Integrations And Data Sources
Integrations overview
LogSentinel SIEM can collect data from everywhere. The lists below include only the most popular vendors and products, but because of the flexibility of our collector, we can collect anything that generates logs:
- Syslog in any variation (RFC 3164, RFC 5424; CEF, LEEF)
- IPFIX/NetFlow
- Text files in any variation (comma-separated, tab separated, fixed length columns, access log format, Linux audit log, JSON, XML) accessed in any fashion (ssh, shared drives, local)
- Windows logs
- Database tables in any RDBMS and any structure
- Database-native audit logs for major vendors
- Cloud services with RESTful APIs
Cloud Integrations
| Source type | Sources |
|---|---|
| Infrastructure-as-a-Service (IaaS) | Amazon Web Services (AWS)Microsoft AzureGoogle Cloud Platform |
| Identity and access management (IAM) | OktaAzure ADCentrifyOneLoginPing |
| Office and Cloud Storage | Microsoft365 / Office365 / OneDriveGoogle Workplace (G Suite)/ Google DriveDropboxBox.com |
| General Software-as-a-Service (SaaS) | SalesforceHubSpotWorkdaySlackServiceNowAtlassian productsZendeskMailchimp |
| Web conferencing | ZoomWebExGoogle MeetMicrosoft Teams |
| Other | Any other cloud service exposing a RESTful API |
On-premise integrations
| Source type | Sources |
|---|---|
| Databases | OracleMicrosoft SQL ServerMySQLPostgreSQL |
| Firewalls | BarracudaCiscoFortinetForcepointGlassWireJuniperPalo AltopfSenseSophosSonicWallWatchGuardZScaler |
| Endpoint protection / antivirus | AvastBitDefenderCarbon BlackCisco AMPCrowdstrikeESETF-SecureFireEye Endpoint SecurityKasperskyMalwareBytesMcAfeeSentinelOneSophosSynantecTrendMicro |
| Web servers | ApacheNginxInternet Information ServicesApache TomcatJettyGlassFish |
| VPN | BarracudaCiscoCitrixOpenVPNF5 NetworksFortinetSonicWallJuniper Pulse |
| Identity and access management (IAM) | OpenAMKeycloakShibooleth IDPCASCentrifyPingRSA SecurID Access |
| Cloud access security broker (CASB) | BitglassForcepointImpervaNetskopeSymantec |
| Misc | ActiveDirectoryMicrosoft ExchangeMicrosoft DynamicsMicrosoft SharePointSAPVMWare vCenter/ESXIEpicKubernetes |
| Other | Any other application/service that has writes a log to syslog, text file, database or Windows log, or exposes it through RESTful API |
Interested in a SIEM Solution that combines log management, behavior analytics (UEBA), threat detection, and incident response into a complete security monitoring platform? Talk to us today!