Skip to main content

System Integrations


Cyber Incident Monitoring Integration Procedure

Go to > Cyber Incident Monitoring

Microsoft 365

Microsoft Office 365 integration currently supports user, admin, system, and policy actions...

GitHub

Introduction  The GitHub integration collects events from the GitHub API.  https://docs.g...

Add Windows Integrations

Introduction  The Windows integration allows you to monitor the Windows OS, services, applicatio...

Sysmon for Linux

Introduction  The Sysmon for Linux integration allows you to monitor the Sysmon for Linux, which...

1 Password Integrations

Introduction  With 1Password Business, you can send your account activity to your security infor...

Atlassian Bitbucket Integrations

Introduction  The Bitbucket integration collects audit logs from the audit log files or the audi...

AWS Cloudtrails Integrations

Introduction  The AWS CloudTrail integration allows you to monitor AWS CloudTrail  Reference: h...

AWS GuardDuty Integrations

Introduction  The Amazon GuardDuty integration collects and parses data from Amazon GuardDuty Fi...

AWS Security Hub Integrations

Introduction  The AWS Security Hub integration collects and parses data from AWS Security Hub RE...

AWS Integrations

Introduction  This document shows information related to AWS Integration.   The AWS integration...

CISCO Meraki Integrations

Introduction  Cisco Meraki offers a centralized cloud management platform for all Meraki devices...

CISCO Secure Endpoint Integrations

Introduction  Secure Endpoint offers cloud-delivered, advanced endpoint detection and response a...

CISCO Umbrella Integrations

Introduction  Cisco Umbrella is a cloud security platform that provides an additional line of de...

Cloudflare Integration

Introduction  Cloudflare integration uses Cloudflare's API to retrieve audit logs and traffic lo...

Crowdstrike Integrations

Introduction  This integration is for CrowdStrike products. It includes the following datasets f...

Dropbox Integrations

Introduction  Connecting Dropbox  Use the Workplace Search Dropbox connector to automatically c...

F5 Integrations

Introduction  This document shows information related to F5 Integration.   The F5 BIG-IP integr...

Fortinet-Fortigate Integrations

Introduction  This integration is for Fortinet FortiGate logs sent in the syslog format.  Pre...

GCP Integrations

Introduction  This document shows information related to GCP Integration.   The Google Cloud in...

GitLab Integrations

Introduction  Introduced in GitLab Starter 8.4. Support for Amazon Elasticsearch was introduced ...

Google Workspace Integrations

Introduction  Google Workspace (formerly G Suite) is a suite of cloud computing, productivity an...

Jumpcloud Integrations

Introduction  The JumpCloud integration allows you to monitor events related to the JumpCloud Di...

Mimecast Integrations

Introduction  The Mimecast integration collects events from the Mimecast API.  Assumpti...

MongoDB Integrations

Introduction  This integration is used to fetch logs and metrics from MongoDB.  Assumpt...

OKTA Integrations

Introduction  The Okta integration collects events from the Okta API, specifically reading from ...

Pulse Connect Secure Integrations

Introduction  This integration is for Pulse Connect Secure.  https://www.ivanti.com/pro...

Slack Integrations

Introduction  Slack is used by numerous organizations as their primary chat and collaboration to...

System Integrations

Introduction  The System integration allows you to monitor servers, personal computers, and more...

Team Viewer Integrations

Remote File Copy via TeamViewer   Identifies an executable or script file remotely downloaded vi...

Z Scaler Integrations

Introduction  This integration is for Zscaler Internet Access logs. It can be used to receive lo...

gcp

Google Cloud Platform Elastic Agent Version 2.33.2 Agent ...

VMware vSphere Integration

This integration periodically fetches logs and metrics from vSphere vCenter servers.   Compatibi...

SentinelOne Integrations

The SentinelOne integration collects and parses data from SentinelOne REST APIs. This integration...

Custom Windows Event Logs - Integration

Custom Windows Event Logs Collect and parse logs from any Windows event log channel with Elastic...

Windows Event Forwarding to Linux server using Nxlog

Introduction Windows Event Forwarding (WEF) allows the collection of event logs from multiple Wi...

Windows Event Forwarding to Linux server using Powershell script

Overview This PowerShell script forwards Windows event logs to a Linux server using the syslog p...

Sophos Integration

Overview The Sophos Central integration allows you to monitor Alerts and Events logs. Sophos Cen...

Atlassian Bitbucket Integrations (New)

Introduction  The Bitbucket integration collects audit logs from the audit log files or the audi...

Palo Alto Cortex XDR Integration

Palo Alto Cortex XDR Integration Using the Cortex XDR APIs, you can integrate Cortex XDR with th...

Active Directory Integrations

Introduction  Elastic Stack security features can be configured to authenticate users through Ac...

Microsoft SQL Server Integration

The Microsoft SQL Server integration package allows you to search, observe, and visualize the SQL...

Azure Logs Integration

Introduction This document shows information related to Azure Active Directory Integration.The A...

ESET Protect Integration

ESET PROTECT allows you to efficiently manage ESET products across workstations and servers withi...

ESET Threat Intelligence Integrations

ESET Threat Intelligence provides advanced, real-time insights into global cybersecurity threats,...

CSPM for Azure Integration

This manual explains how to get started monitoring the security posture of your Azure CSP using t...

Resource Manager Endpoint Integration

The Azure Resource Manager (ARM) endpoint is the primary entry point for interacting with the Azu...

CISCO Secure Email Gateway Integrations

The Cisco Email Security Appliance (ESA) integration is a comprehensive solution for managing and...

CISCO Nexus Integrations

Overview The Cisco Nexus integration allows users to monitor Errors and System Messages. The Cis...

BitDefender Integrations

BitDefender GravityZone supports SIEM integration using "push notifications", which are JSON mess...

Bitwarden Integrations

Overview The Bitwarden integration allows users to monitor collections, events, groups, members ...

Forwarding logs from rsyslog client to a remote rsyslogs server

Introduction This guide will walk you through setting up Rsyslog for log forwarding between a cl...

New script for logs forwarding

# Define the syslog server IP address and port$syslogServerIP = "192.168.20.24"  # Replace with y...