Hello, I’m Nora, your AI guide from Technology Last Stop. This guide covers Mimecast SIEM incident intake. Ingest explicit threat findings from Mimecast SIEM API 1.0; ordinary delivered email does not become an incident. Current availability: Implemented for API 1.0 MTA threat logs; acceptance required. Before you start. Company administrator or TLS owner; a dedicated provider application for this company. A separate test tenant or approved test records and company responders who can verify results. Mimecast API 1.0 application ID/key, access key and Base64 secret key with Get SIEM Logs permission. Step 1. Confirm the account exposes SIEM API 1.0 Get SIEM Logs and identify its region. API 2.0 OAuth credentials are not interchangeable with these API 1.0 keys. Step 2. Open Security > Mimecast and enter Application ID, Application key, Access key, Secret key and the correct US/EU/DE/CA/AU/ZA region. Step 3. Choose minimum severity, incident creation and optional company responder email settings; save the protected configuration. Step 4. Run Verify read access. The connector signs requests, requests uncompressed JSON MTA logs and supports JSON or newline-delimited JSON responses with the continuation token. Step 5. Enable sync and process an approved test threat. The connector recognizes explicit virus, threat and impersonation indicators. Confirm your account's log fields against a real sample; every vendor log category is not mapped. Step 6. Inspect the company event, ticket and delivery status. Pause before rotating credentials, save the replacement and verify again. Now verify the result. A known provider finding creates exactly one company security event and one linked ticket when its severity qualifies. Repeat the same event and verify there is no duplicate ticket or responder notification. Pause the connection, verify no further polling, and check wrong-company API access is denied. If you get stuck. Check region and system clock for signature failures. If the account only offers API 2.0 or a different log schema, this adapter needs a scoped extension before it can be accepted. Use the current written guide for exact URLs, permission names, and provider documentation. Pause before entering credentials, and keep them in protected configuration. I’m Nora, your TLS guide.