Integrations

Agent DNS events in your SIEM

Syslog, CEF, JSON, API and signed webhooks.

Every resolution decision is an event. Each guide ends with the query that proves the data arrived.

Delivery methods

Five outbound methods and one inbound

Syslog forwarding

A host and port set in Settings. Events are forwarded in real time.

Continuous ingestion into any collector

CEF export

One API call with format=cef.

ArcSight, Sentinel via AMA, QRadar, backfill

JSON and CSV export

The same endpoint with format=json or csv. Exports can be scheduled and delivered by email.

Data lakes, notebooks, audits

API pull

Paginated logs endpoint, filterable by action and timeframe.

Custom pipelines, ad hoc pulls

Webhooks

Six signed events. Receivers verify X-Securd-Signature before processing.

SOAR, chat approvals, paging

IOC push (inbound)

API key with lists:write. Up to 1,000 entries per call, with expiry.

Blocking from your SOAR or SIEM

Evaluate Agent DNS with your own agent traffic

Forward events from a single policy to your SIEM and review them with your security team.