300+ integrations. Any device, any format.

Firewalls, endpoints, identity, cloud, network and applications. Every source is read into one standard format, so a detection written once works across your whole estate.

GhostAnalyst reads 300+ sources across firewalls, endpoints, network and identity.

Getting connected.

A device is on the platform the day you point it at us.

  1. Step 1Point your deviceSend its logs to the Sidecar inside your network
  2. Step 2Read on arrivalA built-in parser maps it to one standard format
  3. Step 3Detection startsThe detectors read the new source on their next pass

Built-in parsers, by category.

The sources we read out of the box, by category. Ask us about any device not listed here.

Firewalls 22

  • Stormshield SNS
  • Cisco ASA
  • Cisco FTD
  • OPNsense
  • FortiGate
  • Palo Alto NGFW
  • Check Point
  • Sophos XGS
  • Juniper SRX
  • WatchGuard
  • SonicWall
  • Meraki MX
  • Barracuda
  • Huawei USG
  • H3C SecPath
  • Clavister cOS Core
  • Hillstone
  • Forcepoint NGFW
  • Zyxel USG FLEX
  • MikroTik RouterOS
  • Arista NG Firewall
  • Netgate TNSR

Endpoints 22

  • Windows Event Log
  • Linux Syslog
  • CrowdStrike Falcon
  • SentinelOne
  • Microsoft Defender
  • Carbon Black
  • Trend Micro
  • ESET
  • Kaspersky
  • Bitdefender
  • Malwarebytes
  • Symantec
  • Sophos Intercept X
  • Trellix ENS
  • Cortex XDR
  • Cisco Secure Endpoint
  • Elastic Endpoint
  • Wazuh
  • Tanium
  • Ivanti Endpoint
  • Qualys Cloud Agent
  • Rapid7 Insight Agent

Identity 19

  • Active Directory
  • Microsoft Entra ID
  • Okta
  • CyberArk PAM
  • Wallix Bastion
  • Ping Identity
  • Duo Security
  • OneLogin
  • JumpCloud
  • LDAP
  • RADIUS
  • Thales
  • Keycloak
  • FreeIPA
  • Google Cloud Identity
  • BeyondTrust
  • Delinea Secret Server
  • HashiCorp Vault
  • SailPoint

Cloud 21

  • AWS CloudTrail
  • AWS CloudWatch
  • AWS WAF
  • Azure Monitor
  • Azure WAF
  • GCP Audit Logs
  • Google Workspace
  • Cloudflare
  • Zscaler
  • Netskope
  • Microsoft 365
  • Azure Activity Log
  • AWS GuardDuty
  • AWS Security Hub
  • AWS VPC Flow Logs
  • GCP Security Command Center
  • Oracle Cloud Audit
  • IBM Cloud Activity Tracker
  • Kubernetes Audit
  • OpenStack
  • Proxmox VE

Network 24

  • HAProxy
  • NGINX
  • Apache
  • F5 BIG-IP
  • Citrix NetScaler
  • Cisco ISE
  • Aruba ClearPass
  • Darktrace
  • ExtraHop
  • Vectra AI
  • Snort
  • Suricata
  • Zeek
  • Cisco Catalyst
  • Aruba Switch
  • HP ProCurve
  • Juniper EX
  • Ubiquiti UniFi
  • FortiSwitch
  • Prisma Access
  • Infoblox
  • BlueCat
  • TippingPoint SMS
  • Cisco Umbrella

WAAP and NDR 10

  • UBIKA WAAP
  • Gatewatcher Aioniq
  • Gatewatcher Trackwatch
  • Imperva WAF
  • F5 Advanced WAF
  • Akamai App & API Protector
  • ModSecurity
  • Corelight
  • Stamus Networks
  • Fidelis Network

Applications 16

  • ServiceNow
  • Jira
  • Confluence
  • Slack
  • Microsoft Teams
  • SAP
  • Oracle EBS
  • Salesforce
  • GitHub
  • GitLab
  • Bitbucket
  • Jenkins
  • Nextcloud
  • Zoom
  • SharePoint
  • Exchange Server

Databases 12

  • MySQL
  • PostgreSQL
  • Oracle DB
  • Microsoft SQL Server
  • MongoDB
  • Redis
  • Elasticsearch
  • MariaDB
  • Cassandra
  • IBM Db2
  • Couchbase
  • Neo4j

One format means one detection for every vendor.

Every event is written in OCSF, an open security data standard. A rule for failed logins works the same on a Fortinet firewall and a Windows server, and your data stays portable to any OCSF tool.

Can't see your device? Use Parser Lab.

Custom and in-house formats get a parser too.

  1. Step 1Paste a sampleParser Lab reads the shape of your log line
  2. Step 2Check the mappingSee which standard field each part lands in before saving
  3. Step 3Go liveThe new parser takes effect without a restart

Point a device at us and watch it arrive.

60-day full-platform trial. No credit card. No inbound firewall changes. Live in under an hour.