor lock-in.
1. Cursor-based pull API
Your SIEM or collector polls an authenticated HTTPS endpoint and pages through new events with a cursor, gap-free. Firewall-friendly, resumable, with a 30-day window and replay.
2. Four formats, every SIEM
CEF for Splunk and ArcSight, LEEF for IBM QRadar, ECS for Elastic and Kibana, JSON generic. Selectable per key, with no conversion on your side.
3. Multi-tenant and EU-hosted
Every event carries its tenant assignment, sensitive fields can be hashed or removed. Processing in European data centers, no US cloud intermediary.
What the SIEM export delivers
Included in every MailGuard license, no enterprise surcharge.
Full event coverage
Mailflow, threat detection, malware verdicts, DLP incidents, quarantine and releases, link clicks. SecureFiles and SecureMail events are on the roadmap.
CEF, LEEF, ECS, JSON
All four industry standards natively, selectable per API key. No transformation pipeline of your own.
GDPR mode for payloads
Subjects and addresses in cleartext, as a sha256 hash or removed. It stays correlatable regardless.
Push by webhook or syslog
Instead of polling, Conbool sends new events itself: HMAC-signed to your URL, or as syslog per RFC 5424 over TCP with TLS to your own collector. Framed with octet counting per RFC 6587, so no message falls apart at a line break.
Audit mode reflected
Every verdict shows whether it blocked or only observed. Your SOC tells real blocks apart from audit-only detection.
Configurable retention
Retention per tenant between 7 and 365 days, plus IP allowlist and rate limit per key for controlled access.
Configuration changes in the stream
Anyone weakening a policy used to be invisible in the collector. Every change is now its own event in the stream, with module, action and acting person — precisely the action that often precedes an incident.
Conbool versus the typical gateway
What a SIEM-grade export has to do.
Conbool MailGuard | Typical email gateway | |
|---|---|---|
| SIEM export included | In every license | Often a costly enterprise add-on |
| Format coverage | CEF, LEEF, ECS, JSON | Often just one or two formats |
| Retrieval model | Cursor-based pull, webhook push and syslog over TCP with TLS | Usually pull only, syslog at extra cost |
| Data residency | EU hosting, EU jurisdiction | Often a US cloud detour |
| GDPR mode for events | Cleartext, hash or redaction | Rarely controllable |
| Multi-tenancy | Per-tenant tagging and retention | Mostly global, not separated |
As of October 2026. The right-hand column describes the usual approach without Conbool, not a specific vendor.
SIEM export FAQ
Which SIEM systems can Conbool connect to?
Which formats are supported?
Which events are exported?
Is the export GDPR-compliant?
Does the SIEM export cost extra?
Why pull instead of push?
Email security events in your SIEM.
Included in every MailGuard license. EU-hosted, multi-tenant, audit-ready.