The following connectors can be added in Settings › Integrations so that you can prepare credentials and organization mapping, but they do not collect events yet. They are labelled "coming soon" in the console, on the integrations page of this site and here.
| Connector | What it will collect |
|---|---|
| AWS CloudTrail | Management and data events from one or more accounts. |
| CrowdStrike Falcon | Detections and audit events from the Falcon platform. |
| Microsoft Defender for Endpoint | Alerts and device events; the device isolation response action depends on it. |
| Google Workspace | Login, admin and Drive audit events. |
Until a connector is live, the same data can usually be delivered another way: CloudTrail through an HTTP JSON forwarder, Falcon and Defender for Endpoint through their SIEM export features into the HEC or HTTP listener. Ask support for the recommended path.