Skip to main content
Skip table of contents

Initialize the Mimecast SIEM Beat

This guide outlines the procedure to initialize the Mimecast SIEM Beat configuration using the Open Collector.

Prerequisites

Direction

Port

Protocol

Source

Outbound

443

HTTPS

Mimecast SIEM Beat

Initialize the Beat

  1. Execute the following command to begin configuring the Mimecast SIEM Beat:

    CODE
    ./lrctl mimecastsiembeat start
  2. From the options presented, select New mimecastsiembeat instance and press Enter.

  1. Provide a unique identifier for this Beat instance.

    image-20250611-125731.png
  2. Enter the Base URL for Mimecast configuration.
    The default URL is displayed; modify it if necessary.

    image-20250611-130150.png
  3. Input the Client ID for Mimecast configuration.
    The Client ID was obtained during the steps outlined in Create a Mimecast API Application and Enable SIEM Logs.

    image-20250611-130709.png
  4. Enter the Client Secret for Mimecast configuration.
    The Client Secret was obtained during the steps outlined in Create a Mimecast API Application and Enable SIEM Logs.

    image-20250611-131009.png
  5. Specify the Log Type.
    All 10 types of logs are displayed by default. To fetch all types, simply press Enter, or remove specific types from the list to target particular data.

    image-20250611-214715.png
  6. Enter the page size to retrieve logs in a single request.
    The default value is 100, with a minimum of 1 and a maximum of 100.

    image-20250612-134900.png
  7. Indicate the number of days of logs to retrieve.
    The default setting is 7 days, with a minimum of 1 day and a maximum of 7 days.

    image-20250611-131326.png
  8. Enter the time interval after which the Beat will attempt to retrieve data.
    The default setting is 60 seconds.

    image-20250611-215118.png
  9. Enter the hostname or IP address of the machine where version Sysmon JSON Parser version 7.21 or greater is installed.

    image-20250625-100120.png
  10. Enter the port for data transmission.
    The default is pre-populated as 5044.

    image-20250625-100201.png
  11. Press Enter.
    The configuration has been saved, and the service has started successfully.

  12. To check the status of the service, run the following command:

    CODE
    ./lrctl mimecastsiembeat status

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.