Integrations · SIEM / SOAR

Asset context on every alert.

Forward alerts to any SIEM over syslog in CEF, LEEF or RFC 5424/3164, filtered by type and severity, with native Splunk HTTP Event Collector output. SOAR platforms consume WireTrace through webhooks and the REST API.

CONTEXT IN · FINDINGS OUTYOUR CONTROLS ACTSIEM / SOARsyslog · CEF · LEEF · webhooksThreat intelligenceSTIX 2.1 · CSV · feedsNetwork infrastructureSNMP · LLDP/CDP · syslog inWireTraceunderstandsdecides · validatesFirewallsrule proposals · blocklistsNACidentity & risk via APIAPIs & automationREST · OAuth 2.0 · webhooks
Formats

Standard formats, no proprietary agent.

DestinationMethod
Any SIEMSyslog over UDP, TCP or TLS: CEF, LEEF, RFC 5424, RFC 3164
SplunkHTTP Event Collector
IBM QRadarLEEF over syslog
Microsoft SentinelCEF over syslog
SOARJSON webhooks and the REST API
EmailAlerts and policy notifications over SMTP
Use case

Fewer questions per alert.

Each forwarded alert can carry the device's identity, role and risk, so the analyst starts from what the device is rather than from an address.

See it on your network.

A WireTrace evaluation runs on a mirror port, on your infrastructure, and shows your own devices, communications and risks.