Appearance
Integration Guide
Connect Realm with your security tools, SIEMs, and data infrastructure.
Sources
Security products and platforms that send log data to Realm.
| Integration | Description |
|---|---|
| Abnormal Security | Abnormal Security threat logs |
| Akamai | Akamai Security Events |
| AWS ALB | Application Load Balancer access logs via S3 and SQS |
| AWS CloudTrail | AWS CloudTrail logs via S3 and SQS |
| AWS VPC Flow Logs | VPC Flow Logs via S3 and SQS |
| Azure Event Hub | Azure Event Hub as a source |
| Azure Blob Storage | Azure Blob Storage as a source |
| Checkpoint Firewall | Checkpoint Firewall logs |
| Cisco FTD/ASA | Cisco FTD/ASA logs |
| Cisco Umbrella | Cisco Umbrella logs |
| Cloudflare | Cloudflare logs |
| Corelight NDR | Corelight Network Detection and Response logs |
| CrowdStrike FDR | CrowdStrike Falcon Data Replicator |
| Custom Application Logs: CEF | Ingesting custom application logs in CEF format |
| Custom Application Logs: CSV | Ingesting custom application logs in CSV format |
| Custom Application Logs: JSON | Ingesting custom application logs in JSON format |
| Custom Application Logs: Syslog | Ingesting custom application logs in Syslog format |
| Forcepoint NGFW | Forcepoint NGFW firewall logs (CEF) |
| Fortigate | Fortigate Firewall logs |
| FortiClient | FortiClient logs via FortiAnalyzer |
| GCP Logs | GCP logs via Pub/Sub |
| GitHub Audit Logs | GitHub Enterprise audit logs |
| Google Workspace | Google Workspace logs |
| Infoblox | Infoblox logs |
| Mimecast Email | Mimecast email event logs |
| Okta | Okta identity logs |
| Palo Alto Networks | Palo Alto logs |
| Proofpoint TAP | Proofpoint TAP email threat events |
| Radware CSMS DDOS | Radware CSMS DDOS logs |
| Radware WAF | Radware DefensePro logs |
| Salesforce Event Monitoring | Salesforce Event Monitoring logs |
| SentinelOne Deep Visibility | SentinelOne Deep Visibility logs |
| SentinelOne CEF | SentinelOne Events |
| Snowflake Audit Logs | Snowflake Audit Logs |
| SonicWall | SonicWall firewall logs |
| Windows Event Logs | Windows Event Logs |
| Wiz API | Wiz API logs |
| Wiz Cloud Defender | Wiz Cloud Defender events |
| Zscaler ZIA | Zscaler ZIA logs |
Destinations
SIEMs and data platforms Realm can forward enriched log data to.
| Integration | Description |
|---|---|
| AWS S3 | S3 bucket (source or destination) |
| Azure Blob Storage | Azure Blob Storage as a destination |
| CrowdStrike Next-Gen SIEM | CrowdStrike Next-Gen SIEM as a destination |
| Databricks | Databricks via Zerobus Ingest |
| Elasticsearch | Elasticsearch or AWS OpenSearch |
| Exabeam | Exabeam SIEM |
| Google Cloud Storage | GCS bucket |
| Google SecOps | Google SecOps |
| Hydrolix | Hydrolix Data Lake |
| Microsoft Sentinel | Microsoft Sentinel |
| Cortex XSIAM by Palo Alto | Cortex XSIAM |
| Panther SIEM | Panther |
| Rapid7 InsightIDR | Rapid7 InsightIDR |
| Securonix | Securonix SIEM |
| Splunk | Splunk SIEM |
| Sumo Logic | Sumo Logic as a destination |
Transport Methods
How data moves between your infrastructure and Realm.
| Method | Description |
|---|---|
| AWS S3 | S3 bucket (source or destination) |
| Azure Blob Storage | Azure Storage Containers |
| Collector | Realm on-premises data collector agent |
| Cloud Syslog | Cloud-managed syslog endpoint |
| Cloud HTTP (Webhook) | Cloud HTTP endpoint; configured per source in Custom CEF, Custom JSON |
| Rsyslog | Rsyslog log forwarding |
| Splunk HEC | Splunk HTTP Event Collector |
| Sumo Logic | Sumo Logic as a source |