Supported Devices/Products Matrix

Data ingestion

The following matrix shows the products currently supported by Fluency SIEM, along with the type of data ingress/integration.

VendorProductAPIHttps (HEC)SyslogMiscDate Updated
AcronisCyber Protect CloudY*2023-Jul
AvatierAIMSY
AvananEmail Security* via AWS-S3
AWSCloudTrailY
CloudWatch LogsY
CloudWatch Metrics*PureCloudOps
BarracudaFirewallY
BitdefenderGravityZoneY*
BlackBerryCylancePROTECTY2023-Jul
BroadcomSymantec EPCY
CiscoASAY
AMPY
Defense Orch. (CDO)Y*
ISEY
FTD (Firepower)Y
MerakiY*Y
Umbrella(OpenDNS)Cisco-managed S3
CitrixNetScalerY2021-Oct
Check PointFirewall (NGFW)Y
SandblastY
CoroCybersecurityY2023-Sep
CrowdStrikeFalcon EDRY
DarktraceDarktraceY*
Digital DefenseFrontline VMY*
Duo SecurityAudit APIY
EdgeCastFirewall (CDN)* via AWS-S3
EclecticIQ-Y
FireEyeETP (email)Y
HX (endpoint)Y
FortinetFortiAnalyzerY
Fortigate NGFWY
Foritnet Cloud-
FrontlineVulnerability MgmtY*
GoogleG-Suite (Workspace)YAudit API
ImpervaIncapsulaY*via AWS-S3
InfobloxDNSY
LinuxSyslogYaudispd / sshd
dnsmasq (DNS)Yvia rsyslog
McAfeeWeb GatewayY
MVisionY*
ePOY
MicrosoftOffice365 (M365)YMultiple APIs
Azure EventHubY
Azure AD AuditY
DefenderYDefender Cloud / ATP
Windows EventLogY* via NXLog agent
Windows LDAP* requires local collector
MimecastEmail SecurityY
OktaAudit APIY
PaloAltoFirewall (NGFW)Y
Cortex XDRY
GlobalProtect VPNY
PeplinkRouter/FirewallY*Yw/ InControl API
Ping IdentityPingFederateY
ProofpointEmail SecurityY*
QualysCloud PlateformY*
SalesforceEvent MonitoringY*2023-Oct
SentinelOneEDRYY
CloudFunnel* via AWS-S32023-Jun
Ranger-
SeraphicBrowser SecurityY2023-Nov
SonicWallFirewall (NGFW)Y2022-Mar
SophosEDRY*
FirewallY2021-Dec
TainiumEndpoint SecurityY*
TenableVulnerability MgmtY*Tenable.io
TrellixEndpoint SecurityY*
Trend MicroApex CentralY
Deep SecurityY2022-Jan
Worry-Free Security-no method available
VMwareCarbon BlackY
Carbon Black PSCY
ZixEmail SecurityY*
ZoomVideo ConferencingY*
SyslogData Source (not listed above)Y*new parser upon request

"*": Supported, but not enabled by default. Please contact Fluency Support to enable this integration for your instance.

Use the following link to: Create a Support Ticket

Event Notification

The following matrix shows the products currently supported by Fluency SIEM for event/notification export.

VendorProductAPIWebhookMisc
EmailSIEM Alert Export
SlackYSIEM Alert Export
PagerDutyYYSIEM Alert Export