Best Software for 2025 is now live!
Allen S.
AS
Director Of Information Security at Messiah University

Has anyone implemented ingesting the Audit logs from Mimecast into Graylog?

Are there any tips you would be willing to share? We are looking to create a Graylog Alert/Rule from ingested Mimecast Outbound audit logs to detect when a user sends more the 100 emails over a 15 min window of time. this would generally be indicative of a compromised account that is sending spam to other users.
2 comments
Looks like you’re not logged in.
Users need to be logged in to answer questions
Log In
DB
Senior Principal Consultant
0
Yes, I have a working example. We also sell this as a feature
Looks like you’re not logged in.
Users need to be logged in to write comments
Log In
Reply
CH
0
I have not, I just use the built in alerts and mxtoolbox for mail flow.
Looks like you’re not logged in.
Users need to be logged in to write comments
Log In
Reply