SIEM Event Logging
Forward BridgeLink security and event logs to your SIEM in real time.
Why it matters
Real-time security monitoring and compliance reporting.
Healthcare environments have to monitor access and configuration changes and keep an audit trail for compliance. The SIEM plugin forwards BridgeLink's error and event logs to one or more external SIEM platforms in real time, so authentication, configuration, user management, data access, and system events land in the same place your security team already watches, without anyone leaving WebAdmin.
Capabilities
What it does:
Multiple destinations
Configure and manage several SIEM endpoints at once, each with its own protocol, address, and format, enabled or disabled independently.
Flexible protocols
Send events over an HTTP/HTTPS REST API, Syslog (UDP or TCP, with optional TLS), or write them to a local log file.
Flexible formats
Emit CEF, JSON, or LEEF so events arrive in the shape your SIEM platform expects.
Delivery monitoring and alerts
Track uptime, queue depth, latency, and per-destination status, with email alerts when the success rate drops or the queue backs up.
Release highlights
What's new.
Event forwarding
- Multiple destinations: configure and manage several SIEM endpoints at once, each with its own protocol, address, and format.
- Flexible protocols: HTTP/HTTPS REST API, Syslog (UDP or TCP with optional TLS), or a local log file.
- Flexible formats: CEF, JSON, or LEEF, so events arrive in the shape your SIEM expects.
Platform presets
- Ready-made presets for Elastic Stack, Splunk (HEC), IBM QRadar, and Wazuh fill in the recommended protocol and format automatically.
- Other / Custom connects any platform that accepts HTTP/HTTPS, Syslog, or a log file, such as ArcSight.
- A five-step Add Destination wizard, no SIEM expertise required.
Control and monitoring
- Master switch to enable or disable all SIEM forwarding at once.
- Per-destination toggle to disable individual destinations without deleting their configuration.
- Delivery health monitoring from the Statistics tab.
- Backup and restore the SIEM configuration as a file.
How it works
Get started in minutes.
- 1
License and enable the plugin
Innovar Healthcare installs the SIEM Plugin extension and a license. Once licensed, a SIEM tab appears under Settings in WebAdmin.
- 2
Add your SIEM destinations
A five-step wizard walks you through each destination, with ready-made presets for Elastic Stack, Splunk, IBM QRadar, and Wazuh, or an Other / Custom option for anything else.
- 3
Choose protocol, format, and filters
Pick HTTP/HTTPS, Syslog, or a log file, an event format of CEF, JSON, or LEEF, and optionally filter by event type, severity, or user to control volume and cost.
- 4
Monitor delivery health
The Statistics tab shows uptime, queue depth, latency, and per-destination status, with email alerts when delivery falls behind.
Requirements
What you'll need:
- BridgeLink 26.6.0 or later
- A SIEM Plugin license and the License Manager plugin
- At least one reachable SIEM destination (Elastic Stack, Splunk, IBM QRadar, Wazuh, or a custom HTTP, Syslog, or log-file endpoint)
- Outbound network access from BridgeLink to each destination (for example, port 514 for Syslog)
FAQ
Frequently asked questions.
Which SIEM platforms are supported?
The plugin ships presets for Elastic Stack, Splunk, IBM QRadar, and Wazuh. Any platform that accepts an HTTP/HTTPS REST API, Syslog, or a local log file, such as ArcSight, connects through the Other / Custom option.
What event formats can it send?
CEF, JSON, or LEEF, chosen per destination so events arrive in the shape your SIEM expects.
Can I control which events are forwarded?
Yes. Each destination can filter by event type (authentication, configuration, user management, system, data access, and errors), severity, and user, which also helps lower ingestion costs.
Can I send to more than one SIEM at once?
Yes. You can configure multiple destinations and enable or disable each one independently, with a master switch to stop all forwarding at once.
How do I know events are being delivered?
The Statistics tab reports uptime, queue depth, latency, dropped events, and a connected or disconnected status per destination, refreshed automatically, plus optional email alerts.
Availability
Requires BridgeLink 26.6.0 or later and a SIEM Plugin license. Installed by Innovar Healthcare or your professional services contact.
Add SIEM Event Logging to BridgeLink.
Talk to us about your deployment, or read the full user guide to get started.