Elastic integrations

Stream in logs, metrics, traces, content, and more from your apps, endpoints, infrastructure, cloud, network, workplace tools, and every other common source in your ecosystem. Send alerts to your notification tool of choice. Connect to all the systems that matter with ease.

icon-magnifying-glass

1Password
Abnormal Security
Abuse.ch Malware & URL Threat Intel
Active Directory Entity Analytics
ActiveMQ
AlienVault Open Threat Exchange (OTX)
Amazon Bedrock
Amazon CloudWatch
Amazon GuardDuty
Amazon Security Lake
Amazon VPC
Anomali ThreatStream
Arista Firewall
auditd
Auditd Manager
Authentik
AWS CloudTrail
AWS Elastic Load Balancing
AWS Inspector
AWS Security Hub
AWS WAF
Azure Activity Logs
Azure Audit Logs
Azure Event Hub
Azure Firewall
Azure Front Door
Azure Network Watcher
Azure OpenAI
Azure WAF
Barracuda CloudGen Firewall
Barracuda WAF
Beats
BitDefender
Bitwarden
blacklens.io
Box Events
Bravura Monitor
Broadcom ProxySG
Check Point Email & Collaboration
Check Point Firewall
Check Point Harmony Endpoint
Cilium Tetragon
CISA Known Exploited Vulnerabilities
Cisco Aironet
Cisco ASA
Cisco Duo
Cisco Firepower Threat Defense
Cisco IOS
Cisco Meraki
Cisco Nexus
Cisco Secure Endpoint
Cisco Umbrella
Citrix ADC
Citrix Web Application Firewall
Claroty CTD
Cloudflare
Collective Intelligence Framework
Common Event Format (CEF)
Corelight
Cribl
CrowdStrike Falcon
CrowdStrike Falcon Intelligence
Custom Threat Intelligence
Custom Windows event logs
Customized Connector
CyberArk EPM
CyberArk Privileged Access Security
CyberArk Privileged Threat Analytics
Cybereason
Darktrace
Data Exfiltration Detection
Digital Guardian
Elastic Agent
Email
Endpoint Security
ESET Protect
ESET Threat Intelligence
F5 BIG-IP
F5 BIG-IP Access Policy Manager
Falco
FireEye Network Security
First EPSS
Fleet Server
Forcepoint
Forcepoint Web Security
ForgeRock
Fortinet Forticlient Endpoint Protection
Fortinet FortiEDR
Fortinet Fortigate
Fortinet FortiMail
Fortinet FortiManager
Fortinet FortiProxy
Gigamon
Gitlab
GoFlow2
Google Cloud
Google Cloud Anthos
Google Cloud Audit
Google Cloud Firewall
Google Cloud Pub/Sub
Google Cloud VPC
Google Santa
Google Security Command Center
Google Workspace
Hashicorp Vault
IBM Resilient
Icinga
Imperva Cloud WAF
Imperva WAF
Infoblox BloxOne DDI
Infoblox NIOS
iptables
Jamf Compliance Reporter
Jamf Pro
Jamf Protect
JumpCloud
Juniper SRX Series
Keycloak
LastPass
Linux Audit Framework
Linux systemd journals
Log files (Generic)
LotL Attack Detection
Lumos
Lyve Cloud
Malware Information Sharing Platform (MISP)
Mandiant Advantage
Menlo Security
Microsoft 365 (Office 365) & OneDrive
Microsoft 365 Defender
Microsoft Defender for Cloud
Microsoft Defender for Endpoint
Microsoft DHCP Server
Microsoft DNS Server
Microsoft Entra ID
Microsoft Exchange Message Trace
Microsoft Exchange Server
Microsoft Graph Activity
Microsoft Sentinel
Microsoft SQL Server
Microsoft Teams
NetFlow
Netscout Arbor Sightline
NGINX Ingress Controller
Okta
Okta Entity Analytics
OpenCanary
OpenCTI
Osquery Log Collection
Osquery Manager
PagerDuty
Palo Alto Cortex XDR
Palo Alto Networks
Palo Alto Prisma Access
