Documentation

Integrations Reference

Complete documentation for all 20 database connectors and 14 SIEM integrations supported by DB Audit.

Log Collection Methods

DB Audit supports multiple methods for collecting audit logs from your databases.

Native Audit

Collect directly from database native audit logs and tables

CloudWatch

Collect from AWS CloudWatch Log Groups for AWS-hosted databases

Azure Monitor

Collect from Azure Monitor and Log Analytics for Azure databases

GCP Cloud Logging

Collect from Google Cloud Logging for GCP databases

Custom SQL Query

Use custom SQL queries to collect audit data from tables/views

Database Connectors

Native connectors for 20 databases including relational, NoSQL, and cloud data warehouses.

Relational Databases (10)

PostgreSQL

Port 5432
Native Audit CloudWatch

Features:

  • pg_stat_statements (aggregated statistics)
  • pgaudit (detailed session logs)
  • SSL/TLS support

Configuration:

host, port, database, user, password, ssl

MySQL

Port 3306
Native Audit CloudWatch

Features:

  • Audit Plugin
  • General Query Log
  • Slow Query Log
  • Performance Schema

Configuration:

host, port, database, user, password, ssl

MariaDB

Port 3306
Native Audit

Features:

  • Audit Plugin
  • Query Logging
  • MySQL-compatible

Configuration:

host, port, database, user, password, ssl

Oracle Database

Port 1521
Native Audit Custom SQL Query

Features:

  • Unified Audit Trail (12c+)
  • Standard Audit Trail
  • Fine-Grained Audit (DBA_FGA_AUDIT_TRAIL)
  • V$SQL statistics

Configuration:

host, port, service_name, user, password, thick_mode

SQL Server

Port 1433
Native Audit Azure Monitor

Features:

  • SQL Server Audit
  • Extended Events
  • Default Trace
  • Query Store

Configuration:

host, port, database, user, password, driver, ssl

Azure SQL Database

Port 1433
Azure Monitor

Features:

  • Azure SQL Auditing
  • Diagnostic Logs
  • Query Performance Insight

Configuration:

host, port, database, user, password, ssl

CockroachDB

Port 26257
Native Audit

Features:

  • SQL Audit Logging
  • Event Logs
  • Distributed SQL

Configuration:

host, port, database, user, password, ssl

TimescaleDB

Port 5432
Native Audit CloudWatch

Features:

  • PostgreSQL-based
  • pg_stat_statements
  • Time-series optimized

Configuration:

host, port, database, user, password, ssl

ClickHouse

Port 9000
Native Audit

Features:

  • Query Log
  • Part Log
  • OLAP Analytics

Configuration:

host, port, database, user, password, ssl

IBM Db2

Port 50000
Native Audit

Features:

  • DB2 Audit Facility
  • db2audit
  • Enterprise auditing

Configuration:

host, port, database, user, password, ssl

NoSQL Databases (6)

MongoDB

Port 27017
Native Audit

Features:

  • Audit Log
  • Profiler Integration
  • Document-level auditing

Configuration:

host, port, database, user, password, ssl

Apache Cassandra

Port 9042
Native Audit

Features:

  • Audit Logging
  • CQL Support
  • Distributed wide-column

Configuration:

host, port, user, password, ssl

Redis

Port 6379
Native Audit

Features:

  • MONITOR Command
  • Slowlog Analysis
  • Command logging

Configuration:

host, port, password, ssl

Elasticsearch

Port 9200
Native Audit

Features:

  • Audit Logging
  • Slow Log
  • Security events

Configuration:

host, port, api_key, ssl

Couchbase

Port 8091
Native Audit

Features:

  • Audit Events
  • N1QL Query Logs
  • Document database

Configuration:

host, port, database, user, password, ssl

Neo4j

Port 7687
Native Audit

Features:

  • Query Logging
  • Security Events
  • Graph database

Configuration:

host, port, user, password, ssl

Cloud Data Warehouses (4)

Snowflake

Port 443
Native Audit

Features:

  • Query History
  • Access History Views
  • Cloud-native

Configuration:

host, database, user, api_key

Google BigQuery

Port 443
GCP Cloud Logging

Features:

  • INFORMATION_SCHEMA
  • Audit Logs
  • Serverless

Configuration:

project_id, credentials_json

Amazon Redshift

Port 5439
CloudWatch

Features:

  • STL Tables
  • SYS Tables
  • Query Logging

Configuration:

host, port, database, user, password

Amazon DynamoDB

AWS API
CloudWatch

Features:

  • CloudWatch Integration
  • Stream Processing
  • Key-value store

Configuration:

region, access_key_id, secret_access_key

SIEM Integrations

Forward audit events to 14 leading SIEM and security platforms with automatic batching, rate limiting, and retry logic.

Supported Event Types

Audit Events Alerts AI Detections Policy Violations Classification Findings

Cloud SIEM Platforms (10)

Microsoft Sentinel

API Key (Shared Key)
Cloud Native Log Analytics UEBA Threat Intelligence

Configuration:

workspace_id, shared_key, log_type

CrowdStrike Falcon

OAuth
Falcon Data Replicator LogScale XDR Threat Hunting

Configuration:

base_url, client_id, client_secret

Palo Alto Cortex XSIAM

API Key
XDR SOAR Threat Intelligence Automation

Configuration:

api_url, api_key, api_key_id

Google Chronicle

OAuth
Petabyte Scale YARA-L UDM Threat Detection

Configuration:

customer_id, credentials_json

AWS Security Hub

API Key
AWS Native ASFF Format Multi-Account Compliance

Configuration:

region, access_key_id, secret_access_key

Datadog Security

API Key
Cloud SIEM Cloud Security Management Application Security

Configuration:

api_key, site

Sumo Logic

API Key
Cloud SIEM Log Analytics Compliance Observability

Configuration:

collector_url

ServiceNow SecOps

Basic Auth
Incident Response Vulnerability Management Threat Intelligence

Configuration:

instance_url, username, password

SentinelOne

API Token
XDR Singularity Platform Remote Operations AI-powered

Configuration:

console_url, api_token

Trellix

API Key
XDR Helix Detection as Code Threat Intelligence

Configuration:

api_url, api_key

Hybrid SIEM Platforms (3)

Splunk

HEC Token 1000 events/sec
Real-time Analytics HTTP Event Collector Index Routing SPL

Configuration:

hec_url, hec_token, index, source_type

Elastic Security

API Key 1000 events/sec
SIEM Endpoint Security Cloud Security Detection Rules

Configuration:

hosts, api_key, index_pattern

LogRhythm

API Key
SIEM SOAR Network Detection & Response UEBA

Configuration:

api_url, api_key

On-Premise SIEM (1)

IBM QRadar

Token 200 events/sec
Event Processing Offense Rules Network Flow Analysis DSM

Configuration:

console_url, api_token

Enterprise Features

Built for scale with enterprise-grade reliability.

Automatic Batching

Events are automatically batched for efficient transmission to SIEM platforms.

Rate Limiting

Per-provider rate limits (200-1000 events/sec) with intelligent throttling.

Retry Logic

Exponential backoff with configurable retry attempts ensures delivery.

Need a custom integration?

We're constantly adding new connectors. Let us know what you need.