Integrations
WireTrace understands. Existing controls enforce.
WireTrace adds device identity, risk and decoded evidence to the tools you already run. It does not replace your firewalls, NAC or switches: it tells them what is on the network, what it is doing, and what should change.
Categories
Six ways in and out.
At a glance
What connects, and how.
| Integration | Direction | How |
|---|---|---|
| Any SIEM | Out | Syslog over UDP, TCP or TLS in CEF, LEEF, RFC 5424 or RFC 3164, filtered by type and severity |
| Splunk | Out | Native Splunk HTTP Event Collector output |
| IBM QRadar / Microsoft Sentinel | Out | Ingest WireTrace alerts through standard syslog formats (LEEF / CEF) |
| SOAR and automation | Out | JSON webhooks and the REST API |
| Email, SNMP traps | Out | Alerts and policy notifications |
| NAC | Pull | Asset identity, classification and risk through the read-only REST API |
| Firewalls | Pull / export | IP, domain and URL blocklists; rule proposals in iptables, nftables, Cisco IOS and pf syntax |
| Switches and routers | In | Read-only SNMP v1/v2c/v3, LLDP/CDP; inbound syslog and SNMP traps |
| Threat intelligence | In | STIX 2.1 import/export, CSV, custom feed URLs, commercial feeds with your key |
| Identity providers | In | LDAP/Active Directory and OpenID Connect single sign-on |
Ticketing actions are available as early access. Ask us about the integration you need.
Bring your stack to the demo.
A WireTrace evaluation runs on a mirror port, on your infrastructure, and shows your own devices, communications and risks.