EXPEL WORKBENCH™ INTEGRATIONS
Integrations portfolio
You've invested in the right tech for your environment, and we make it work harder.
Featured integrations
AWS CloudTrail
Amazon Web Services
AWS API activity logs for cloud threat detection
How it works
Direct API integration (aws) ingesting CloudTrail event logs for cloud activity monitoring.
Data ingested
CloudTrail API events, IAM activity
Category
CloudCloud Infrastructure
Ingestion Method
API
CrowdStrike Falcon Endpoint
CrowdStrike
Endpoint protection & threat intelligence
How it works
Direct API connection (crowdstrike) ingesting endpoint telemetry and enriching with threat intel.
Data ingested
Process trees, network connections, threat intel matches
Category
EDREndpoint
Ingestion Method
API
Partners
Google Workspace
Google email, Drive & admin activity monitoring
How it works
Direct API integration (gsuite) pulling admin console and Gmail activity logs.
Data ingested
Gmail phishing signals, Drive sharing anomalies, admin activity logs
Category
Email & ProductivityEmail Security
Ingestion Method
API
Partners
Resources
Microsoft 365
Microsoft
Email threat signals & M365 activity logs
How it works
Direct API integration (office365) pulling mailbox and admin activity logs.
Data ingested
Email phishing signals, mailbox audit logs, M365 admin activity
Category
Email & ProductivityEmail Security
Ingestion Method
API
Partners
Microsoft Defender for Endpoint
Microsoft
Endpoint detection & response telemetry
How it works
Connects via direct API (microsoft_atp) to pull endpoint detection telemetry from the Defender console.
Data ingested
EDR alerts, process/device telemetry, threat detections
Category
EDREndpoint
Ingestion Method
API
Partners
Resources
Microsoft Entra ID Protection
Microsoft
Identity threat detection & risky sign-in alerts
How it works
Direct API integration (azure_identity_protection) pulling identity risk signals from Entra.
Data ingested
Risky sign-ins, identity risk events, conditional access signals
Category
Identity & AccessIdP / IAM
Ingestion Method
API
Partners
Okta
Okta
Identity provider — user auth & access anomaly alerts
How it works
Dual path: direct API (okta_direct) for native pull, plus an indirect via-SIEM path (okta plugin) when logs are routed through Sumo Logic or Splunk.
Data ingested
System logs, risky authentications, policy change events
Category
Identity & AccessIdP / IAM
Ingestion Method
API
Partners
Resources
Palo Alto Networks Next Gen Firewall
Palo Alto Networks
Next-gen firewall log ingestion & threat correlation
How it works
Dual path: direct API (palo_alto_networks) for native pull, plus via-SIEM ingestion (palo_alto_networks_siem) when logs are routed through Splunk, Sumo Logic, or LogTrust.
Data ingested
Firewall traffic logs, threat prevention alerts, URL filtering
Category
Firewall / NGFWNetwork
Ingestion Method
API
Partners
SentinelOne Singularity
SentinelOne
AI-driven endpoint detection & autonomous response
How it works
Direct API integration (sentinel_one) ingesting endpoint detections and supporting automated response actions.
Data ingested
Threat detections, storylines, automated remediation signals
Category
EDREndpoint
Ingestion Method
API
Partners
Resources
Splunk
Splunk
SIEM log source & alert forwarding
How it works
Direct API integration (SIEM plugin) — Expel operates as a managed layer on top of existing Splunk alerts and searches.
Data ingested
Splunk alerts, saved searches, notable events
Category
SIEMXDR / SIEM
Ingestion Method
API
Partners
Wiz Cloud Security
Wiz
Cloud posture & vulnerability risk context
How it works
Hybrid API + webhook integration (wiz, ViaWebhookPlugin) — Wiz pushes findings to Expel in real time, supplemented by API pulls for context.
Data ingested
Wiz issues, severity scores, cloud resource/posture context
Category
CloudCSPM / CNAPP
Ingestion Method
API + Webhook
Partners
Resources
AI / Automation
Anthropic Claude
Anthropic
AI-assisted investigation & analyst workflow support
How it works
Connects via API to support AI-assisted analysis and automation within Expel’s SOC workflows.
Data ingested
N/A — used for internal analyst workflow assistance, not customer telemetry ingestion
Category
AI / Automation
Ingestion Method
API
Cloud
Amazon Elastic Kubernetes Service (EKS)
Amazon Web Services
Kubernetes cluster activity & container runtime signals
How it works
Connects via API to pull cluster audit logs and container runtime events from Amazon Elastic Kubernetes Service.
Data ingested
Cluster audit logs, container runtime/orchestration events
Category
CloudContainer Security
Ingestion Method
API
AWS CloudTrail
Amazon Web Services
AWS API activity logs for cloud threat detection
How it works
Direct API integration (aws) ingesting CloudTrail event logs for cloud activity monitoring.
Data ingested
CloudTrail API events, IAM activity
Category
CloudCloud Infrastructure
Ingestion Method
API
AWS GuardDuty
Amazon Web Services
Intelligent threat detection for AWS workloads
How it works
Direct API integration (aws_guardduty) pulling GuardDuty’s machine-learning-based threat findings.
Data ingested
GuardDuty findings (anomalous API calls, recon, compromised credentials)
Category
CloudCloud Threat Detection
Ingestion Method
API
FortiCNAPP
Fortinet
Cloud workload protection & posture management
How it works
Connects via API to pull cloud misconfiguration findings and workload threat detections from Fortinet FortiCNAPP (Lacework).
Data ingested
Cloud misconfigurations, workload anomaly detections, compliance findings
Category
CloudCNAPP / Cloud Security
Ingestion Method
API
Google Cloud
Cloud audit & activity log ingestion
How it works
Connects via API to pull audit logs and resource activity events from Google Cloud Platform.
