Solution · SIEM & SOC

SIEM export for youremail security gateway.No data silo.

Phishing, malware, DLP, quarantine and mailflow events from MailGuard stream into your SIEM as a normalized feed. Via pull API, in CEF, LEEF, ECS or JSON, to Splunk, Microsoft Sentinel, IBM QRadar or Elastic.

Why email security events belong in the SIEM

Email is the most common attack path. Without correlating gateway verdicts, the attack surfaces too late.

Threats stay in the gateway silo

Phishing, BEC and malware are caught at the gateway, but without export they never reach the central SOC dashboard. Correlation with endpoint, firewall and identity logs is missing.

NIS2 and GDPR require evidence

NIS2 mandates logging and provability of security-relevant events, GDPR a record under Art. 30. Without continuous event export the evidence stays incomplete.

Proprietary exports or costly add-ons

Many gateways provide logs only through paid enterprise tiers, incomplete formats or a US cloud detour. That complicates integration and data residency.

Push syslog is fragile

Plain syslog push over UDP drops events under load and is hard to route through firewalls. A cursor-based pull is more robust and complete.

How Conbool gets events into your SIEM

An append-only event stream that any SIEM collects. No data silo, no vendor lock-in.

1. Cursor-based pull API

Your SIEM or collector polls an authenticated HTTPS endpoint and pages through new events with a cursor, gap-free. Firewall-friendly, resumable, with a 30-day window and replay.

2. Four formats, every SIEM

CEF for Splunk and ArcSight, LEEF for IBM QRadar, ECS for Elastic and Kibana, JSON generic. Selectable per key, with no conversion on your side.

3. Multi-tenant and EU-hosted

Every event carries its tenant assignment, sensitive fields can be hashed or removed. Processing in European data centers, no US cloud intermediary.

What the SIEM export delivers

Included in every MailGuard license, no enterprise surcharge.

Full event coverage

Mailflow, threat detection, malware verdicts, DLP incidents, quarantine and releases, link clicks. SecureFiles and SecureMail events are on the roadmap.

CEF, LEEF, ECS, JSON

All four industry standards natively, selectable per API key. No transformation pipeline of your own.

GDPR mode for payloads

Subjects and addresses in cleartext, as a sha256 hash or removed. It stays correlatable regardless.

Push via webhook

As an alternative to polling, Conbool sends new events immediately, HMAC-signed, to your URL, with retry and timestamp protection against replays.

Audit mode reflected

Every verdict shows whether it blocked or only observed. Your SOC tells real blocks apart from audit-only detection.

Configurable retention

Retention per tenant between 7 and 365 days, plus IP allowlist and rate limit per key for controlled access.

Conbool versus the typical gateway

What a SIEM-grade export has to do.

 
Conbool MailGuard
Typical email gateway
SIEM export included
In every license
Often a costly enterprise add-on
Format coverage
CEF, LEEF, ECS, JSON
Often just one or two formats
Delivery model
Pull API with cursor plus webhook push
Often syslog push only
Data residency
EU hosting, EU jurisdiction
Often a US cloud detour
GDPR mode for events
Cleartext, hash or redaction
Rarely controllable
Multi-tenancy
Per-tenant tagging and retention
Mostly global, not separated

This comparison describes operation across a company. For individual users, encryption inside the client remains a workable solution.

SIEM export FAQ

Which SIEM systems can Conbool connect to?
Virtually any SIEM that can poll an authenticated HTTPS endpoint. Splunk, Microsoft Sentinel, IBM QRadar and Elastic connect through their standard collectors, generic targets via curl or a cron job. Alternatively Conbool sends events via webhook push.
Which formats are supported?
CEF for Splunk and ArcSight, LEEF for IBM QRadar, ECS for Elastic and Kibana, and JSON generic. The format is selectable per API key, no conversion required.
Which events are exported?
Mailflow status, threat detection, malware verdicts, DLP incidents, quarantine and releases, and link clicks from MailGuard. SecureFiles and SecureMail events are on the roadmap.
Is the export GDPR-compliant?
Yes. Processing runs in European data centers without a US cloud intermediary. Sensitive fields such as subject and addresses can be sent in cleartext, as a sha256 hash or fully removed per tenant. A right-to-be-forgotten endpoint removes traces on request.
Does the SIEM export cost extra?
No. The SIEM export is part of MailGuard and included in the license, with no enterprise surcharge.
Why pull instead of push?
A cursor-based pull is firewall-friendly, resumable and loses no events under load. If you prefer push, use the HMAC-signed webhook with retry as well.

Verwandte Lösungen

Email security events in your SIEM.

Included in every MailGuard license. EU-hosted, multi-tenant, audit-ready.