Sublime Security Logs

Connecting Sublime Security logs in your Panther Console

Overview

Panther supports ingesting Sublime Security audit logs, messages with rule matches (also known as Message Events), and all messages in the Message Data Model (MDM) format into Panther via AWS S3.

How to onboard Sublime Security logs to Panther

Step 1: Create a Sublime Security log source in Panther

  1. In the left-hand navigation bar of your Panther Console, click Configure > Log Sources.

  2. Click Create New.

  3. Search for "Sublime Security," then click its tile.

  4. In the upper-right corner of the slide-out panel, click Start Setup. A page titled "Sublime Security" is shown. An arrow is drawn to the upper-right corner, to a button labeled "Start Setup."

Step 2: Export Sublime Security logs to S3

Panther-managed detections

See Panther-managed rules for Sublime Security in the panther-analysis GitHub repository.

Supported log types

Sublime.Audit

Sublime.MessageEvent

Sublime.MDM

Last updated

Was this helpful?