Five outbound methods and one inbound
Syslog forwarding
A host and port set in Settings. Events are forwarded in real time.
Continuous ingestion into any collector
CEF export
One API call with format=cef.
ArcSight, Sentinel via AMA, QRadar, backfill
JSON and CSV export
The same endpoint with format=json or csv. Exports can be scheduled and delivered by email.
Data lakes, notebooks, audits
API pull
Paginated logs endpoint, filterable by action and timeframe.
Custom pipelines, ad hoc pulls
Webhooks
Six signed events. Receivers verify X-Securd-Signature before processing.
SOAR, chat approvals, paging
IOC push (inbound)
API key with lists:write. Up to 1,000 entries per call, with expiry.
Blocking from your SOAR or SIEM
Splunk
Syslog input, CEF extractions, verification searches.
Syslog · CEF export · Webhooks
Microsoft Sentinel
CEF via AMA, KQL queries, analytics rule candidate.
Syslog (CEF) · CEF export
Elastic
Filebeat syslog input or JSON export into an index.
Syslog · JSON export
Datadog
Agent syslog pipeline, action facet, monitor.
Syslog · Webhooks
Google SecOps (Chronicle)
CEF through the forwarder, UDM mapping notes.
Syslog (CEF)
IBM QRadar
Syslog log source with the universal CEF DSM.
Syslog (CEF)
Sumo Logic
Syslog source on an installed collector.
Syslog
Evaluate Agent DNS with your own agent traffic
Forward events from a single policy to your SIEM and review them with your security team.