Data ingested
Audit logs, resource activity events, IAM changes
Category
CloudCloud Infrastructure
Ingestion Method
API
Partners
Resources
Google Kubernetes / GKE
Container orchestration activity & runtime signals
How it works
Direct API integration (gcp) pulling container orchestration and runtime audit data.
Data ingested
GKE audit logs, container runtime events
Category
CloudContainer Security
Ingestion Method
API
Partners
Resources
Google Workspace Alert Center
Google Workspace security alert aggregation
How it works
Connects via API to pull security alerts and admin notifications from Google Workspace Alert Center.
Data ingested
Security alerts, admin notifications
Category
CloudSaaS Security
Ingestion Method
API
Partners
Resources
Microsoft Azure
Microsoft
General Azure platform activity & resource logs
How it works
Connects via API to pull activity and resource logs across Microsoft Azure services.
Data ingested
Azure activity logs, resource change events
Category
CloudCloud Infrastructure
Ingestion Method
API
Partners
Resources
Microsoft Azure Kubernetes Service (AKS)
Microsoft
Kubernetes cluster activity & container runtime signals
How it works
Connects via API to pull cluster audit logs and container runtime events from Azure Kubernetes Service.
Data ingested
Cluster audit logs, container runtime/orchestration events
Category
CloudContainer Security
Ingestion Method
API
Partners
Microsoft Azure Monitor log analytics
Microsoft
Azure resource activity & diagnostic log ingestion
How it works
Connects via API to pull diagnostic and activity logs from Azure Monitor Log Analytics.
Data ingested
Azure resource activity logs, diagnostic logs
Category
CloudLog Management
Ingestion Method
API
Partners
Microsoft Defender for Cloud Apps
Microsoft
Cloud app usage & data-loss policy events
How it works
Connects via API to pull cloud app discovery and policy violation alerts from Microsoft Defender for Cloud Apps.
Data ingested
Cloud app activity, policy violation alerts, shadow IT discovery
Category
CASBCloud
Ingestion Method
API
Partners
Oracle Cloud Infrastructure (OCI)
Oracle
Cloud audit & activity log ingestion
How it works
Connects via API to pull audit logs and resource activity events from Oracle Cloud Infrastructure.
Data ingested
Audit logs, resource activity events, IAM changes
Category
CloudCloud Infrastructure
Ingestion Method
API
Partners
Resources
Orca Security
Orca Security
Agentless cloud posture & vulnerability risk context
How it works
Connects via API to pull cloud misconfiguration and vulnerability findings from Orca Security.
Data ingested
Cloud misconfigurations, vulnerability findings, risk context
Category
CloudCSPM / CNAPP
Ingestion Method
API
Partners
Resources
Palo Alto Networks Prisma Cloud Compute
Palo Alto Networks
Container & cloud workload vulnerability/runtime protection
How it works
Connects via API to pull container vulnerability findings and runtime threat detections from Prisma Cloud Compute.
Data ingested
Container vulnerability findings, runtime threat detections
Category
CloudContainer / Cloud Workload Security
Ingestion Method
API
Partners
Palo Alto Networks Strata Logging Service
Palo Alto Networks
Centralized firewall & network security log storage
How it works
Connects via API to pull aggregated firewall and network security logs from Palo Alto Networks Strata Logging Service.
Data ingested
Aggregated firewall/network security logs
Category
CloudLog Management
Ingestion Method
API
Partners
Sumo Logic Cloud Infrastructure Security
Sumo Logic
Cloud infrastructure security posture & threat detection
How it works
Connects via API to pull cloud misconfiguration and threat detections from Sumo Logic Cloud Infrastructure Security.
Data ingested
Cloud misconfigurations, threat detections
Category
CloudCSPM / Cloud Threat Detection
Ingestion Method
API
Sysdig Secure
Sysdig
Container & cloud runtime threat detection
How it works
Connects via API to pull runtime threat detections and vulnerability findings from Sysdig Secure.
Data ingested
Runtime threat detections, container vulnerability findings
Category
CloudContainer / Cloud Workload Security
Ingestion Method
API
Wiz Cloud Security
Wiz
Cloud posture & vulnerability risk context
How it works
Hybrid API + webhook integration (wiz, ViaWebhookPlugin) — Wiz pushes findings to Expel in real time, supplemented by API pulls for context.
Data ingested
Wiz issues, severity scores, cloud resource/posture context
Category
CloudCSPM / CNAPP
Ingestion Method
API + Webhook
Partners
Resources
Email & Productivity
Abnormal AI
Abnormal AI
AI-based email threat detection & response
How it works
Connects via API to pull phishing, BEC, and account-takeover detections from the Abnormal Security platform.
Data ingested
phishing/BEC detections, remediation actions, account takeover signals
Category
Email & ProductivityEmail Security
Ingestion Method
API
Partners
Google Workspace
Google email, Drive & admin activity monitoring
How it works
Direct API integration (gsuite) pulling admin console and Gmail activity logs.
Data ingested
Gmail phishing signals, Drive sharing anomalies, admin activity logs
Category
Email & ProductivityEmail Security
Ingestion Method
API
Partners
Resources
Microsoft 365
Microsoft
Email threat signals & M365 activity logs
How it works
Direct API integration (office365) pulling mailbox and admin activity logs.
Data ingested
Email phishing signals, mailbox audit logs, M365 admin activity
Category
Email & ProductivityEmail Security
Ingestion Method
API
Partners
Mimecast
Mimecast
Email threat detection & security event logs
How it works
Connects via API to pull phishing, malware, and impersonation detections from Mimecast.
Data ingested
Email threat detections, quarantine/remediation events
Category
Email & ProductivityEmail Security
Ingestion Method
API
Partners
Phishing Submission
Phishing Submission
End-user reported phishing email intake
How it works
Ingested via mailbox/plugin submission of user-reported suspicious emails for analyst triage.
