Saviynt Enterprise Identity Cloud (v1.0.8)

Saviynt Enterprise Identity Cloud (EIC) is a cloud-based platform that converges identity governance, administration, and privileged access management into a single, intelligent solution to help organizations secure and manage user identities.

Author
Cortex XSOAR
Support
xsoar
URL
https://www.paloaltonetworks.com/cortex
Categories
Analytics & SIEM, Identity and Access Management

Integrations (1)

Modeling rules (1)

README

<~XSIAM>

Saviynt Enterprise Identity Cloud (EIC)

Overview

Saviynt Enterprise Identity Cloud (EIC) is an AI-driven, cloud-native identity security platform that unifies Identity Governance and Administration (IGA).
It manages and secures all user and non-human access across hybrid IT environments to help organizations reduce risk and meet compliance mandates.

This Pack Includes

Data Normalization and Querying Capabilities

Supported Log Category


Enable Data Collection

Configure Saviynt Enterprise Identity Cloud

To fetch audit logs from Saviynt Enterprise Identity Cloud (EIC), you must first create an Analytics Record within Saviynt and set up a dedicated user with appropriate permissions.

For more detailed instructions, click here.

Note:
The Saviynt API requires a username and password to obtain an authorization token before logs can be fetched.
username: Specify the user name to log in to Saviynt Identity Cloud.
password: Specify the password to log in to Saviynt Identity Cloud.

Configure Cortex XSIAM

  1. Navigate to Settings -> Data Sources.
  2. On the top right corner, click + Add Data Source.
  3. Search for Saviynt Enterprise Identity Cloud and click Connect.
  4. Under Connect, insert the name for the instance.
  5. Insert the Server URL.
  6. Insert the Username.
  7. Insert the Password.
  8. Under Collect, select Fetch events checkbox, and click Connect.

</~XSIAM>