Palo Alto Prisma Cloud
Pensando
pfSense
Ping Federate
Ping Identity PingOne
Pleasant Password Server
PowerShell
Prebuilt Security Detection Rules
Proofpoint OnDemand
Proofpoint Targeted Attack Protection (TAP)
Qualys VMDR
Radware DefensePro
Rapid7 InsightVM
Rapid7 Threat Command
Recorded Future
SentinelOne
SentinelOne Cloud Funnel
ServiceNow ITOM
ServiceNow ITSM
ServiceNow SecOps
SNMP
Snort
Snyk
Sonicwall Firewall
Sophos Central
Sophos UTM
Sophos XG Firewall
SpyCloud
Squid Proxy
Stormshield Network Security
Sublime Security
Suricata
Symantec Endpoint Protection
Sysdig
syslog
Sysmon
Sysmon for Linux
System Audit
Tanium
Teleport
Tenable Vulnerability Management
ThreatConnect
ThreatQuotient
Thycotic Secret Server
Tomcat NetWitness Logs
Trellix EDR Cloud
Trellix ePO
Trend Micro Deep Security
Trend Vision One
Tychon
Vectra Detect
VMware Carbon Black EDR
WatchGuard Firebox
Web Crawler
Webhook
Wiz
xMatters
Zeek (Bro)
Zero Networks
ZeroFox
Aerospike
Airflow
Akamai
Amazon CloudFront
Amazon DynamoDB
Amazon EBS
Amazon Kinesis Data Firehose
Amazon RDS
Amazon Redshift
Amazon S3 Storage Lens
Amazon SNS
Amazon SQS
Amazon VPC NAT Gateway
Apache Spark
Apache Tomcat
Atlassian Confluence
Atlassian Jira
AWS API Gateway
AWS Billing
AWS Fargate
AWS Lambda
AWS Network Firewall
AWS Transit Gateway
AWS Usage
AWS VPN
Azure App Service
Azure Application Gateway
Azure Application Insights
Azure Application State Insights
Azure Billing
Azure Blob Storage
Azure Container Instance
Azure Container Registry
Azure Container Service
Azure Database Account
Azure Functions
Azure Monitor
Azure Platform
Azure Spring Cloud
Azure Storage Account
Azure VM
Azure VM Scale Sets
Bitbucket
Cisco Identity Services Engine (ISE)
Cisco Secure Email Gateway
Cloud Foundry
CockroachDB
collectd
Confluence Cloud
Confluence Data Center
Confluence Server
Couchbase
Dropbox
Dropbox Paper
Dropwizard
Elastic APM Server
Elasticsearch
File Integrity Monitoring
Fluentd
GCP Metrics Input
GCP Vertex AI
Gmail
Go Expvar
Google Cloud Billing
Google Cloud Compute
Google Cloud Dataproc
Google Cloud DNS
Google Cloud Firestore
Google Cloud Functions
Google Cloud GKE
Google Cloud Load Balancing
Google Cloud Redis
Google Cloud Stackdriver
Google Cloud Storage
Google CloudSQL Metrics
Google Drive
Graphite
GraphQL
HA-Proxy
HTTP Check
IBM Websphere
ICMP Check
InfluxDB
Jaeger
JavaScript
Jira Cloud
JIRA Data Center
Jira Server
JMS
JMX Jolokia
journald
Kubernetes API Server
Kubernetes Controller Manager
Kubernetes Events
Kubernetes Metrics Service
Kubernetes Proxy
Kubernetes Scheduler
Linux
Logstash
Memcached
Microsoft OneDrive
Microsoft Outlook
Mimecast
ModSecurity
MQTT
Munin
Nagios XI
NATS Streaming
Netskope
Network Drive & File Systems
Network Packet Capture
Notion
OpenMetrics
OpenTelemetry
OpenTracing
OpsGenie
Oracle Weblogic
PHP FPM
Prometheus
Prometheus Input
QNAP NAS
Redis Enterprise
Salesforce
Salesforce Sandboxes
SharePoint Online
SharePoint Server
Spring Boot
SQL Input
StatsD
Swimlane SOAR
TCP Check
Tenable Security Center
Twitter
Universal Profiling
VMware Carbon Black Cloud
X.509 SSL/TLS Certificate Check
ZooKeeper
Zscaler Internet Access
Zscaler Private Access