300+ integrations. Any device, any format.
Firewalls, endpoints, identity, cloud, network and applications. Every source is read into one standard format, so a detection written once works across your whole estate.
Getting connected.
A device is on the platform the day you point it at us.
- Step 1Point your deviceSend its logs to the Sidecar inside your network
- Step 2Read on arrivalA built-in parser maps it to one standard format
- Step 3Detection startsThe detectors read the new source on their next pass
Built-in parsers, by category.
The sources we read out of the box, by category. Ask us about any device not listed here.
Firewalls 22
- Stormshield SNS
- Cisco ASA
- Cisco FTD
- OPNsense
- FortiGate
- Palo Alto NGFW
- Check Point
- Sophos XGS
- Juniper SRX
- WatchGuard
- SonicWall
- Meraki MX
- Barracuda
- Huawei USG
- H3C SecPath
- Clavister cOS Core
- Hillstone
- Forcepoint NGFW
- Zyxel USG FLEX
- MikroTik RouterOS
- Arista NG Firewall
- Netgate TNSR
Endpoints 22
- Windows Event Log
- Linux Syslog
- CrowdStrike Falcon
- SentinelOne
- Microsoft Defender
- Carbon Black
- Trend Micro
- ESET
- Kaspersky
- Bitdefender
- Malwarebytes
- Symantec
- Sophos Intercept X
- Trellix ENS
- Cortex XDR
- Cisco Secure Endpoint
- Elastic Endpoint
- Wazuh
- Tanium
- Ivanti Endpoint
- Qualys Cloud Agent
- Rapid7 Insight Agent
Identity 19
- Active Directory
- Microsoft Entra ID
- Okta
- CyberArk PAM
- Wallix Bastion
- Ping Identity
- Duo Security
- OneLogin
- JumpCloud
- LDAP
- RADIUS
- Thales
- Keycloak
- FreeIPA
- Google Cloud Identity
- BeyondTrust
- Delinea Secret Server
- HashiCorp Vault
- SailPoint
Cloud 21
- AWS CloudTrail
- AWS CloudWatch
- AWS WAF
- Azure Monitor
- Azure WAF
- GCP Audit Logs
- Google Workspace
- Cloudflare
- Zscaler
- Netskope
- Microsoft 365
- Azure Activity Log
- AWS GuardDuty
- AWS Security Hub
- AWS VPC Flow Logs
- GCP Security Command Center
- Oracle Cloud Audit
- IBM Cloud Activity Tracker
- Kubernetes Audit
- OpenStack
- Proxmox VE
Network 24
- HAProxy
- NGINX
- Apache
- F5 BIG-IP
- Citrix NetScaler
- Cisco ISE
- Aruba ClearPass
- Darktrace
- ExtraHop
- Vectra AI
- Snort
- Suricata
- Zeek
- Cisco Catalyst
- Aruba Switch
- HP ProCurve
- Juniper EX
- Ubiquiti UniFi
- FortiSwitch
- Prisma Access
- Infoblox
- BlueCat
- TippingPoint SMS
- Cisco Umbrella
WAAP and NDR 10
- UBIKA WAAP
- Gatewatcher Aioniq
- Gatewatcher Trackwatch
- Imperva WAF
- F5 Advanced WAF
- Akamai App & API Protector
- ModSecurity
- Corelight
- Stamus Networks
- Fidelis Network
Applications 16
- ServiceNow
- Jira
- Confluence
- Slack
- Microsoft Teams
- SAP
- Oracle EBS
- Salesforce
- GitHub
- GitLab
- Bitbucket
- Jenkins
- Nextcloud
- Zoom
- SharePoint
- Exchange Server
Databases 12
- MySQL
- PostgreSQL
- Oracle DB
- Microsoft SQL Server
- MongoDB
- Redis
- Elasticsearch
- MariaDB
- Cassandra
- IBM Db2
- Couchbase
- Neo4j
One format means one detection for every vendor.
Every event is written in OCSF, an open security data standard. A rule for failed logins works the same on a Fortinet firewall and a Windows server, and your data stays portable to any OCSF tool.
Can't see your device? Use Parser Lab.
Custom and in-house formats get a parser too.
- Step 1Paste a sampleParser Lab reads the shape of your log line
- Step 2Check the mappingSee which standard field each part lands in before saving
- Step 3Go liveThe new parser takes effect without a restart
Point a device at us and watch it arrive.
60-day full-platform trial. No credit card. No inbound firewall changes. Live in under an hour.