Skip to main content

How to Integrate Mimecast

This guide outlines how to integrate Mimecast with Defense.com’s SIEM platform using the Get SIEM Logs API endpoint.

Written by Daniel Sampson
Updated today

The Mimecast integration is available on our Enterprise and Advanced packages.

Prerequisites

  • Administrator access to the Mimecast Administration Console.

  • Enhanced Logging must be enabled for the log type you want to collect (MTA logs are currently supported for SIEM integration).

Enable Enhanced Logging (if not already enabled)

  1. Log in to the Mimecast Administration Console.

  2. Navigate to Administration > Account > Account Settings.

  3. Select the Enhanced Logging section.

  4. Enable the required log type(s).

  5. Click Save.

Create an API Application and Service Account

  1. Follow the official Mimecast guide to create an API application and associate it with a service account: Managing API Applications

  2. The permission required for the Get SIEM Logs API is:

    1. Gateway

    2. Tracking

    3. Read

  3. Assign this permission to the service account you created.

Provide Your Credentials to Defense.com

Once the API application and service account are set up, securely share the following credentials with us. We recommend using https://onetimesecret.com/ to generate a secure, time-limited link and include that link in a new support ticket.

  • Application ID:

  • Application Key:

  • Service account email address:

  • Secret Key:

Next Steps

Once we receive your credentials, we’ll configure the integration on our side and confirm when Mimecast logs are successfully flowing into your Defense.com SIEM. If you have any questions during the process, please open a support ticket.

That's it! You've successfully integrated Mimecast 🎉

Did this answer your question?