Elastic integrations

Stream in logs, metrics, traces, content, and more from your apps, endpoints, infrastructure, cloud, network, workplace tools, and every other common source in your ecosystem. Send alerts to your notification tool of choice. Connect to all the systems that matter with ease.

icon-magnifying-glass

ActiveMQ
Aerospike
Airflow
Akamai
Amazon Bedrock
Amazon CloudFront
Amazon CloudWatch
Amazon DynamoDB
Amazon EBS
Amazon Kinesis Data Firehose
Amazon RDS
Amazon Redshift
Amazon S3 Storage Lens
Amazon SNS
Amazon SQS
Amazon VPC
Amazon VPC NAT Gateway
Apache Spark
Apache Tomcat
AWS API Gateway
AWS Billing
AWS CloudTrail
AWS Elastic Load Balancing
AWS Fargate
AWS Lambda
AWS Network Firewall
AWS Transit Gateway
AWS Usage
AWS VPN
Azure Activity Logs
Azure App Service
Azure Application Gateway
Azure Application Insights
Azure Application State Insights
Azure Audit Logs
Azure Billing
Azure Container Instance
Azure Container Registry
Azure Container Service
Azure Database Account
Azure Event Hub
Azure Functions
Azure Monitor
Azure OpenAI
Azure Platform
Azure Spring Cloud
Azure Storage Account
Azure VM
Azure VM Scale Sets
Beats
Cisco IOS
Citrix ADC
Cloud Foundry
CockroachDB
collectd
Couchbase
Cribl
Custom Windows event logs
Customized Connector
Dropwizard
Elastic Agent
Elastic APM Server
Elasticsearch
Email
Fleet Server
Fluentd
GCP Metrics Input
GCP Vertex AI
Go Expvar
Google Cloud
Google Cloud Anthos
Google Cloud Billing
Google Cloud Compute
Google Cloud Dataproc
Google Cloud DNS
Google Cloud Firestore
Google Cloud Firewall
Google Cloud Functions
Google Cloud GKE
Google Cloud Load Balancing
Google Cloud Pub/Sub
Google Cloud Redis
Google Cloud Stackdriver
Google Cloud Storage
Google Cloud VPC
Google CloudSQL Metrics
Graphite
HA-Proxy
HTTP Check
IBM Websphere
Icinga
ICMP Check
InfluxDB
iptables
Jaeger
JavaScript
JMX Jolokia
journald
Kubernetes API Server
Kubernetes Controller Manager
Kubernetes Events
Kubernetes Metrics Service
Kubernetes Proxy
Kubernetes Scheduler
Linux
Linux systemd journals
Log files (Generic)
Logstash
Malware Information Sharing Platform (MISP)
Memcached
Microsoft 365 (Office 365) & OneDrive
Microsoft Entra ID
Microsoft SQL Server
ModSecurity
MQTT
Munin
Nagios XI
NATS Streaming
NetFlow
OpenMetrics
OpenTelemetry
OpenTracing
OpsGenie
Oracle Weblogic
Osquery Log Collection
Osquery Manager
PagerDuty
Pensando
PHP FPM
Prometheus
Prometheus Input
Redis Enterprise
Salesforce
ServiceNow ITOM
ServiceNow ITSM
SNMP
Snyk
Spring Boot
SQL Input
StatsD
syslog
TCP Check
Tomcat NetWitness Logs
Twitter
Universal Profiling
Web Crawler
Webhook
X.509 SSL/TLS Certificate Check
xMatters
Zeek (Bro)
ZooKeeper
1Password
Abnormal Security
Abuse.ch Malware & URL Threat Intel
Active Directory Entity Analytics
AlienVault Open Threat Exchange (OTX)
Amazon GuardDuty
Amazon Security Lake
Anomali ThreatStream
Arista Firewall
Atlassian Confluence
Atlassian Jira
auditd
Auditd Manager
Authentik
AWS Inspector
AWS Security Hub
AWS WAF
Azure Blob Storage
Azure Firewall
Azure Front Door
Azure Network Watcher
Azure WAF
Barracuda CloudGen Firewall
Barracuda WAF
Bitbucket
BitDefender
Bitwarden
blacklens.io
