| Abnormal.ai - Abuse Campaigns | Abnormal.ai | Any destination | This pack flags malicious abuse-mailbox campaigns and failed remediation attempts across reported messages. |
| Abnormal.ai - Abuse Mailbox Messages Not Analyzed | Abnormal.ai | Any destination | This pack tracks the backlog of user-reported abuse mailbox messages Abnormal.ai did not analyze. |
| Abnormal.ai - Audit Logs | Abnormal.ai | Any destination | This pack flags failed admin actions and mass remediation events from the Abnormal.ai portal audit trail. |
| Abnormal.ai - Threats | Abnormal.ai | Any destination | This pack flags unremediated high-risk email threats like business email compromise (BEC), extortion, and credential phishing targeting VIPs. |
| Active Directory | Active Directory | Any destination | This pack processes Active Directory Domain Services events, including Kerberos authentication, directory-service changes, and DCSync replication abuse. |
| Akamai CDN | Akamai | Any destination | Akamai logs show client requests and responses at the edge. |
| AlphaSOC Findings | AlphaSOC | Any destination | AlphaSOC findings flag DNS and IP threats detected across your network. |
| Amazon CloudFront | AWS | Any destination | AWS CloudFront logs show requests, cache use, and edge activity. |
| Amazon Connect | AWS | Any destination | This pack extracts contact and agent signals from Amazon Connect logs, flagging abandoned calls and fraud risk. |
| Amazon VPC Flow Logs | AWS | Any destination | Amazon VPC Flow Logs capture network traffic between VPC resources. |
| Argo CD | Argo CD | Any destination | This pack processes Argo CD sync, health, and RBAC events from the application controller and API server. |
| Auth0 | Auth0 | Any destination | Auth0 logs cover login, signup, MFA, and API activity. |
| Aviatrix Controller API Audit | Aviatrix | Any destination | Aviatrix Controller audit logs capture API commands, user attribution, and results. |
| Aviatrix FQDN Firewall | Aviatrix | Any destination | Aviatrix FQDN firewall logs capture egress domain requests and policy enforcement. |
| Aviatrix Gateway Network Stats | Aviatrix | Any destination | Aviatrix gateway net stats logs expose per-interface rx/tx bytes, packet counts, and network drop events. |
| Aviatrix Gateway System Stats | Aviatrix | Any destination | Aviatrix gateway system stats expose per-gateway CPU, memory, and disk utilization across cloud gateways. |
| Aviatrix L4 Microsegmentation | Aviatrix | Any destination | Aviatrix DCF microsegmentation logs capture east-west policy enforcement across cloud gateways. |
| Aviatrix L7/TLS Inspection | Aviatrix | Any destination | Aviatrix L7/TLS inspection logs capture TLS session context and policy enforcement. |
| Aviatrix Suricata IDS/IPS | Aviatrix | Any destination | Aviatrix Suricata IDS/IPS alerts capture signature hits on gateway network traffic. |
| Aviatrix Tunnel Status | Aviatrix | Any destination | Aviatrix tunnel status logs capture Site2Cloud and transit link state changes, events, and failure causes. |
| Aviatrix VPN Session | Aviatrix | Any destination | Aviatrix VPN gateway logs capture per-user session lifecycles, auth events, and gateway traffic volumes. |
| AWS Application Load Balancer Logs | AWS | Any destination | AWS ALBs capture HTTP request activity routed through them. |
| AWS CloudTrail | AWS | Any destination | AWS CloudTrail records API calls and account activity across AWS services. |
| AWS CloudWatch Logs | AWS | Any destination | AWS CloudWatch Logs captures log streams from Lambda, ECS, and more. |
| AWS Config | AWS | Any destination | AWS Config monitors and records resource configuration changes. |
| AWS Elastic Load Balancer Logs | AWS | Any destination | AWS ELBs captures HTTP and HTTPS requests from Classic Load Balancers. |
| AWS GuardDuty | AWS | Any destination | AWS GuardDuty detects threats in your AWS account. |
| AWS Lambda | AWS | Any destination | AWS Lambda logs capture invocations, errors, and cold starts. |
| AWS Network Load Balancer Logs | AWS | Any destination | AWS NLBs captures connection activity and performance data. |
| AWS Route 53 | AWS | Any destination | AWS Route 53 captures DNS queries across your AWS infrastructure. |
| AWS Security Hub | AWS | Any destination | AWS Security Hub aggregates security findings across AWS. |
| AWS WAF | AWS | Any destination | AWS WAF captures AWS WAF logs from CloudWatch, S3, or Firehose. |
| Azure NSG | Azure | Any destination | Azure Network Security Group v2 flow logs record per-connection decisions and byte counts. |
| BlueCat DNS | BlueCat | Any destination | BlueCat BDDS syslog captures DNS queries and DHCP leases. |
