This procedure helps you to connect your CylanceENDPOINT via SIEM to the Expel Workbench. The procedure is to port in logs by creating a new Syslog source, configuring that source in Workbench, then configure your CylanceENDPOINT device in Workbench.


Some steps in this procedure vary greatly depending upon the SIEM-based technology you use.

Step 1: Logging CylanceENDPOINT to a desired SIEM

Refer to your SIEM documentation or work with your SIEM representative to port in CylanceENDPOINT logs. You can also refer to the following web references for creating a new Syslog source:

Step 2: Configure the SIEM in Workbench

This link opens the Expel Knowledge Base section for connecting SIEM-based technology to Workbench. Follow the applicable article to configure your SIEM-based tech and confirm that CylanceENDPOINT logs are flowing through and available.

Step 3: Configure CylanceENDPOINT via SIEM in Workbench

  1. In a new browser tab, go to

  2. Fill in the device fields like this:

    • SIEM, select the SIEM that was onboarded in Step 2.

    • For Name, type the host name of the CylanceENDPOINT device.

    • For Location, type the geographic location of the device

  3. Fill in the Connection Settings field based on the Sumo Logic SIEM you selected:

    • For Source category, type the Sumo Logic source category for this device.


This page was accurate at the time of writing, but changes happen. If you find the instructions are outdated, let us know via your engagement manager or account representative.