Ironclad SIEM Integration Library
Ironclad connects to the technologies that make up a typical business's security stack — Microsoft 365, identity providers, endpoints, firewalls and security tools — and correlates their logs into one place. Here's exactly how each connection works.
Microsoft
Microsoft 365
Centralize Microsoft 365 audit, sign-in and mailbox activity alongside your other security telemetry.
View integration details →Microsoft Entra ID
Bring identity and authentication events from Entra ID (Azure AD) into Ironclad for correlation and detection.
View integration details →Microsoft Defender
Pull Microsoft Defender for Endpoint alerts and device events into Ironclad alongside your other data sources.
View integration details →Windows
Collect Windows event logs from servers and workstations for endpoint visibility and detection.
View integration details →Active Directory
Monitor on-premises Active Directory for authentication anomalies and privilege changes.
View integration details →Network
Cisco Meraki
Bring Meraki firewall and network event logs into Ironclad for network-layer detection.
View integration details →Fortinet FortiGate
Ingest FortiGate firewall logs for perimeter and internal network detection.
View integration details →SonicWall
Collect SonicWall firewall logs for network detection and investigation.
View integration details →Security
Don't see a data source you use? Contact us — we add new integrations as we confirm real support for them.