Skip to main content

Legacy Exabeam Site Collector GuideExabeam Site Collector Administration Guide (Legacy)

Exabeam Site Collector

The Exabeam Site Collector is an application that securely and efficiently uploads event data to Exabeam SaaS services in the Exabeam Security Operations Platform.

Exabeam Site Collector High-level Architecture
Figure 1. Exabeam Site Collector High-level Architecture


At a high level, the Exabeam Site Collector collects messages; transfers, persists, and uploads data; and connects to Exabeam Security Operations Platform.

The Exabeam Site Collector is the managed entry point for logs to be routed to other processing tools, such as Exabeam Advanced Analytics, Exabeam Data Lake, Exabeam Incident Responder, and Exabeam Case Manager in the Exabeam Security Management Platform. Site collectors gather logs from external servers, systems, data centers, or Exabeam collectors (including Windows, File, and GZip).

The site collector routes collected logs to the Exabeam Security Management Platform. The site collector continuously queues and uploads logs as well as manages the forwarding rate and message backlog. Data is encrypted and compressed in transmission and while at rest in the Exabeam Security Operations Platform. A persistent connection to the Exabeam Security Operations Platform allows the site collector to connect to your assets such as Active Directory for context and authentication, access API for log repositories, and any Incident Responder actions.

You can deploy multiple site collectors as your log volume and sources grow. You can deploy them in any network, data center or virtual private cloud (VPC) as required. All SaaS service log data is collected via API using the Exabeam Security Operations Platform. See Install Exabeam Site Collector for prerequisites and restrictions.

Important

For information on configuring agent-based or server-side collectors, refer to the Exabeam Data Lake Collector Guide