Data ingested
User-submitted suspicious email reports
Category
Email & ProductivityEmail Security / User Reporting
Ingestion Method
Webhook
Proofpoint Insider Threat Management
Proofpoint
Insider risk & data-exfiltration activity monitoring
How it works
Ingested via SIEM forwarding of user activity and data-exfiltration alerts from Proofpoint Insider Threat Management.
Data ingested
User activity logs, data exfiltration alerts
Category
Email & ProductivityInsider Risk / DLP
Ingestion Method
SIEM
Partners
Resources
Proofpoint TAP
Proofpoint
Targeted phishing & malicious attachment/URL detection
How it works
Connects via API to pull phishing, malware, and click-time URL detections from Proofpoint Targeted Attack Protection (TAP).
Data ingested
phishing/malware detections, click-time URL events
Category
Email & ProductivityEmail Security
Ingestion Method
API
Partners
Sublime Security Defend
Sublime Security
Detection-as-code email security & threat detection
How it works
Connects via API to pull phishing and malicious email detections from Sublime Security.
Data ingested
Email threat detections, detection rule matches
Category
Email & ProductivityEmail Security
Ingestion Method
API
Partners
Resources
Endpoint
Arctic Wolf Aurora Endpoint Security
Arctic Wolf
AI-driven endpoint protection & threat prevention
How it works
Connects via API to pull threat detections and endpoint status from CylanceENDPOINT (BlackBerry).
Data ingested
Malware detections, endpoint device status, threat classifications
Category
EndpointEPP / AV
Ingestion Method
API
Partners
Broadcom Symantec Endpoint Protection
Broadcom
Endpoint antivirus & threat prevention telemetry
How it works
Ingested via SIEM forwarding of endpoint detection and antivirus events from Symantec Endpoint Protection.
Data ingested
Antivirus detections, endpoint policy violations
Category
EndpointEPP / AV
Ingestion Method
SIEM
Partners
Resources
Broadcom VMware Carbon Black Cloud
Broadcom
Cloud-native endpoint detection & response telemetry
How it works
Connects via API to pull endpoint detections and process telemetry from Carbon Black Cloud (Broadcom).
Data ingested
EDR alerts, process/binary telemetry, device status
Category
EDREndpoint
Ingestion Method
API
Partners
Resources
Broadcom VMware Carbon Black Endpoint
Broadcom
Endpoint detection & response telemetry (legacy CB Response)
How it works
Connects via API to pull endpoint sensor events and detections from Carbon Black EDR (Broadcom).
Data ingested
Endpoint sensor events, process telemetry, detections
Category
EDREndpoint
Ingestion Method
API
Partners
Resources
Cisco Secure Endpoint
Cisco
Endpoint detection & response telemetry
How it works
Connects via API to pull endpoint detections and file trajectory data from Cisco Secure Endpoint (AMP).
Data ingested
Endpoint detections, file trajectory/retrospective alerts
Category
EDREndpoint
Ingestion Method
API
Resources
CrowdStrike Falcon Endpoint
CrowdStrike
Endpoint protection & threat intelligence
How it works
Direct API connection (crowdstrike) ingesting endpoint telemetry and enriching with threat intel.
Data ingested
Process trees, network connections, threat intel matches
Category
EDREndpoint
Ingestion Method
API
Partners
Cybereason EDR/XDR
Cybereason
Endpoint detection & response telemetry
How it works
Connects via API to pull endpoint detections and malicious operation (Malop) data from Cybereason.
Data ingested
Endpoint detections, Malop (malicious operation) alerts, process telemetry
Category
EDREndpoint
Ingestion Method
API
Partners
Resources
DarkTrace Prevent / Detect
Darktrace
AI-driven threat detection & autonomous response actions
How it works
Connects via API to pull Darktrace Detect alerts and trigger Darktrace Prevent autonomous response actions.
Data ingested
Threat detections, autonomous response actions
Category
EndpointXDR / Detection & Response
Ingestion Method
API
Resources
Elastic Security
Elastic
Endpoint detection & response telemetry (Elastic Security)
How it works
Connects via API to pull endpoint detections and process telemetry from Elastic Security (formerly Endgame).
Data ingested
Endpoint detections, process telemetry, malware alerts
Category
EDR / Endpoint SecurityEndpoint
Ingestion Method
API
Microsoft Defender for Endpoint
Microsoft
Endpoint detection & response telemetry
How it works
Connects via direct API (microsoft_atp) to pull endpoint detection telemetry from the Defender console.
Data ingested
EDR alerts, process/device telemetry, threat detections
Category
EDREndpoint
Ingestion Method
API
Partners
Resources
Sentinel Singularity Hologram
SentinelOne
Deception-based lateral movement & credential-theft detection
How it works
Connects via API to pull deception-trap alerts from SentinelOne Singularity Hologram (formerly Attivo Networks).
Data ingested
Deception trap alerts, lateral movement detections
Category
Deception TechnologyEndpoint
Ingestion Method
API
Resources
SentinelOne Singularity
SentinelOne
AI-driven endpoint detection & autonomous response
How it works
Direct API integration (sentinel_one) ingesting endpoint detections and supporting automated response actions.
Data ingested
Threat detections, storylines, automated remediation signals
Category
EDREndpoint
Ingestion Method
API
Partners
Resources
Symantec SES
Symantec
Cloud-delivered endpoint protection & detection telemetry
How it works
Connects via API to pull endpoint detections and policy events from Symantec Endpoint Security (SES).
Data ingested
Endpoint detections, policy compliance events
Category
EndpointEPP / EDR
Ingestion Method
API
Tanium XEM Core
Tanium
Real-time endpoint visibility & management telemetry
How it works
Connects via API to pull endpoint inventory, configuration, and threat response data from Tanium XEM Core.
Data ingested
Endpoint inventory, configuration state, threat response actions
Category
EndpointEndpoint Management / XDR
Ingestion Method
API
Partners
Resources
Trellix Endpoint Security (HX)
Trellix
Endpoint detection & response telemetry
How it works
Connects via API to pull endpoint detections and process telemetry from Trellix Endpoint Security (HX).
