Log source
AvailableWazuh
By Wazuh
Imports a customer's own Wazuh deployment — agent inventory from the Wazuh Manager API and rule-engine alerts from the Wazuh Indexer — into the Qorionix SIEM incident queue. Read-only: does not change agent configuration, rules or manager state.
What you can connect
Capabilities and availability
Each capability has its own setup and status. Review the details before enabling it for your organisation.
cloud alerts
AvailableSetup available in the console
More in Log source
Log source
HTTP Event Collector (Splunk-compatible)
A token-authenticated HTTP endpoint in the Splunk HEC shape. Anything that can POST JSON or raw lines with a token header can send logs: Splunk forwarders, Fluent Bit, Vector, the Docker splunk log driver and most SaaS log exporters.
Log source
Linux auditd
Authentication, privilege and process audit records from the Linux audit daemon, forwarded over syslog and parsed with the auditd parser.
Log source
Syslog (any firewall, switch or server)
Almost every firewall, switch, router, NAS and Linux server can send syslog. Events arrive over TLS or TCP, are parsed and stored as OCSF, and are searchable at once.