Security Events Export (SEE)
4 min read
Table of contents
Overview
Security Events Export (SEE) gives your security team near-real-time access to security and audit events from your dedicated Unique environment. Unique streams these events into an Azure Event Hub in your single-tenant subscription.
Your Security Operations Center (SOC) reads the events from this Event Hub with your own SIEM, for example Microsoft Sentinel or Splunk.
Each client has their own dedicated Azure subscription and their own dedicated Event Hub. No data crosses tenant boundaries. Access is possible only with the connection data that Unique issues for your environment.
Availability
SEE is available only for Single-Tenant SaaS clients. Multi-Tenant SaaS clients must transition to a single-tenant hosting model to use SEE. Self-hosted clients establish their own event drainage and do not use SEE.
SEE covers subscription-level and resource-level events of your dedicated environment. Tenant-level events, for example Entra ID sign-in and audit logs, are monitored centrally by the Unique Security Operations Center. They are not part of SEE.
What SEE delivers
SEE exports two event categories:
Microsoft Defender for Cloud alerts. Security alerts from the Defender workload protection plans in your subscription. Reference: Defender security alerts.
Azure Activity Log. The control-plane log of your subscription. It records management operations, for example resource changes, policy assignments, role assignments, and Privileged Identity Management (PIM) activations by Unique staff in your environment. Reference: Azure Activity Log.
Properties of the delivery:
Events arrive in the native Azure JSON schema, without transformation. Each Event Hub message contains a
recordsarray.Both event categories stream into one Event Hub. Your SIEM filters and routes the records.
The Event Hub keeps events for 7 days. Your consumer can replay events in this window.
Delivery is near real time. The latency depends on the Azure export pipelines and is typically some minutes.
More event types, filtering, schema transformation, private networking, and alternative destinations are not part of the standard offering. Unique treats such requests as consulting work with separate scope and cost.
What Unique needs from you
Give Unique this information before the setup:
SIEM target. Microsoft Sentinel, Splunk, or an other Azure Event-Hub-capable consumer.
Region. The region of your Sentinel Log Analytics workspace, if applicable. Unique provisions the Event Hub in the same region. With this information you authorize Unique to store the exported events in that region.
Target environments. The Unique environments that need the export, for example prod or test. Azure consumption cost applies per environment.
A recipient for the credentials. Unique shares credentials through a one-time 1Password link. Name the recipient by email and full name.
The connection to the Event Hub goes over the public internet with TLS. The Event Hub endpoint is separate from the application ingress.
IP Access restrictions on the application do not apply to the Event Hub endpoint.
On request, Unique restricts the Event Hub endpoint to an IP allow-list. You must provide the static egress IP ranges of your SIEM and keep the list current. Consumers without static egress IPs, for example Consumption Logic Apps or some Splunk Cloud stacks, are not a good fit for an allow-list. Private endpoints and network peerings are not part of the standard offering.
What you get from Unique
Unique provides:
This documentation.
The Event Hub connection data: the namespace hostname, the Event Hub name, and a dedicated consumer group for your SIEM.
Credentials that match your SIEM, delivered through a one-time 1Password link. Treat them as secret:
For Microsoft Sentinel: a listen-only connection string for the Event Hub.
For Splunk: the
Tenant ID,Client ID, and client secret of a Microsoft Entra application. The application holds read access to your Event Hub namespace only.
Connect your SIEM
Unique provides step-by-step guides for the two validated consumers:
Setup with Microsoft Sentinel
Setup with Splunk
Other Event-Hub-capable consumers can work, but Unique has not validated them.
Connection test
After the setup, Unique and your team do a connection test together. Unique generates a set of sample alerts in Microsoft Defender for Cloud. The sample alerts refer to simulated resources and are safe. Your team confirms that the alerts arrive in your SIEM. This completes the initial connection.
Cost
The export runs on Azure resources in your dedicated subscription. Azure bills these resources on consumption. Unique forwards this consumption on your regular environment Azure bill, without markup.
For the standard setup, the observed cost is in the range of CHF 20 to 50 per month per environment. The cost depends on the event volume of your environment. No volume customization is available in the standard offering.
Responsibilities
Activity | Unique | Client (SOC / Cloud team) |
|---|---|---|
Event Hub provisioning (namespace, hubs, access policies) | A/R | C |
Continuous export of the supported event types | A/R | C |
Ingestion from the Event Hub into the SIEM | A/R | |
Secure storage of the credentials | A/R | |
Monitoring of ingestion health and message delivery | C | A/R |
Communication of export degradation, for example a broken pipeline | C/I | A/R |
Triage and investigation of exported events | I | A/R |
Triage of tenant-level events | A/R | I (when your environment is affected) |
Support and scope
Unique Engineering is available for the initial connection at the agreed rate. Later changes go through Unique Enterprise Support. Scope changes and new requirements are handled as separate estimates/offerings under the contracted day rate.