Data ingested
Endpoint detections, process telemetry
Category
EDREndpoint
Ingestion Method
API
Partners
Resources
Trend Micro Apex One
Trend Micro
Endpoint protection & detection telemetry
How it works
Connects via API to pull endpoint detections and antivirus events from Trend Micro Apex One.
Data ingested
Endpoint detections, antivirus events
Category
EndpointEPP / EDR
Ingestion Method
API
Partners
Resources
Identity & Access
1Password
1Password
Password manager activity & security event logs
How it works
Connects via API to pull sign-in events, vault access, and security audit logs from 1Password Business.
Data ingested
Sign-in events, vault access logs, admin activity, security audit events
Category
Identity & AccessPassword Management
Ingestion Method
API
Resources
Cisco Duo
Cisco
Multi-factor authentication signals
How it works
Direct API integration (duo_direct) pulling MFA authentication events.
Data ingested
MFA authentication logs, anomalous login attempts
Category
Identity & AccessMFA
Ingestion Method
API
Resources
CrowdStrike Falcon Identity Protection
CrowdStrike
Identity threat detection via CrowdStrike
How it works
Direct API integration (crowdstrike_idp) pulling identity-specific detections from Falcon.
Data ingested
Identity threat detections, lateral movement/credential abuse alerts
Category
Identity & AccessIdP / IAM
Ingestion Method
API
Partners
CyberArk Identity
CyberArk
Identity & access management authentication events
How it works
Connects via API to pull authentication events and access policy changes from CyberArk Identity.
Data ingested
Authentication events, access policy changes, admin activity
Category
Identity & AccessIdP / IAM
Ingestion Method
API
Partners
Resources
CyberArk Privileged Access (PAM)
CyberArk
Privileged session & credential vaulting activity
How it works
Ingested via SIEM forwarding of privileged session and credential access events from CyberArk PAM.
Data ingested
Privileged session logs, credential checkout/checkin events
Category
Identity & AccessPAM
Ingestion Method
SIEM
Partners
JumpCloud
JumpCloud
Cloud directory & device authentication event logs
How it works
Connects via API to pull authentication and directory event logs from JumpCloud.
Data ingested
Authentication events, directory/device management logs
Category
Identity & AccessIdP / IAM / Directory
Ingestion Method
API
LastPass
LastPass
Password manager activity & security event logs
How it works
Connects via API to pull sign-in events and admin activity logs from LastPass.
Data ingested
Sign-in events, admin activity, security alerts
Category
Identity & AccessPassword Management
Ingestion Method
API
Partners
Resources
Microsoft Defender for Identity
Microsoft
On-premises identity threat detection & lateral movement alerts
How it works
Connects via API to pull identity-based attack detections from Microsoft Defender for Identity.
Data ingested
Identity attack detections, lateral movement/reconnaissance alerts
Category
Identity & AccessIdentity Threat Detection
Ingestion Method
API
Partners
Resources
Microsoft Entra ID Protection
Microsoft
Identity threat detection & risky sign-in alerts
How it works
Direct API integration (azure_identity_protection) pulling identity risk signals from Entra.
Data ingested
Risky sign-ins, identity risk events, conditional access signals
Category
Identity & AccessIdP / IAM
Ingestion Method
API
Partners
Microsoft Entra ID via Event Hub
Microsoft
Identity sign-in & audit log streaming
How it works
Ingested via Azure Event Hub streaming of sign-in and audit logs from Microsoft Entra ID.
Data ingested
Sign-in logs, audit logs, risk detections
Category
Identity & AccessIdP / IAM
Ingestion Method
Collector
Partners
Resources
Okta
Okta
Identity provider — user auth & access anomaly alerts
How it works
Dual path: direct API (okta_direct) for native pull, plus an indirect via-SIEM path (okta plugin) when logs are routed through Sumo Logic or Splunk.
Data ingested
System logs, risky authentications, policy change events
Category
Identity & AccessIdP / IAM
Ingestion Method
API
Partners
Resources
Okta Auth0
Okta
Identity & authentication event logs
How it works
Connects via API to pull authentication and access events from Auth0 (Okta).
Data ingested
Authentication events, access anomaly alerts
Category
Identity & AccessIdP / IAM
Ingestion Method
API
Resources
OneLogin
OneLogin
Identity provider — authentication & access event logs
How it works
Connects via API to pull authentication and access anomaly events from OneLogin.
Data ingested
Authentication events, access anomaly alerts
Category
Identity & AccessIdP / IAM
Ingestion Method
API
Ping One for Workforce
Ping Identity
Workforce identity & authentication event logs
How it works
Ingested via collector forwarding of authentication and access events from PingOne for Workforce.
Data ingested
Authentication events, access policy changes
Category
Identity & AccessIdP / IAM
Ingestion Method
Collector
Partners
Messaging & Productivity
Slack Enterprise Grid
Slack
Team messaging & incident notification delivery
How it works
Connects via API to post incident notifications and alerts to Slack channels.
Data ingested
Notification/alert delivery actions
Category
Messaging / NotificationMessaging & Productivity
Ingestion Method
API
Partners
Resources
Network
Akamai Guardicore Segmentation
Akamai
Workload microsegmentation & lateral movement visibility
How it works
Connects via API to pull segmentation policy violations and reputation/lateral movement alerts from the Guardicore Centra (Akamai) platform.
Data ingested
Segmentation policy violations, lateral movement alerts
Category
MicrosegmentationNetwork
Ingestion Method
API
Resources
Arista NDR
Arista
Network detection & response telemetry
How it works
Connects via webhook to receive network threat detections from Arista NDR (formerly Awake Security).
Data ingested
Network anomaly detections, encrypted traffic analysis alerts
Category
NDRNetwork
Ingestion Method
Webhook
Broadcom VMware NSX Advanced Load Balancer (formerly AVI Vantage)
Broadcom
Application delivery controller & load balancer traffic logs
How it works
Connects via API to pull traffic, health-check, and security event logs from the NSX Advanced Load Balancer (formerly Avi Vantage).
