SIEM export for youremail security gateway.No data silo.
Phishing, malware, DLP, quarantine and mailflow events from MailGuard stream into your SIEM as a normalized feed. Via pull API, in CEF, LEEF, ECS or JSON, to Splunk, Microsoft Sentinel, IBM QRadar or Elastic.
Why email security events belong in the SIEM
Email is the most common attack path. Without correlating gateway verdicts, the attack surfaces too late.
Threats stay in the gateway silo
Phishing, BEC and malware are caught at the gateway, but without export they never reach the central SOC dashboard. Correlation with endpoint, firewall and identity logs is missing.
NIS2 and GDPR require evidence
NIS2 mandates logging and provability of security-relevant events, GDPR a record under Art. 30. Without continuous event export the evidence stays incomplete.
Proprietary exports or costly add-ons
Many gateways provide logs only through paid enterprise tiers, incomplete formats or a US cloud detour. That complicates integration and data residency.
Push syslog is fragile
Plain syslog push over UDP drops events under load and is hard to route through firewalls. A cursor-based pull is more robust and complete.
How Conbool gets events into your SIEM
An append-only event stream that any SIEM collects. No data silo, no vendor lock-in.
1. Cursor-based pull API
Your SIEM or collector polls an authenticated HTTPS endpoint and pages through new events with a cursor, gap-free. Firewall-friendly, resumable, with a 30-day window and replay.
2. Four formats, every SIEM
CEF for Splunk and ArcSight, LEEF for IBM QRadar, ECS for Elastic and Kibana, JSON generic. Selectable per key, with no conversion on your side.
3. Multi-tenant and EU-hosted
Every event carries its tenant assignment, sensitive fields can be hashed or removed. Processing in European data centers, no US cloud intermediary.
What the SIEM export delivers
Included in every MailGuard license, no enterprise surcharge.
Full event coverage
Mailflow, threat detection, malware verdicts, DLP incidents, quarantine and releases, link clicks. SecureFiles and SecureMail events are on the roadmap.
CEF, LEEF, ECS, JSON
All four industry standards natively, selectable per API key. No transformation pipeline of your own.
GDPR mode for payloads
Subjects and addresses in cleartext, as a sha256 hash or removed. It stays correlatable regardless.
Push via webhook
As an alternative to polling, Conbool sends new events immediately, HMAC-signed, to your URL, with retry and timestamp protection against replays.
Audit mode reflected
Every verdict shows whether it blocked or only observed. Your SOC tells real blocks apart from audit-only detection.
Configurable retention
Retention per tenant between 7 and 365 days, plus IP allowlist and rate limit per key for controlled access.
Conbool versus the typical gateway
What a SIEM-grade export has to do.
Conbool MailGuard | Typical email gateway | |
|---|---|---|
| SIEM export included | In every license | Often a costly enterprise add-on |
| Format coverage | CEF, LEEF, ECS, JSON | Often just one or two formats |
| Delivery model | Pull API with cursor plus webhook push | Often syslog push only |
| Data residency | EU hosting, EU jurisdiction | Often a US cloud detour |
| GDPR mode for events | Cleartext, hash or redaction | Rarely controllable |
| Multi-tenancy | Per-tenant tagging and retention | Mostly global, not separated |
This comparison describes operation across a company. For individual users, encryption inside the client remains a workable solution.
SIEM export FAQ
Which SIEM systems can Conbool connect to?
Which formats are supported?
Which events are exported?
Is the export GDPR-compliant?
Does the SIEM export cost extra?
Why pull instead of push?
Verwandte Lösungen
Email security events in your SIEM.
Included in every MailGuard license. EU-hosted, multi-tenant, audit-ready.