| Check Point | Check Point | Any destination | This pack processes Check Point logs in CEF format, with or without syslog prefix. |
| Cisco ACI | Cisco | Any destination | Cisco ACI syslog events capture fabric health, endpoint moves, and admin activity. |
| Cisco ASA | Cisco | Any destination | Cisco ASA firewall logs capture syslog events for traffic, VPNs, and security alerts. |
| Cisco ASA - Google SecOps | Cisco | Google SecOps | This pack maps Cisco ASA syslog events to the UDM schema in Google Security Operations. |
| Cisco ASA - Microsoft Sentinel | Cisco | Microsoft Sentinel | This pack maps parsed Cisco ASA syslog events to the CommonSecurityLog schema in Microsoft Sentinel. |
| Cisco FTD | Cisco | Any destination | Cisco FTD syslog events cover access control, intrusion prevention, file detection, and VPN. |
| Cisco IOS | Cisco | Any destination | Cisco IOS syslog captures security, auth, and routing events. |
| Cisco IOS Traceback | Cisco | Any destination | Cisco IOS traceback events signal software faults, memory failures, and CPU issues. |
| Cisco Meraki | Cisco | Any destination | Cisco Meraki captures appliance events, flows, VPN firewall, NAT flows, and URL activity. |
| Cisco Meraki - Microsoft Sentinel | Cisco | Microsoft Sentinel | This pack maps parsed Cisco Meraki syslog events to the Syslog table schema in Microsoft Sentinel. |
| Cloudflare | Cloudflare | Any destination | Cloudflare logs show edge traffic, performance, and security. |
| CrowdStrike FDR | CrowdStrike | Any destination | Falcon Data Replicator (FDR) provides endpoint detection and response. |
| DNS Stream | DNS Stream | Any destination | This vendor-neutral DNS query/response stream includes tunneling and DGA beaconing indicators. |
| Exabeam - Cisco ASA | Cisco | Exabeam | This pack processes Cisco ASA firewall logs sent to Exabeam and filters by ASA code to drop non-actionable syslog noise. |
| Exabeam - CrowdStrike FDR | CrowdStrike | Exabeam | This pack processes CrowdStrike Falcon Data Replicator events sent to Exabeam and drops sensor and telemetry noise. |
| Exabeam - Fortinet FortiGate | Fortinet | Exabeam | This pack processes FortiGate firewall logs sent to Exabeam and filters out routine traffic and health-check noise. |
| Exabeam - Palo Alto | Palo Alto | Exabeam | This pack processes PAN-OS syslog sent to Exabeam and filters empty and duplicate-start traffic logs, leaving raw CSV untouched. |
| Exabeam - SentinelOne Cloud Funnel | SentinelOne | Exabeam | This pack processes SentinelOne EDR events sent to Exabeam and samples high-volume event types to reduce ingest costs. |
| Exabeam - Windows | Windows | Exabeam | This pack processes Windows Event Logs sent to Exabeam and filters to codes Exabeam parsers use, keeping raw XML intact for parsing. |
| Exabeam - Zscaler | Zscaler | Exabeam | This pack processes Zscaler ZIA web, ZIA DNS, and ZPA logs sent to Exabeam and filters and samples routine traffic. |
| ExtraHop | ExtraHop | Any destination | ExtraHop Reveal(x) detections surface network threats and behavioral anomalies. |
| ExtraHop - Microsoft Sentinel | ExtraHop | Microsoft Sentinel | This pack tags ExtraHop Reveal(x) network detections with severity and IPs for Microsoft Sentinel ingestion. |
| F5 | F5 | Any destination | F5 logs capture traffic, security policy, and intrusion events. |
| Fastly | Fastly | Any destination | Fastly CDN logs record client requests, cache states, and delivery performance. |
| Fortinet - Microsoft Sentinel | Fortinet | Microsoft Sentinel | This pack maps FortiGate logs to the CommonSecurityLog schema in Microsoft Sentinel. |
| Fortinet Firewall | Fortinet | Any destination | Fortinet firewall logs record allowed, denied, and other network traffic. |
| GCP Firewall | Google Cloud | Any destination | GCP VPC Firewall logs record allowed and denied traffic. |
| Google Cloud Audit | Google Cloud | Any destination | Google Cloud Audit logs capture admin activity and policy violations. |
| Google SecOps - AWS VPC | AWS | Google SecOps | This pack maps AWS VPC flow records to the UDM schema in Google Security Operations. |
| Google SecOps - Fortinet Firewall | Fortinet | Google SecOps | This pack maps Fortinet firewall logs to the UDM schema in Google Security Operations. |
| Google SecOps - Palo Alto Firewall | Palo Alto | Google SecOps | This pack remaps PAN-OS logs to the UDM schema in Google Security Operations. |
| Google SecOps - Windows Event Log | Windows | Google SecOps | This pack maps Windows security events to the UDM schema in Google Security Operations. |
| HAProxy Ingress | HAProxy | Any destination | HAProxy Ingress logs record how Kubernetes ingress traffic is routed and served. |