Data ingested
Load balancer traffic logs, health-check events, WAF/security events
Category
Load Balancer / Application DeliveryNetwork
Ingestion Method
API
Partners
Check Point AV, Anti-Bot, and IPS
Check Point
Antivirus, anti-bot & intrusion prevention log source
How it works
Ingested via collector/SIEM forwarding of AV, anti-bot, and IPS detection logs from Check Point gateways.
Data ingested
AV/anti-bot detections, IPS signature alerts
Category
Firewall / IPSNetwork
Ingestion Method
Collector
Partners
Resources
Check Point Quantum Network Security
Check Point
Next-gen firewall log ingestion & threat prevention
How it works
Connects via API to pull firewall, threat prevention, and access logs from Check Point Quantum gateways.
Data ingested
Firewall logs, threat prevention events, access control logs
Category
Firewall / NGFWNetwork
Ingestion Method
API
Resources
Cisco ASA
Cisco
Firewall & VPN traffic log source
How it works
Ingested via collector/SIEM forwarding of firewall and VPN session logs from Cisco ASA.
Data ingested
Firewall traffic logs, VPN session events
Category
Firewall / VPNNetwork
Ingestion Method
Collector
Resources
Cisco Firepower
Cisco
Next-gen firewall & intrusion prevention logs
How it works
Connects via API to pull firewall and IPS detection logs from Cisco Firepower.
Data ingested
Firewall traffic logs, IPS detections
Category
Firewall / NGFWNetwork
Ingestion Method
API
Resources
Cisco Meraki
Cisco
Cloud-managed network & security appliance logs
How it works
Connects via API to pull security event and network activity logs from Cisco Meraki.
Data ingested
Security event logs, network activity/traffic logs
Category
NetworkNetwork Management / Firewall
Ingestion Method
API
Resources
Cisco Umbrella
Cisco
DNS-layer security & web filtering logs
How it works
Connects via API to pull DNS query and web filtering security events from Cisco Umbrella.
Data ingested
DNS query logs, web filtering/blocking events
Category
NetworkSecure Web Gateway / DNS Security
Ingestion Method
API
Resources
Cloudflare WAF
Cloudflare
Web application firewall event logs
How it works
Connects via API to pull WAF rule triggers and blocked-request events from Cloudflare.
Data ingested
WAF events, blocked requests, rule triggers
Category
NetworkWAF
Ingestion Method
API
Partners
Resources
Cloudflare Zero Trust Network Access (ZTNA)
Cloudflare
Zero-trust network access session & policy logs
How it works
Connects via webhook (or collector, depending on deployment) to receive access session and policy decision logs from Cloudflare Zero Trust.
Data ingested
Access session logs, policy decisions, device posture signals
Category
NetworkZTNA / Zero Trust
Ingestion Method
Webhook
Resources
Corelight Open NDR
Corelight
Network detection & response built on open-source Zeek
How it works
Connects via API to pull network traffic metadata and threat detections from Corelight (Zeek-based sensors).
Data ingested
Network traffic metadata, protocol logs, threat detections
Category
NDRNetwork
Ingestion Method
API
Darktrace
Darktrace
AI-based network anomaly detection
How it works
Direct API integration (darktrace_direct) pulling AI-based network anomaly detections.
Data ingested
Network anomaly alerts, model breaches
Category
NDRNetwork
Ingestion Method
API
ExtraHop Reveal(x) 360
ExtraHop
Cloud-delivered network detection & response
How it works
Connects via API to pull network threat detections from ExtraHop Reveal(x) 360 (SaaS-delivered NDR).
Data ingested
Network threat detections, device/asset inventory signals
Category
NDRNetwork
Ingestion Method
API
Resources
ExtraHop Reveal(x) Enterprise
ExtraHop
On-premises network detection & response
How it works
Connects via API to pull network threat detections from ExtraHop Reveal(x) Enterprise sensors.
Data ingested
Network threat detections, wire data metrics
Category
NDRNetwork
Ingestion Method
API
Resources
Fastly Next-Gen WAF
Fastly
Web application firewall & bot management events
How it works
Connects via API to pull WAF and bot-mitigation events from Fastly Next-Gen WAF.
Data ingested
WAF blocks/alerts, bot detection events
Category
NetworkWAF
Ingestion Method
API
Partners
Resources
Forcepoint Web Filter
Forcepoint
Web filtering & URL category enforcement logs
How it works
Ingested via SIEM forwarding of web filtering and policy enforcement logs from Forcepoint Web Filter.
Data ingested
Web filtering logs, blocked URL categories
Category
NetworkSecure Web Gateway
Ingestion Method
SIEM
Resources
FortiAnalyzer
Fortinet
Fortinet log aggregation & analysis
How it works
Direct API integration (fortianalyzer) pulling aggregated Fortinet log/event data.
Data ingested
Fortinet firewall logs, aggregated security events
Category
Firewall MgmtNetwork
Ingestion Method
API
FortiGate
Fortinet
Next-gen firewall traffic & threat logs
How it works
Ingested via SIEM forwarding of firewall traffic and threat prevention logs from Fortinet FortiGate.
Data ingested
Firewall traffic logs, IPS/AV detections, VPN events
Category
Firewall / NGFWNetwork
Ingestion Method
SIEM
iboss Secure Access Service Edge (SASE)
iboss
Secure web gateway & SASE traffic logs
How it works
Ingested via SIEM forwarding of web traffic and policy enforcement logs from the iboss SASE platform.
Data ingested
Web traffic logs, policy enforcement events
Category
NetworkSASE / SWG
Ingestion Method
SIEM
Imperva WAF
Thales
Web application firewall event logs
How it works
Connects via API to pull WAF rule triggers and blocked-request events from Thales Imperva WAF (on-prem or cloud).
