The Mimecast integration is available on our Enterprise and Advanced packages.
Prerequisites
Administrator access to the Mimecast Administration Console.
Enhanced Logging must be enabled for the log type you want to collect (MTA logs are currently supported for SIEM integration).
Enable Enhanced Logging (if not already enabled)
Log in to the Mimecast Administration Console.
Navigate to Administration > Account > Account Settings.
Select the Enhanced Logging section.
Enable the required log type(s).
Click Save.
Create an API Application and Service Account
Follow the official Mimecast guide to create an API application and associate it with a service account: Managing API Applications
The permission required for the Get SIEM Logs API is:
Gateway
Tracking
Read
Assign this permission to the service account you created.
Provide Your Credentials to Defense.com
Once the API application and service account are set up, securely share the following credentials with us. We recommend using https://onetimesecret.com/ to generate a secure, time-limited link and include that link in a new support ticket.
Application ID:
Application Key:
Service account email address:
Secret Key:
Next Steps
Once we receive your credentials, we’ll configure the integration on our side and confirm when Mimecast logs are successfully flowing into your Defense.com SIEM. If you have any questions during the process, please open a support ticket.
That's it! You've successfully integrated Mimecast 🎉
