Integrations And Data Sources

Integrations overview

LogSentinel SIEM can collect data from everywhere. The lists below include only the most popular vendors and products, but because of the flexibility of our collector, we can collect anything that generates logs:

  • Syslog in any variation (RFC 3164, RFC 5424; CEF, LEEF)
  • IPFIX/NetFlow
  • Text files in any variation (comma-separated, tab separated, fixed length columns, access log format, Linux audit log, JSON, XML) accessed in any fashion (ssh, shared drives, local)
  • Windows logs
  • Database tables in any RDBMS and any structure
  • Database-native audit logs for major vendors
  • Cloud services with RESTful APIs

Cloud Integrations

Source typeSources
Infrastructure-as-a-Service (IaaS)Amazon Web Services (AWS)Microsoft AzureGoogle Cloud Platform
Identity and access management (IAM)OktaAzure ADCentrifyOneLoginPing
Office and Cloud StorageMicrosoft365 / Office365 / OneDriveGoogle Workplace (G Suite)/ Google DriveDropboxBox.com
General Software-as-a-Service (SaaS)SalesforceHubSpotWorkdaySlackServiceNowAtlassian productsZendeskMailchimp
Web conferencingZoomWebExGoogle MeetMicrosoft Teams
OtherAny other cloud service exposing a RESTful API

On-premise integrations

Source typeSources
DatabasesOracleMicrosoft SQL ServerMySQLPostgreSQL
FirewallsBarracudaCiscoFortinetForcepointGlassWireJuniperPalo AltopfSenseSophosSonicWallWatchGuardZScaler
Endpoint protection / antivirusAvastBitDefenderCarbon BlackCisco AMPCrowdstrikeESETF-SecureFireEye Endpoint SecurityKasperskyMalwareBytesMcAfeeSentinelOneSophosSynantecTrendMicro
Web serversApacheNginxInternet Information ServicesApache TomcatJettyGlassFish
VPNBarracudaCiscoCitrixOpenVPNF5 NetworksFortinetSonicWallJuniper Pulse
Identity and access management (IAM)OpenAMKeycloakShibooleth IDPCASCentrifyPingRSA SecurID Access
Cloud access security broker (CASB)BitglassForcepointImpervaNetskopeSymantec
MiscActiveDirectoryMicrosoft ExchangeMicrosoft DynamicsMicrosoft SharePointSAPVMWare vCenter/ESXIEpicKubernetes
OtherAny other application/service that has writes a log to syslog, text file, database or Windows log, or exposes it through RESTful API

Interested in a SIEM Solution that combines log management, behavior analytics (UEBA), threat detection, and incident response into a complete security monitoring platform? Talk to us today!