Data ingested
WAF events, blocked requests
Category
NetworkWAF
Ingestion Method
API
Partners
Resources
McAfee IDS
McAfee
Network intrusion detection log source
How it works
Ingested via collector/SIEM forwarding of intrusion detection alerts from McAfee IDS.
Data ingested
Intrusion detection alerts, signature matches
Category
IDS/IPSNetwork
Ingestion Method
Collector
Partners
Netskope Next Gen SWG
Netskope
Web traffic filtering & threat protection logs
How it works
Connects via API to pull web traffic and threat protection events from Netskope Next Gen SWG.
Data ingested
Web traffic logs, threat protection events
Category
NetworkSecure Web Gateway
Ingestion Method
API
Partners
Resources
Palo Alto Networks Next Gen Firewall
Palo Alto Networks
Next-gen firewall log ingestion & threat correlation
How it works
Dual path: direct API (palo_alto_networks) for native pull, plus via-SIEM ingestion (palo_alto_networks_siem) when logs are routed through Splunk, Sumo Logic, or LogTrust.
Data ingested
Firewall traffic logs, threat prevention alerts, URL filtering
Category
Firewall / NGFWNetwork
Ingestion Method
API
Partners
Vectra AI (NDR)
Vectra AI
AI-driven network detection & response
How it works
Connects via API to pull network attack-signal detections from Vectra AI.
Data ingested
Network attack-signal detections, entity risk scores
Category
NDRNetwork
Ingestion Method
API
Partners
Resources
Verizon Network Detection and Response
Verizon
Cloud-delivered network detection & response
How it works
Connects via API to pull network threat detections from Verizon Network Detection and Response.
Data ingested
Network threat detections, packet capture metadata
Category
NDRNetwork
Ingestion Method
API
Partners
Resources
Zscaler Secure Internet Access (ZIA)
Zscaler
Secure internet access & web traffic filtering logs
How it works
Connects via collector, webhook, or SIEM forwarding (deployment-dependent) of web traffic and threat protection logs from Zscaler Internet Access (ZIA).
Data ingested
Web traffic logs, threat protection events, policy violations
Category
NetworkSecure Web Gateway
Ingestion Method
Collector
Partners
Resources
Risk & Vulnerability
Qualys VMDR
Qualys
Vulnerability scanning & risk detection
How it works
Connects via API to pull vulnerability scan results and asset risk scores from Qualys VMDR.
Data ingested
Vulnerability findings, asset risk scores
Category
Risk & VulnerabilityVulnerability Management
Ingestion Method
API
Partners
Resources
Rapid7 InsightVM
Rapid7
Vulnerability scanning & risk detection
How it works
Connects via API to pull vulnerability scan results and asset risk data from Rapid7 InsightVM.
Data ingested
Vulnerability findings, asset risk scores
Category
Risk & VulnerabilityVulnerability Management
Ingestion Method
API
Partners
Tenable Vulnerability Management
Tenable
Vulnerability scanning & risk detection
How it works
Connects via API to pull vulnerability scan results and asset risk data from Tenable Vulnerability Management.
Data ingested
Vulnerability findings, asset risk scores
Category
Risk & VulnerabilityVulnerability Management
Ingestion Method
API
Resources
SaaS
Box
Box
File-sharing activity & admin audit logs
How it works
Connects via API to pull file access, sharing, and admin event logs from Box.
Data ingested
File access/sharing events, admin activity logs
Category
Cloud Storage / CollaborationSaaS
Ingestion Method
API
Partners
Resources
Dropbox
Dropbox
File-sharing activity & admin audit logs
How it works
Connects via API to pull file access, sharing, and admin event logs from Dropbox Business.
Data ingested
File access/sharing events, admin activity logs
Category
Cloud Storage / CollaborationSaaS
Ingestion Method
API
Partners
Resources
GitHub
GitHub
Repository activity & security alert logs
How it works
Connects via API to pull audit logs, repository access events, and code-scanning alerts from GitHub.
Data ingested
Audit logs, repo access events, secret/code-scanning alerts
Category
SaaSSource Code Management
Ingestion Method
API
Resources
GitLab
GitLab
Repository activity & security alert logs
How it works
Connects via API to pull audit logs, pipeline activity, and security scan findings from GitLab.
Data ingested
Audit logs, pipeline events, security scan findings
Category
SaaSSource Code Management
Ingestion Method
API
Partners
Resources
Microsoft Intune
Microsoft
Mobile device & endpoint management compliance data
How it works
Connects via API to pull device compliance and configuration data from Microsoft Intune.
Data ingested
Device compliance status, configuration/policy events
Category
Endpoint / Device ManagementSaaS
Ingestion Method
API
Partners
Netskope Cloud Access Security Broker (CASB)
Netskope
Cloud app usage & data-loss policy events
How it works
Connects via API to pull cloud app activity and DLP policy violations from Netskope CASB.
Data ingested
Cloud app activity logs, DLP policy violations
Category
CASBSaaS
Ingestion Method
API
Partners
Resources
Palo Alto Networks SaaS Security
Palo Alto Networks
SaaS application security & data-loss policy events
How it works
Connects via API to pull cloud app activity and policy violation alerts from Palo Alto Networks SaaS Security.
Data ingested
Cloud app activity, policy violation alerts
Category
CASBSaaS
Ingestion Method
API
Partners
Salesforce Shield
Salesforce
Salesforce platform event monitoring & compliance logging
How it works
Connects via API to pull platform event logs and field-level audit data from Salesforce shi-internationaleld.
Data ingested
Platform event logs, field audit trail, transaction security events
Category
SaaSSaaS Security / Compliance
Ingestion Method
API
Partners
Resources
Varonis SaaS
Varonis
SaaS data access & exposure risk monitoring
How it works
Connects via API to pull data access activity and exposure risk alerts from Varonis SaaS.
