Every layer of your stack.
One audit platform.
100+ integrations — 22 databases, 10 data lakes and lakehouses,14 SIEM platforms, every major cloud, and the identity, alerting, and deployment tooling you already run. No agents to install, no appliances to rack.
22 supported databases
Native connectors for relational, NoSQL, and cloud data warehouses. Each one streams events with under a second of detection latency.
PostgreSQL
RelationalFull support via pgaudit and pg_stat_statements
MySQL
RelationalEnterprise audit log and general log support
MariaDB
RelationalAudit plugin and query logging
Oracle
RelationalFine-grained auditing and unified audit trail
SQL Server
RelationalSQL Server Audit and extended events
IBM DB2
RelationalDB2 audit facility and db2audit
Informix
RelationalNative audit trail for the IBM estate
Netezza
WarehouseLegacy IBM warehouse coverage while you modernize
MongoDB
NoSQLAudit log parsing and profiler integration
Cassandra
NoSQLAudit logging with CQL support
DynamoDB
NoSQLCloudWatch integration and stream processing
Redis
NoSQLMONITOR command and slowlog analysis
Couchbase
NoSQLAudit events and N1QL query logs
Elasticsearch
SearchAudit logging and slow log capture
Snowflake
Cloud DWQuery history and access history views
BigQuery
Cloud DWINFORMATION_SCHEMA and audit logs
Redshift
Cloud DWSTL and SYS tables for query logging
Azure SQL
CloudAzure SQL auditing and diagnostic logs
CockroachDB
DistributedSQL audit logging and event logs
TimescaleDB
Time-seriesPostgreSQL-based with pg_stat_statements
ClickHouse
AnalyticsQuery log and part log analysis
Neo4j
GraphQuery logging and security events
10 data lake technologies
Audit lakes and lakehouses across AWS, Azure, and Google Cloud with the same policies you apply to your databases.
Amazon S3 Data Lakes
AWSCloudTrail and S3 access log auditing
AWS Lake Formation
AWSData governance and fine-grained access audit
Amazon Athena
AWSQuery execution history and cost tracking
Azure Data Lake Storage Gen2
AzureDiagnostic logging and access auditing
Azure Synapse Analytics
AzureUnified query audit and DMV monitoring
Microsoft Fabric
AzureOneLake unified audit logging
Google BigLake
GCPUnified data lake access auditing
Databricks Lakehouse
Multi-cloudUnity Catalog audit and query history
Apache Hadoop
Multi-cloudHDFS audit logging and YARN job tracking
Apache Hive
Multi-cloudHiveServer2 audit logs and query analysis
14 SIEM platforms
Events forward to the SIEM you already run, filtered at the collector so you are not paying per-gigabyte for noise.
Splunk
Send audit events via HTTP Event Collector (HEC) to Splunk Enterprise or Splunk Cloud.
Microsoft Sentinel
Forward events to Azure Sentinel workspace using the Data Collector API.
IBM QRadar
Integrate with IBM QRadar SIEM for advanced threat detection and correlation.
Elastic Security
Stream events to Elasticsearch for analysis with Elastic Security and Kibana.
CrowdStrike Falcon
Enhance endpoint protection with database activity context in Falcon LogScale.
Palo Alto Cortex XSIAM
Forward database events to Cortex XSIAM for AI-powered security operations.
Google Chronicle
Send events to Chronicle Security Operations for threat detection at scale.
AWS Security Hub
Consolidate database security findings with AWS Security Hub.
Datadog Security
Monitor database activity alongside infrastructure with Datadog Security Monitoring.
Sumo Logic
Ingest audit logs to Sumo Logic for cloud-native security analytics.
ServiceNow SecOps
Create security incidents from database alerts in ServiceNow Security Operations.
SentinelOne
Correlate database activity with endpoint data in SentinelOne Singularity.
Trellix
Feed database audit events to Trellix XDR for extended detection and response.
LogRhythm
Integrate with LogRhythm SIEM for log management and security analytics.
Deploy anywhere
Run it in our cloud or yours — AWS, Azure, GCP, on-prem, or fully air-gapped. Kubernetes-native and installed via Helm in minutes; your data never has to leave your network.
Amazon Web Services
AWS- CloudWatch Logs
- CloudTrail
- RDS & Aurora
- S3 Audit Logs
- IAM
- KMS
- Secrets Manager
- Lambda
Microsoft Azure
Azure- Azure Monitor
- Azure SQL Auditing
- Log Analytics
- Blob Storage
- Key Vault
- Managed Identity
- Defender for SQL
Google Cloud Platform
GCP- Cloud Logging
- Cloud SQL Logs
- Pub/Sub
- Secret Manager
- Workload Identity
- VPC Service Controls
- CMEK
On-Premise
Self-hosted- Kubernetes-native, installed via Helm
- S3-compatible object storage
- Full data control — nothing leaves your network
- Same collector as the cloud deployment
Air-Gapped
Isolated networks- Fully offline operation
- Offline license and update bundles
- LDAP/AD auth — no cloud IdP required
- Built for classified and regulated networks
9 identity providers
SSO via SAML 2.0 or OIDC, or direct LDAP/Active Directory bind for air-gapped environments. Just-in-time provisioning and automatic role mapping.
Alerts, your way
Notifications route to Slack, Teams, email, PagerDuty, or webhooks, with multi-level escalation if nobody acknowledges. Events forward to your SIEM.
Slack
Real-time alerts to channels
Microsoft Teams
Team channel alerts
Configurable email notifications
PagerDuty
On-call alert routing and escalation
Webhooks
Custom HTTP endpoints
SIEM
Splunk, QRadar, Sentinel, and 11 more
Email delivers through the transport you choose:
Run it anywhere
Cloud SaaS with nothing to install, or self-hosted on the operating systems and infrastructure you already operate.
Deployment
- Cloud (SaaS) — Sign up and connect — nothing to run
- Docker
- Kubernetes
- Helm
- Single binary — Linux, Windows, or macOS
Operating systems
- Ubuntu 20.04+
- RHEL 8+
- Debian 11+
- Windows Server 2019+
- macOS 12+ (Monterey)
Infrastructure & ops
- MinIO · Object storage
- Prometheus · Metrics
- Grafana · Dashboards
- HashiCorp Vault · Secrets
- Kafka / Redpanda · Streaming
Don't see your database?
We add connectors based on customer demand. Tell us what you run, or build a custom connector with our docs.