Integrations · SIEM / SOAR
Asset context on every alert.
Forward alerts to any SIEM over syslog in CEF, LEEF or RFC 5424/3164, filtered by type and severity, with native Splunk HTTP Event Collector output. SOAR platforms consume WireTrace through webhooks and the REST API.
Formats
Standard formats, no proprietary agent.
| Destination | Method |
|---|---|
| Any SIEM | Syslog over UDP, TCP or TLS: CEF, LEEF, RFC 5424, RFC 3164 |
| Splunk | HTTP Event Collector |
| IBM QRadar | LEEF over syslog |
| Microsoft Sentinel | CEF over syslog |
| SOAR | JSON webhooks and the REST API |
| Alerts and policy notifications over SMTP |
Use case
Fewer questions per alert.
Each forwarded alert can carry the device's identity, role and risk, so the analyst starts from what the device is rather than from an address.
See it on your network.
A WireTrace evaluation runs on a mirror port, on your infrastructure, and shows your own devices, communications and risks.