Log source
AvailableHTTP Event Collector (Splunk-compatible)
By Splunk forwarders, Fluent Bit, Vector, Docker
A token-authenticated HTTP endpoint in the Splunk HEC shape. Anything that can POST JSON or raw lines with a token header can send logs: Splunk forwarders, Fluent Bit, Vector, the Docker splunk log driver and most SaaS log exporters.
What you can connect
Capabilities and availability
Each capability has its own setup and status. Review the details before enabling it for your organisation.
Log collection
AvailableSetup available in the console
More in Log source
Log source
Linux auditd
Authentication, privilege and process audit records from the Linux audit daemon, forwarded over syslog and parsed with the auditd parser.
Log source
Syslog (any firewall, switch or server)
Almost every firewall, switch, router, NAS and Linux server can send syslog. Events arrive over TLS or TCP, are parsed and stored as OCSF, and are searchable at once.
Log source
Windows servers and PCs
Sign-ins, privilege use and process starts from Windows machines running the Qorionix sensor, parsed from the Security event log into named fields (logon, account change, process creation).