📄️ IBM QRadar
Forwards LEEF-formatted events to an Event Collector over syslog
📄️ ArcSight
Forwards CEF-formatted events over syslog
📄️ OpenText
Forwards CEF-formatted events to OpenText Security Log Analytics over syslog
📄️ Trellix
Forwards CEF-formatted events to Trellix SIEM / McAfee ESM over syslog
📄️ Snare
Forwards CEF-formatted events to Snare (Prophecy) over syslog
📄️ Logpoint
Forwards JSON-formatted events over syslog
📄️ Graylog
Forwards GELF-formatted events to a GELF input over TCP, TLS, UDP, or HTTP(S)
📄️ OVHcloud Logs Data Platform
Forwards GELF-formatted events to the OVHcloud GELF input
📄️ Datadog
Forwards JSON events to the Cloud SIEM logs intake API over HTTPS
📄️ Sumo Logic
Forwards JSON events to a Cloud SIEM HTTP Source collector
📄️ Rapid7 InsightIDR
Forwards JSON events to a log HTTP ingestion endpoint
📄️ CrowdStrike Falcon Next-Gen SIEM
Sends events natively over its HTTP Event Collector endpoint