How to Forward HPE Morpheus Audit Logs to a SIEM Using Dual Log Sources
HPE Morpheus Enterprise uses two separate internal loggers — AuditLogService and ActivityService — that capture different aspects of system activity, and both are needed for complete audit coverage in a SIEM. AuditLogService records HTTP controller-level actions such as logins and API calls, including source IP addresses, while ActivityService tracks object-level changes like provisioning and backups but without source IP data. Neither log alone provides a full picture of security-relevant events, such as privileged user creation, making a two-feed setup necessary for effective correlation rules. The working configuration forwards both logs to a SIEM as CEF over syslog using rsyslog file-tailing, with no plugins, scheduled jobs, or API polling required. The setup has been tested on Morpheus versions 8.1.x and 9.0.x running on RHEL 8, with logs forwarded into IBM QRadar.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in