Set up alerts for admin activities

Martin September 16, 2021

Is it possible to set up alerts via email for admin activities such as a change in group membership or permission scheme?

We using Rapid 7 as a SIEM tool so perhaps there's a way of sending the logs to that? Tried googling a few suggestions but 99.9% of the results are always to do with how to configure alerts for projects and issues.

 

Thanks

1 answer

0 votes
Thomas Deiler
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
October 15, 2021

Dear @Martin ,

if Rapid 7 can talk 'REST', you can pull this information form the audit log endpoint. Then  alerting is a piece of cake.

So long

Thomas

Suggest an answer

Log in or Sign up to answer