Connect the security tools and systems you already run
UTMStack ships 33 built-in integrations for operating systems, clouds, firewalls, antivirus and endpoint detection tools. Anything else can send logs over syslog, through an agent, through an application programming interface (API) or to the HTTP intake.
33 built-in integrations
Ready-made connectors with their own parsers and, for most sources, their own detection rules, from Microsoft 365 to FortiGate.
Agents for Windows, Linux and macOS
Lightweight agents collect logs, run response actions and update themselves. The macOS agent is part of a paid subscription.
Any syslog source
Point any device at a UTMStack agent over syslog, including the Common Event Format (CEF) and Log Event Extended Format (LEEF) many security products use.
HTTP log intake
A web endpoint lets your own applications send logs straight to UTMStack.
Works with your EDR
Bring in alerts from endpoint detection and response (EDR) tools such as CrowdStrike Falcon, SentinelOne, Sophos Central and Bitdefender GravityZone, and correlate them with everything else.
One connector, many tenants
Cloud integrations such as Microsoft 365, Azure, Sophos Central and CrowdStrike can hold a separate connection for each customer tenant.
All 33 built-in integrations
Plus any other source over syslog (including CEF and LEEF), the UTMStack agent, a cloud API or the HTTP intake.
Operating System
WindowsAgentCollect Windows system, security and event-log activity through the lightweight UTMStack agent installed on each host.
LinuxAgentCollect Linux system, authentication and audit logs through the lightweight UTMStack agent installed on each host.
macOSAgentCollect macOS system and security log activity from Apple Mac endpoints through the lightweight UTMStack agent.IBM AIXCollectorCollect IBM AIX Unix system, security and audit logs to monitor activity on IBM Power platforms.
IBM AS/400 (IBM i)CollectorCollect IBM AS/400 (IBM i) system and audit journals to monitor user activity on midrange platforms.
Cloud
Amazon Web ServicesPluginIngest AWS account activity and API calls through CloudTrail and CloudWatch to audit cloud access and changes.Microsoft AzurePluginIngest Microsoft Azure platform and activity logs to monitor cloud workloads, identities and resource changes.
Microsoft 365PluginIngest Microsoft 365 audit logs across Exchange, Teams, SharePoint and OneDrive to monitor user and admin activity.
Google Cloud PlatformPluginIngest Google Cloud audit and activity logs to monitor compute, storage and identity across projects.
Firewall
Cisco ASACollectorIngest Cisco ASA firewall traffic, VPN and threat logs to monitor perimeter security and access.
Cisco MerakiCollectorIngest Cisco Meraki firewall and security appliance syslog to monitor cloud-managed network traffic and threats.
Cisco FirepowerCollectorIngest Cisco Firepower firewall and intrusion prevention logs to monitor attacks at the perimeter.
Fortinet FortiGateCollectorIngest Fortinet FortiGate traffic and threat logs to monitor perimeter security and network activity.
Fortinet FortiWebCollectorIngest Fortinet FortiWeb web application firewall logs to monitor attacks on exposed websites and APIs.
Sophos XG FirewallCollectorIngest Sophos XG firewall logs covering web filtering, intrusion prevention and VPN to monitor traffic and threats.
Palo Alto NetworksCollectorIngest Palo Alto Networks firewall traffic and threat logs to monitor application use and perimeter security.
SonicWallCollectorIngest SonicWall firewall traffic and threat logs to monitor perimeter security and network activity.
pfSenseCollectorIngest pfSense firewall and router logs to monitor network traffic and threats.
MikroTik RouterOSCollectorIngest MikroTik RouterOS firewall, routing and wireless logs to monitor network activity and configuration.
Network
NetFlowCollectorIngest NetFlow records from routers and switches to watch traffic patterns and spot anomalies.
Cisco SwitchCollectorIngest Cisco switch syslog to monitor configuration changes, performance and security events.
XDR
SentinelOneCollectorIngest SentinelOne endpoint detections and behavior data to correlate and investigate threats at scale.
Sophos CentralPluginIngest Sophos Central detections across endpoint, server, firewall and email to correlate threats in one place.
CrowdStrike FalconPluginIngest CrowdStrike Falcon endpoint and workload detections to correlate them with the rest of your data.
Antivirus
Kaspersky Security CenterCollectorIngest Kaspersky Security Center detections and endpoint data to correlate malware activity across the network.
ESET PROTECTCollectorIngest ESET PROTECT endpoint detections to correlate malware defense across all your devices.
Bitdefender GravityZonePluginIngest Bitdefender GravityZone detections and endpoint data to correlate threats across business devices.
IDS / IPS
Suricata IDS/IPSCollectorIngest Suricata intrusion alerts and network events to detect malicious traffic across the network.
Virtualization
VMware ESXiCollectorIngest VMware ESXi hypervisor syslog so activity on virtualization hosts is monitored.
Database
Oracle DatabaseCollectorIngest Oracle Database audit logs to monitor queries, access and privileged activity across your databases.
DevOps
GitHubCollectorIngest GitHub audit logs to monitor repository access, code changes and organization activity.
Deception
Deceptive BytesCollectorIngest alerts from the Deceptive Bytes endpoint deception platform to surface attacker activity early.
SIEM
UTMStack self-monitoringCollectorIngest UTMStack's own platform logs to monitor its health, internal activity and audit events.
Questions buyers ask
What if my product is not on the list?
Most products can send syslog, and UTMStack reads standard formats such as CEF and LEEF. Applications can send JSON to the HTTP intake. You then build or adjust a pipeline for the new source and test it in the playground.
Do I have to replace my EDR or antivirus?
No. UTMStack integrates with CrowdStrike, SentinelOne, Sophos, Bitdefender, ESET, Kaspersky and others, and correlates their alerts with the rest of your data.
Which operating systems does the agent support?
Windows Server 2016 or later, Linux distributions running rsyslog, and macOS. The macOS agent is part of a paid subscription.
How is an agent installed?
Open the integration in UTMStack, copy the generated one-line command and run it as an administrator or root. The command carries a secret connection key that registers the agent with your server.
Related capabilities
- Log managementCollect logs from any source, correlate them in real time before storage, and keep hot and cold data searchable for up to 5 years.
- Multi-tenancyNative multi-tenancy in UTMStack 12: separate tenants on one server, your own branding, federation across servers, SSO and custom roles.
- Automated responseBuild response flows on a visual canvas to isolate hosts, kill processes, log off and block users or IPs. Track every run and use a live console.
- Asset managementKeep a live inventory of the servers, endpoints and devices sending data to UTMStack, with OS, IP, status and last-seen details plus installed software.
Protect your organization this week, not next quarter
Talk to an engineer today, or start using UTMStack in minutes.
Need to extend your SOC team?
Our analysts work as an extension of your security team: they cover nights and weekends, take alert overflow and back you up on hard incidents. Book a 30-minute call to plan the coverage you need.
Want to try UTMStack?
Click through the live demo in your browser with no sign-up, start a free cloud instance, or install the open source edition on your own server in about 30 minutes.