| Infoblox | Infoblox | Any destination | Infoblox NIOS syslog captures DNS, DHCP, audit, and CEF activity from appliances. |
| Istio Proxy | Istio | Any destination | Istio Proxy logs capture inbound and outbound traffic handled by Envoy. |
| Juniper SRX Firewall Traffic Logs | Juniper | Any destination | Juniper SRX Firewall records network session data. |
| Kube Proxy | Kubernetes | Any destination | This pack keeps kube-proxy errors and warnings only, dropping routine iptables sync noise fired every cycle. |
| Microsoft DNS | Microsoft | Any destination | This pack parses the classic Windows DNS Server debug text log (dns.log) and decodes query names and response codes. |
| MITRE ATT&CK AWS WAF Enrichment | AWS | Any destination | This pack tags AWS WAF logs with MITRE ATT&CK tactics and techniques. |
| MITRE ATT&CK CloudTrail Enrichment | AWS | Any destination | This pack tags CloudTrail logs with MITRE ATT&CK tactics and techniques. |
| MITRE ATT&CK FortiGate Enrichment | Fortinet | Any destination | This pack tags FortiGate logs with MITRE ATT&CK tactics and techniques. |
| MITRE ATT&CK Okta Enrichment | Okta | Any destination | This pack tags Okta logs with MITRE ATT&CK tactics and techniques. |
| MITRE ATT&CK Palo Alto Enrichment | Palo Alto | Any destination | This pack tags Palo Alto logs with MITRE ATT&CK tactics and techniques. |
| MITRE ATT&CK Windows Enrichment | Windows | Any destination | This pack tags Windows event logs with MITRE ATT&CK tactics and techniques. |
| Netskope | Netskope | Any destination | Netskope logs capture cloud app use, policies, and security events. |
| NGINX | NGINX | Any destination | NGINX logs record client requests, responses, and errors from the web server. |
| Okta | Okta | Any destination | Okta logs show authentication, user activity, and policy events. |
| OpenAI - Audit Logs | OpenAI | Any destination | This pack flags failed logins, new API keys, and privilege changes from OpenAI organization audit logs. |
| OpenTelemetry Logs | OpenTelemetry | Any destination | OTLP/JSON logs nest events under resourceLogs, scopeLogs, and logRecords arrays, three levels deep per payload. |
| Orca Security | Orca Security | Any destination | This pack normalizes Orca Security cloud findings for SIEM and data lake routing. |
| Palo Alto Cortex | Palo Alto | Any destination | Cortex XDR alerts include severity, MITRE ATT&CK mapping, and source/destination context. |
| Palo Alto Firewall | Palo Alto | Any destination | Palo Alto firewall logs capture traffic, threat, and system events. |
| Palo Alto Networks - Microsoft Sentinel | Palo Alto | Microsoft Sentinel | This pack maps PAN-OS logs to the CommonSecurityLog schema in Microsoft Sentinel. |
| Palo Alto Networks - XSIAM | Palo Alto | Cortex XSIAM | This pack remaps PAN-OS logs to the Cortex XSIAM flat JSON schema. |
| Proofpoint Email Security | Proofpoint | Any destination | Proofpoint Email Security logs capture email threats, phishing, and malware detections. |
| Qualys Detections | Qualys | Any destination | This pack surfaces new, confirmed, and reopened Qualys vulnerability detections, dropping low-severity noise. |
| SentinelOne Cloud Funnel EDR | SentinelOne | Any destination | SentinelOne Cloud Funnel streams EDR and Deep Visibility events as JSON to cloud storage. |
| Syslog | Syslog | Any destination | This pack parses generic RFC 3164/5424 syslog with severity mapping and a log-volume metric. |
| Windows DNS Log | Windows | Any destination | The Windows DNS Server analytic log covers queries, zone transfers, and dynamic updates. |
| Windows Office 365 | Microsoft | Any destination | This pack flags high-risk Microsoft 365 (M365) Unified Audit Log events: mail-forwarding rules, delegation, and role changes. |
| Windows XML | Windows | Any destination | Windows Event logs capture system, application, and security activity from Windows hosts. |
| WinEventLog | Windows | Any destination | Windows Event Log captures authentication, process creation, and account management events. |
| ZScaler ZIA DNS | Zscaler | Any destination | ZScaler Internet Access (ZIA) DNS logs capture org-wide DNS activity and policy actions. |
| Zscaler ZIA Firewall | Zscaler | Any destination | Zscaler Internet Access (ZIA) Firewall logs show network traffic and security events. |
| Zscaler ZIA Tunnel | Zscaler | Any destination | Zscaler Internet Access (ZIA) Tunnel logs show tunnel health, traffic, and key events. |
| Zscaler ZIA Web Logs | Zscaler | Any destination | Zscaler Internet Access (ZIA) Web Logs capture user web activity and security actions. |
| Zscaler ZPA | Zscaler | Any destination | Zscaler Private Access captures private app access, sessions, and connections. |