As part of Security Information and Event Management (SIEM) from the Security Operations Center (SOC) environment, an interface is created that calls up the function for logging inconsistencies in user data in the central system for authentication and authorization for the existing users and stores the results in a central log database. A view is provided on this log database, which makes the log data available to the SIEM/SOC system.
Supplement
The interface is set up as a task in the task planning on the central application server. When the interface runs daily, a web service of the central authorization and authentication server calls up the existing data of all users to check for consistency and logs the results.
Subject description
The central system for authenticating and authorizing users is to be automatically monitored with regard to the consistency of user data, enabling inconsistencies to be detected at an early stage. The interface solution ensures that the data is checked regularly. The logged data is made available to the SOC / SIEM (Security Operations Center / Security Information and Event Management) monitoring system for further processing.