Material Security Logs
Connecting Material Security logs in your Panther Console
Last updated
Connecting Material Security logs in your Panther Console
Last updated
The Material Security log integration is in open beta starting with Panther version 1.110, and is available to all customers. Please share any bug reports and feature requests with your Panther support team.
Panther ingests Material Security logs by configuring an Event Subscription in Material to forward events to an HTTP endpoint in Panther.
Material Security is a unified email security, user behavior analytics, and data loss prevention solution for Microsoft 365 and Google Workspace.
To connect these logs into Panther:
In the left-hand navigation bar of your Panther Console, click Configure > Log Sources.
Click Create New.
Search for “Material Security,” then click its tile.
In the slide-out panel, click Start Setup.
Follow Panther's instructions for configuring an HTTP Source, beginning at Step 5.
In the Auth method dropdown field, select Bearer.
Payloads sent to this source are subject to the payload requirements for all HTTP sources.
Do not proceed to the next step until the creation of your HTTP endpoint has completed.
Log into your Material Security tenant.
In the upper-right corner click the puzzle piece (Integrations) icon.
From the left-hand navigation bar, select Events.
In the upper-right corner, click Create Subscription.
In the Create Subscription form, under Event and Notification Type, enter values for the following fields:
Event: Select New Case Created.
Notification Type: Select Webhook.
Subscription Name: Enter a short description.
Under Event-Specific Options, in the Case Source field, choose all applicable options.
Under Notification, enter values for the following fields:
HTTP Method: Select Method > POST.
URI: Enter the HTTP Source URL you generated in Panther in Step 1.
Under Headers, in the Headers field, add the bearer token you entered or generated in Panther in Step 1, for example: { "Authorization": "Bearer <token value>" }
.
In the top-right corner, click Save.