Start with SIEM: trial, activation, and your first logs
From zero to searchable logs in about ten minutes — usually with nothing to install.
- 1Open the SIEM portal (the SIEM Dashboard tab at the top of your dashboard) and go to Settings. Start the 14-day free trial on Starter, Growth, or Pro — a card is required but nothing is charged until day 14, and canceling before then costs nothing — or buy any plan outright, billed from day one. The trial runs at the limits of the tier you pick and converts to it automatically.
- 2If your devices already run the Cybermatic Device Agent, you're done installing: within one agent check-in, log collection switches on automatically and each device appears on the Log Sources page. The agents collect curated security events — sign-ins, privilege changes, service installs, suspicious processes — not a noisy firehose.
- 3New devices: install the Device Agent exactly as for Security Posture Management (Settings → Device agents). One agent does both jobs.
- 4Network devices that can't run an agent — firewalls, switches, NAS — send syslog to your Cybermatic Discovery Agent instead: see the syslog guide below.
- 5Within minutes you can Search your logs, and the built-in detection pack (29 rules) starts raising Alerts, which group into Offenses per machine or account. Ask Cybermatic Copilot in the SIEM portal to explain anything it finds.
Tip: Every plan includes unlimited log sources — connect everything. The GB/day allowance is the only meter, and bursts to 3× are absorbed free.