Integration: Kaseya SIEM and N-able N-Central

The Kaseya SIEM and N-able N-Central integration enables organizations to connect an N-Central instance to Kaseya SIEM using N-Central API credentials. Once connected, N-Central becomes available as an application within the organization and can be used with supported Kaseya SIEM workflows. If Unify functionality is configured, N-Central device data can also support Unify-related correlation workflows.

Prerequisites

Before configuring the integration, make sure the following requirements are met:

  • A role created in N-Central for the integration

  • An API-only N-Central user

  • A generated User-API Token (JWT)

  • Administrative access to Kaseya SIEM

If Unify functionality is being used, also configure a scheduled automation policy to populate the IPV4_PUB custom property.

If IP restrictions are configured in your firewall or in N-Central, allow the following IP addresses:

  • 35.192.223.4

  • 35.224.156.102

How to...

Troubleshooting

Unable to connect N-Central

Verify that:

  • The N-Central API information was entered correctly.

  • The JSON Web Token is valid.

  • The API-only user is assigned the correct role.

  • The role has the required read-only permissions.

  • Any firewall or product-level IP restrictions allow the required IP addresses.

Duplicate events or alerts appear

Verify that the same N-Central instance is not connected to multiple organizations. Connecting the same N-Central instance to multiple organizations can result in duplicate event and alert generation.

Public IP addresses are not populated

Verify that:

  • The IPV4_PUB custom property exists.

  • The automation policy is scheduled and enabled.

  • The automation policy targets the expected devices.

  • The selected devices have run the scheduled task.

Device information updates slowly

N-able rate limits may affect the ability to retrieve device information in environments with more than 5,000 devices. Symptoms may include slow updates to IP addresses or Entra Device IDs.

FAQ