Data ingested
Data access activity, exposure/permission risk alerts
Category
Data Security / DSPMSaaS
Ingestion Method
API
Workday
Workday
HR platform activity & security audit logs
How it works
Connects via API to pull user activity and admin audit logs from Workday.
Data ingested
User activity logs, admin audit events
Category
HR / SaaS SecuritySaaS
Ingestion Method
API
Resources
Security Ops & SIEM
Cribl
Cribl
Log/data pipeline routing & transformation
How it works
Connects via API to route, filter, and forward security telemetry processed through Cribl Stream.
Data ingested
Routed/transformed log and telemetry data
Category
Observability Pipeline / Log RoutingSecurity Ops & SIEM
Ingestion Method
API
Crowdstrike Data Replicator
CrowdStrike
Raw endpoint telemetry export from CrowdStrike Falcon
How it works
Connects via API to pull raw sensor/event data streamed through CrowdStrike Falcon Data Replicator.
Data ingested
Raw endpoint sensor/event telemetry
Category
EDR / Data ExportSecurity Ops & SIEM
Ingestion Method
API
Partners
Resources
CrowdStrike Logscale
CrowdStrike
High-volume log ingestion & search platform
How it works
Connects via API to query and ingest log data stored in CrowdStrike Falcon LogScale (formerly Humio).
Data ingested
Ingested/indexed log data, search results
Category
Log ManagementSecurity Ops & SIEM
Ingestion Method
API
Partners
Resources
CrowdStrike Logscale Collector
CrowdStrike
Log collection & forwarding agent for LogScale
How it works
Connects via collector agent to forward log sources into CrowdStrike Falcon LogScale.
Data ingested
Forwarded log source data
Category
Log Management / CollectorSecurity Ops & SIEM
Ingestion Method
Collector
Partners
Resources
Datadog
Datadog
Infrastructure & application observability logs
How it works
Connects via API to pull security signals, logs, and infrastructure monitoring data from Datadog.
Data ingested
Security signals, infrastructure/app logs, monitoring alerts
Category
Observability / Log ManagementSecurity Ops & SIEM
Ingestion Method
API
Partners
Resources
Devo
Devo
Cloud-native SIEM & log analytics
How it works
Connects via API to pull correlated security signals and log data from the Devo platform.
Data ingested
Correlated security signals, log data
Category
Security Ops & SIEMSIEM / Log Management
Ingestion Method
API
Elasticsearch
Elastic
Log storage, search & analytics platform
How it works
Connects via API to query and ingest indexed logs from an Elasticsearch cluster.
Data ingested
Indexed logs, search query results
Category
Log Management / SearchSecurity Ops & SIEM
Ingestion Method
API
Resources
Exabeam Fusion New-Scale SIEM Collector
Exabeam
Log collection agent for Exabeam New-Scale SIEM
How it works
Connects via collector agent to forward log sources into Exabeam Fusion New-Scale SIEM.
Data ingested
Forwarded log source data
Category
Security Ops & SIEMSIEM / Collector
Ingestion Method
Collector
Exabeam Fusion SIEM Collector
Exabeam
Log collection agent for Exabeam Fusion SIEM
How it works
Connects via collector agent to forward log sources into Exabeam Fusion SIEM.
Data ingested
Forwarded log source data
Category
Security Ops & SIEMSIEM / Collector
Ingestion Method
Collector
Google Security Operations (SecOps)
Cloud-native SIEM & SOAR log correlation
How it works
Connects via API to pull correlated detections and case data from Google Security Operations (formerly Chronicle/Siemplify).
Data ingested
Correlated detections, case/incident data
Category
Security Ops & SIEMSIEM / SOAR
Ingestion Method
API
Partners
Resources
IBM QRadar SIEM
IBM
SIEM log ingestion & correlated offenses
How it works
Connects via API to pull correlated offenses and log source events from IBM QRadar SIEM.
Data ingested
Correlated offenses, log source events
Category
Security Ops & SIEMSIEM
Ingestion Method
API
Partners
Resources
LogRhythm
LogRhythm
SIEM log ingestion & correlated alarms
How it works
Connects via API to pull correlated alarms and log data from the LogRhythm SIEM platform.
Data ingested
Correlated alarms, log source data
Category
Security Ops & SIEMSIEM
Ingestion Method
API
LogRhythm Collector
LogRhythm
Log collection agent for LogRhythm SIEM
How it works
Connects via collector agent to forward log sources into the LogRhythm SIEM platform.
Data ingested
Forwarded log source data
Category
Security Ops & SIEMSIEM / Collector
Ingestion Method
Collector
Logz.io
Logz.io
Cloud-native log management & observability
How it works
Connects via API to pull log data and security alerts from the Logz.io platform.
Data ingested
Log data, correlated security alerts
Category
Log Management / SIEMSecurity Ops & SIEM
Ingestion Method
API
Panther Cloud SIEM
Panther
Detection-as-code cloud-native SIEM
How it works
Connects via API to pull correlated detections and log data from the Panther cloud SIEM platform.
Data ingested
Correlated detections, log data
Category
Cloud SIEMSecurity Ops & SIEM
Ingestion Method
API
SentinelOne Singularity Data Lake
SentinelOne
Unified security data lake for log storage & analytics
How it works
Connects via API to query and ingest log data stored in SentinelOne Singularity Data Lake.
Data ingested
Ingested/indexed log data, query results
Category
Data Lake / SIEMSecurity Ops & SIEM
Ingestion Method
API
Snowflake
Snowflake
Cloud data warehouse log ingestion & analytics
How it works
Connects via API to query and ingest security-relevant log data stored in Snowflake.
Data ingested
Warehoused log data, query results
Category
Data Warehouse / Log StorageSecurity Ops & SIEM
Ingestion Method
API
Resources
Splunk Collector
Splunk
Log collection agent for Splunk
How it works
Connects via collector/forwarder agent to forward log sources into Splunk.
