[Desarrolladores]

SIEM Integration

Most security operations teams already have a SIEM investment. The SIEM Integration module connects the platform bidirectionally to those existing systems rather than asking teams to choose between them. Events flow in…

Categoría: ManagementÚltima Actualización:
managementgeospatial

Overview#

Most security operations teams already have a SIEM investment. The SIEM Integration module connects the platform bidirectionally to those existing systems rather than asking teams to choose between them. Events flow in from your SIEM to feed investigations; platform alerts and findings flow back out to your SIEM for centralised correlation alongside other organisational data.

Managing multiple SIEM connections simultaneously is supported, which suits organisations with separate enterprise and operational technology environments or those mid-migration between SIEM platforms.

Key Features#

  • Multi-Platform Support: Connect to Splunk, IBM QRadar, Microsoft Sentinel, Elastic Security, LogRhythm, ArcSight, Sumo Logic, and Google Chronicle. Manage multiple connections simultaneously with independent configurations per platform.

  • Flexible Connection Types: Connect via published service interface endpoints, message brokers (Kafka, RabbitMQ, Azure Event Hubs), or cloud storage (S3, Azure Blob, GCS). Each connection type is optimised for its use case with appropriate authentication, retry logic, and error handling.

  • Data Normalisation: Transform events between SIEM-native formats and the platform schema with configurable field mappings and transformation rules. Supports JSON, CEF, SYSLOG, CSV, XML, and LEEF formats with built-in functions for date conversion, IP normalisation, severity mapping, and custom transformations.

  • Event Routing: Route incoming SIEM events to specific investigations and workflows based on configurable match conditions. Filter by severity, category, source, or custom fields, with actions to cache, notify, or discard events for noise reduction.

  • Bidirectional Event Streaming: Stream events from your SIEM into the platform (inbound), forward platform alerts to your SIEM (outbound), or synchronise in both directions. Monitor stream health with live status indicators, event counts, and error tracking.

  • Connection Testing: Validate connections before enabling with tests covering network connectivity, authentication, query execution, data retrieval, and write operations. Review response times and sample data before going live.

Supported Platforms#

PlatformQuery LanguageAuthentication
SplunkSPLToken or Basic Auth
Microsoft SentinelKQLOAuth2 / Service Principal
IBM QRadarAQLSEC Token
Elastic SecurityElasticsearch DSLAPI Key or Basic Auth
LogRhythmNativeAPI Token
ArcSightNativeAPI Credentials
Sumo LogicNativeAPI Key
Google ChronicleNativeOAuth2

Use Cases#

  • Law enforcement agencies correlating platform investigation findings with broader network events in an existing SIEM without fragmenting the security operations workflow.
  • Government departments with separate enterprise and OT environments that feed different SIEM instances, both connecting to the platform through independent configurations.
  • Intelligence organisations using routing rules to direct only high-severity events into active investigations while reducing noise from low-priority alerts.
  • Financial institutions normalising events from multiple SIEMs into a common schema for unified threat analysis across business units with different tooling.

Open Standards#

  • MITRE ATT&CK: Detected attack patterns are tagged with ATT&CK technique identifiers (e.g. T1021, T1041, T1566) across all connected SIEM sources, enabling consistent tactic and technique classification in investigation workflows.
  • CEF (Common Event Format): Inbound events encoded in the ArcSight-originated CEF log format are parsed and normalised into the platform schema via the field-mapping engine.
  • Syslog (RFC 5424 / RFC 3164): Syslog-formatted event streams from network devices and SIEM forwarders are accepted as a native source format alongside JSON and CEF.
  • LEEF (Log Event Extended Format): IBM QRadar's LEEF log format is supported as a source format, allowing QRadar-originated events to be ingested without pre-conversion.
  • OAuth 2.0 (RFC 6749): Service-principal and client-credentials flows are used to authenticate outbound connections to Microsoft Sentinel and Google Chronicle, with token exchange handled per the RFC 6749 client credentials grant.
  • Elasticsearch NDJSON Bulk API: Outbound events forwarded to Elastic Security are serialised as newline-delimited JSON action/document pairs matching the Elasticsearch _bulk endpoint wire format.
  • HMAC-SHA256 (RFC 2104): Generic HTTPS webhook push targets are authenticated with an HMAC-SHA256 signature over the JSON payload body, allowing receiving systems to verify message integrity and origin.
  • ISO 8601: All event timestamps across inbound normalisation, outbound payloads, and stream health metrics are serialised as ISO 8601 date-time strings to ensure interoperability with downstream SIEM correlation engines.

Getting Started#

  1. Select Your SIEM: Choose your SIEM platform and gather the required connection credentials.
  2. Configure Connection: Enter endpoint details, authentication, and query settings.
  3. Test Connectivity: Run connection tests to validate authentication and data access.
  4. Set Up Normalisation: Define field mappings to translate between your SIEM format and the platform schema.
  5. Configure Routing: Create rules to direct incoming events to the appropriate investigations and workflows.

Last Reviewed: 2026-02-23 Last Updated: 2026-04-14

¿Listo para Integrar?

Acceda a la documentación de pasarelas NATO STANAG o contacte a nuestro equipo de integración de defensa para obtener soporte.