Box Events
Bravura Monitor
Broadcom ProxySG
Check Point Email & Collaboration
Check Point Firewall
Check Point Harmony Endpoint
Cilium Tetragon
CISA Known Exploited Vulnerabilities
Cisco Aironet
Cisco ASA
Cisco Duo
Cisco Firepower Threat Defense
Cisco Identity Services Engine (ISE)
Cisco Meraki
Cisco Nexus
Cisco Secure Email Gateway
Cisco Secure Endpoint
Cisco Umbrella
Citrix Web Application Firewall
Claroty CTD
Cloudflare
Collective Intelligence Framework
Common Event Format (CEF)
Confluence Cloud
Confluence Data Center
Confluence Server
Corelight
CrowdStrike Falcon
CrowdStrike Falcon Intelligence
Custom Threat Intelligence
CyberArk EPM
CyberArk Privileged Access Security
CyberArk Privileged Threat Analytics
Cybereason
Darktrace
Data Exfiltration Detection
Digital Guardian
Dropbox
Dropbox Paper
Endpoint Security
ESET Protect
ESET Threat Intelligence
F5 BIG-IP
F5 BIG-IP Access Policy Manager
Falco
File Integrity Monitoring
FireEye Network Security
First EPSS
Forcepoint
Forcepoint Web Security
ForgeRock
Fortinet Forticlient Endpoint Protection
Fortinet FortiEDR
Fortinet Fortigate
Fortinet FortiMail
Fortinet FortiManager
Fortinet FortiProxy
Gigamon
Gitlab
Gmail
GoFlow2
Google Cloud Audit
Google Drive
Google Santa
Google Security Command Center
Google Workspace
GraphQL
Hashicorp Vault
IBM Resilient
Imperva Cloud WAF
Imperva WAF
Infoblox BloxOne DDI
Infoblox NIOS
Jamf Compliance Reporter
Jamf Pro
Jamf Protect
Jira Cloud
JIRA Data Center
Jira Server
JMS
JumpCloud
Juniper SRX Series
Keycloak
LastPass
Linux Audit Framework
LotL Attack Detection
Lumos
Lyve Cloud
Mandiant Advantage
Menlo Security
Microsoft 365 Defender
Microsoft Defender for Cloud
Microsoft Defender for Endpoint
Microsoft DHCP Server
Microsoft DNS Server
Microsoft Exchange Message Trace
Microsoft Exchange Server
Microsoft Graph Activity
Microsoft OneDrive
Microsoft Outlook
Microsoft Sentinel
Microsoft Teams
Mimecast
Netscout Arbor Sightline
Netskope
Network Drive & File Systems
Network Packet Capture
NGINX Ingress Controller
Notion
Okta
Okta Entity Analytics
OpenCanary
OpenCTI
Palo Alto Cortex XDR
Palo Alto Networks
Palo Alto Prisma Access
Palo Alto Prisma Cloud
pfSense
Ping Federate
Ping Identity PingOne
Pleasant Password Server
PowerShell
Prebuilt Security Detection Rules
Proofpoint OnDemand
Proofpoint Targeted Attack Protection (TAP)
QNAP NAS
Qualys VMDR
Radware DefensePro
Rapid7 InsightVM
Rapid7 Threat Command
Recorded Future
Salesforce Sandboxes
SentinelOne
SentinelOne Cloud Funnel
ServiceNow SecOps
SharePoint Online
SharePoint Server
Snort
Sonicwall Firewall
Sophos Central
Sophos UTM
Sophos XG Firewall
SpyCloud
Squid Proxy
Stormshield Network Security
Sublime Security
Suricata
Swimlane SOAR
Symantec Endpoint Protection
Sysdig
Sysmon
Sysmon for Linux
System Audit
Tanium
Teleport
Tenable Security Center
Tenable Vulnerability Management
ThreatConnect
ThreatQuotient
Thycotic Secret Server
Trellix EDR Cloud
Trellix ePO
Trend Micro Deep Security
Trend Vision One
Tychon
Vectra Detect
VMware Carbon Black Cloud
VMware Carbon Black EDR
WatchGuard Firebox
Wiz
Zero Networks
ZeroFox
Zscaler Internet Access
Zscaler Private Access