Security information and event management (SIEM)

Overview

Sitefinity Cloud includes a security information and event management (SIEM) solution out of the box. The Sitefinity Cloud SIEM solution is based on Microsoft Azure Sentinel and offers real-time monitoring and analysis of events as well as tracking and logging of security data for compliance or auditing purposes.

Use SIEM out of the box

Every Sitefinity Cloud subscription is equipped with Azure Sentinel solution instance that inspects the log analytics workspace used to gather the logs from various infrastructure components. SIEM improves security by proactively inspecting large volumes of raw logs that are otherwise difficult to go through and extract the valuable security information.
Analytics rules are enabled for Sitefinity web applications and for the relevant Sitefinity Cloud infrastructure to help raise alerts and create incidents in real time for the Sitefinity Cloud Engineering Team to address. Each alert type is classified by severity with potential high severity threats triggering a call to the Sitefinity Cloud On-Duty Team for immediate investigation.
High severity alerts are treated like incidents and are handled via the incident handling process.
For more information about this process, see Sitefinity Cloud Support Workflow.

Use Advanced Security and Compliance add-on

The Advanced Security and Compliance add-on for Sitefinity Cloud includes additional SIEM rules based on HTTP logs plus more advanced features.
For more information about the benefits of this add-on, see Advanced Security and Compliance.

Was this article helpful?