Data ingested
Forwarded log source data
Category
Security Ops & SIEMSIEM / Collector
Ingestion Method
Collector
Splunk Core Alerts
Splunk
Splunk saved-search alert ingestion
How it works
Connects via API to pull triggered saved-search alerts from Splunk Core.
Data ingested
Triggered alert/search results
Category
Security Ops & SIEMSIEM
Ingestion Method
API
Sumo Logic Cloud SIEM
Sumo Logic
Cloud-native SIEM log ingestion & correlation
How it works
Connects via API to pull correlated security signals and log data from Sumo Logic Cloud SIEM.
Data ingested
Correlated security signals, log data
Category
Security Ops & SIEMSIEM
Ingestion Method
API
Partners
Resources
Sumo Logic Collector
Sumo Logic
Log collection agent for Sumo Logic
How it works
Connects via collector agent to forward log sources into Sumo Logic.
Data ingested
Forwarded log source data
Category
Security Ops & SIEMSIEM / Collector
Ingestion Method
Collector
Ticketing & Notification
ServiceNow ITSM
ServiceNow
IT service management ticket creation & workflow
How it works
Connects via API to create and update incident tickets in ServiceNow ITSM.
Data ingested
Ticket creation/update actions, workflow status
Category
ITSM / TicketingTicketing & Notification
Ingestion Method
API
Partners
XDR / SIEM
CrowdStrike Falcon Next-Gen SIEM
CrowdStrike
Next-gen SIEM log ingestion & correlation
How it works
Connects via API to pull correlated detections and log data from CrowdStrike Falcon Next-Gen SIEM.
Data ingested
Correlated detections, indexed log data
Category
SIEMXDR / SIEM
Ingestion Method
API
Partners
Resources
Exabeam Advanced Analytics
Exabeam
User & entity behavior analytics
How it works
Direct API integration (exabeam) pulling user/entity behavior analytics.
Data ingested
UEBA risk scores, behavioral anomaly alerts
Category
UEBA / SIEMXDR / SIEM
Ingestion Method
API
Resources
Exabeam Fusion SIEM
Exabeam
Cloud-native SIEM with built-in UEBA
How it works
Connects via API to pull correlated detections and log data from Exabeam Fusion SIEM.
Data ingested
Correlated detections, log data, UEBA risk scores
Category
SIEMXDR / SIEM
Ingestion Method
API
Exabeam Threat Center
Exabeam
Centralized threat detection, investigation & response workspace
How it works
Connects via API to pull correlated threats and case data from Exabeam Threat Center.
Data ingested
Correlated threat detections, case/investigation data
Category
Threat Detection, Investigation & Response (TDIR)XDR / SIEM
Ingestion Method
API
Hunters SOC Platform
Hunters
Cloud-native SOC platform for threat detection & response
How it works
Connects via API to pull correlated detections and case data from the Hunters SOC Platform.
Data ingested
Correlated detections, case/investigation data
Category
SIEM / TDIRXDR / SIEM
Ingestion Method
API
IBM QRadar
IBM
IBM SIEM log ingestion
How it works
Direct API integration (qradar) pulling correlated SIEM offenses/events.
Data ingested
QRadar offenses, correlated security events
Category
SIEMXDR / SIEM
Ingestion Method
API
Microsoft Azure Sentinel
Microsoft
Cloud-native SIEM log ingestion
How it works
Ingested as a SIEM source via direct API (azure_sentinel) — Sentinel forwards its correlated alerts/logs to Expel.
Data ingested
Sentinel analytics rule alerts, log search results
Category
SIEMXDR / SIEM
Ingestion Method
API
Partners
Microsoft Defender XDR
Microsoft
Cross-domain detection across Microsoft stack
How it works
Direct API integration (microsoft_defender_xdr) aggregating cross-product Microsoft detections into one feed.
Data ingested
Cross-domain incidents/alerts spanning endpoint, identity, email, cloud apps
Category
XDRXDR / SIEM
Ingestion Method
API
Partners
Resources
Palo Alto Networks XSIAM/CXDR
Palo Alto Networks
Extended detection & response platform
How it works
Direct API integration — XSIAM via palo_alto_networks_cortex_xsiam, CXDR via palo_alto_networks_cxdr — pulling cross-domain detection data.
Data ingested
XDR incidents/alerts, correlated detections across network/endpoint
Category
XDRXDR / SIEM
Ingestion Method
API
Securonix Next-Gen SIEM
Securonix
Cloud-native SIEM with behavior analytics
How it works
Connects via API to pull correlated detections and UEBA risk scores from Securonix Next-Gen SIEM.
Data ingested
Correlated detections, UEBA risk scores
Category
SIEM / UEBAXDR / SIEM
Ingestion Method
API
Splunk
Splunk
SIEM log source & alert forwarding
How it works
Direct API integration (SIEM plugin) — Expel operates as a managed layer on top of existing Splunk alerts and searches.
Data ingested
Splunk alerts, saved searches, notable events
Category
SIEMXDR / SIEM
Ingestion Method
API
Partners
Not seeing an integration?
New integrations are being added each month, reach out to discuss our capabilities.
Frequently asked questions
No. Expel is API-first, vendor-agnostic, and purpose-built to work with the security technology stack you already have. We connect to your existing EDR, SIEM, identity, cloud, and network tools via API, maximizing the value of your current investments rather than displacing them.
Most customers are fully integrated and operational within days, not months. Expel’s integration team handles the technical setup, and pre-built connectors mean there is no custom development required on your side. You reach full detection coverage quickly without a lengthy professional services engagement.
Expel owns integration maintenance end-to-end. When a vendor releases an API change, schema update, or new telemetry format, Expel’s engineering team updates the connector rather than your team. Customers are notified of material changes through Workbench, and the maintenance burden never lands on your side.
Expel monitors integration health continuously. If a data source goes silent due to a misconfiguration, agent failure, or API issue, Expel alerts your team through Expel Workbench™ and our SOC flags the coverage gap proactively. Integration health is visible in your Workbench dashboard at all times.
