Documentation

Managed SOC · Reference

Supported log sources

The telemetry sources the Managed SOC ingests, what each one contributes to detection, and how to connect them.

The SOC's coverage is only as good as the telemetry it receives. This reference lists supported sources, the detections each enables, and how to connect them. Everything here lands in the same cross-vendor log ingestion and normalization layer, where events are parsed and enriched with asset, identity, and threat-intelligence context before a rule ever runs. Connect identity and endpoints first — they carry the highest-value signal.

Identity

ProviderMethodKey signals
Microsoft Entra IDOAuth connector (read-only)Sign-ins, MFA, risky users, role changes
OktaAPI token connectorAuth events, MFA, admin changes
Google WorkspaceService-account connectorLogin, admin audit, OAuth grants

Connecting identity enables detections for impossible-travel sign-ins, MFA fatigue, privilege escalation, and suspicious OAuth grants.

Endpoints

SourceMethodNotes
intSignal Security SuiteNativeOn by default, no setup
Microsoft Defender for EndpointAPI integrationStreaming API + ingest key
Third-party EDRIntegration + ingest keyCheck availability with your engineer

Endpoint telemetry drives process-behavior, malware, persistence, and lateral-movement detections.

Network

  • Firewalls — forward traffic and threat logs via syslog to a collector.
  • DNS — forward query logs to detect tunneling and known-bad domains.
  • Proxies / secure web gateways — forward access logs.

Cloud

PlatformLogMethod
AWSCloudTrail (+ GuardDuty)Cross-account role or S3 forwarding
AzureActivity + sign-in logsDiagnostic settings to event hub
GCPCloud Audit LogsPub/Sub export

SaaS

Connect business-critical SaaS — email, file storage, and collaboration — to catch account takeover, data exfiltration, and malicious sharing.

Note

Do not have a source listed here? Ask your onboarding engineer — new integrations are added regularly, and generic syslog/HTTP ingestion covers many sources not named above.

Connecting a source

Most connectors are added in Portal → Settings → Integrations: choose the source, authorize or paste credentials, then confirm green data health under SOC → Data health. See Getting started for the recommended order.

Need a hand with Managed SOC?Talk to our team →