Skip to main content

Responses are generated using AI and may contain mistakes.

CollectorsCloud Collectors Administration Guide

Configure the PingOne Identity Cloud Collector

The PingOne Identity cloud collector collects audit log events that include user-related activities, poll subscription, and system configuration changes. These logs provide visibility into identity-related threats, such as suspicious login attempts or unauthorized policy modifications.

Use the following steps to configure the PingOne Identity cloud collector.

  1. Before you configure the PingOne Identity Cloud Collector, ensure that you complete the prerequisites.

  2. Log in to the New-Scale Security Operations Platform with your registered credentials as an administrator.

  3. Navigate to Collectors > Cloud Collectors.

  4. Click New Collector.

  5. Click PingOne Identity.

  6. Enter the following information for the cloud collector.

    PinOne_Collector_configuration.png
    • NAME – Specify a name for the Cloud Collector.

    • ACCOUNT ID – Enter the account ID that you obtained while completing the prerequisites.

    • AUTHENTICATION – Select the authentication method OAuth2.

      • CLIENT ID – Enter the client ID that you obtained while completing the prerequisites.

      • CLIENT SECRET – Enter the client secret that you obtained while completing the prerequisites.

    • DATA SOURCES – Select the endpoints from which you want to collect data. Then enter the subscription ID for each of the endpoint that you select.

      The following table lists the audit source API and security events supported by the cloud collector.

      Audit Source: API

      Service or Module Covered

      Administrator login

      Provides admin login success and login failed events

      AD Connect

      Provides AD Connect connection and disconnection events from the PingOne for Enterprise hosts for a specific period

      Administrator activity

      • Provides admin events such as admin created, deleted, invitation mail sent and property updated

      • Provides application events such as app created, deleted, updated, added to group, removed from group

      • Provides group events such as group created or deleted

      • Provides updates in the authentication policy

      Ping ID administrative activity

      Provides events such as updates in general settings updated, changes in authentication properties and account updates

      Directory

      Provides user updates events such as delete, create, password changed, and password policy updates

      Provisioning

      Provides group updates events and user updates events

      SSO

      Provides SSO events such as init connection with SSO, successful connection, and failure of connection

      Ping ID

      Provides device events such as device paired or unpaired, and device wipe success or time out

      PingID SDK

      Provides PingID device user transactions during a particular period

      PingID SDK Administrative Activity

      Provides PingID device user transactions initiated by a PingID administrator during a particular period

      Table 2. Audit source API and security events supported by the collector


  7. (Optional) SITE – Select an existing site or to create a new site with a unique ID, click manage your sites. Adding a site name helps you to ensure efficient management of environments with overlapping IP addresses.

    By entering a site name, you associate the logs with a specific independent site. A sitename metadata field is automatically added to all the events that are going to be ingested via this collector. For more information about Site Management, see Define a Unique Site Name.

  8. (Optional) TIMEZONE – Select a time zone applicable to you for accurate detections and event monitoring.

    By entering a time zone, you override the default log time zone. A timezone metadata field is automatically added to all events ingested through this collector.

    Timezone_sitename_site_management_1.png
  9. To confirm that the New-Scale Security Operations Platform communicates with the service, click Test Connection

  10. Click Install.

    AWS_S3_2.png

    A confirmation message informs you that the new Cloud Collector is created.