Menlo Security¶
Menlo Security provides web and e-mail event telemetry. Cyderes utilizes this information to track suspicious e-mail attachments and unauthorized or malicious web behaviors on endpoints.
Cyderes supports the ingestion of Menlo events using their Logging API.
Chronicle Data Types¶
- MENLO_SECURITY
Configuration¶
Any combination of the following log types can be ingested:
- web: web access logs
- audit: admin portal audit logs
- email: email URL rewriter logs
- attachment: email attachment logs
- smtp: smtp message transform and restore logs
- isoc: Menlo Threat Intelligence alerts
Gather Information¶
Provide the following information to Cyderes to complete implementation:
- Menlo API Authentication Token (obtained from Menlo Customer Success)