Part of Incident Management

Database events in your SIEM.
Without the per-gigabyte bill.

Database logs are the highest-value security source you own and the most expensive to ingest, which is why so many teams sample them or drop them entirely. We normalize, score, and filter at the collector — so your SIEM gets the events that matter and you keep the complete trail at object-storage prices.

See the 14 Integrations
14
SIEM platforms supported
90%
Less volume forwarded, typical
<1s
Capture to forward
0
Per-GB ingest fees from us
Ingest Control

Decide what ships
before you pay to store it

Six controls on every destination. Set them per SIEM, so the compliance team's feed and the SOC's feed are not the same firehose.

event_types

Forward only the classes you care about: audit_events, alerts, ai_detections, policy_violations, classification_findings. Send findings to the SIEM and keep the raw trail here.

severity_filter

Critical only, or critical and warning. Informational events stay local where storage costs object-storage prices instead of SIEM prices.

database_filter

Forward from the regulated estate and leave development noise behind. Scope per destination, so different teams get different feeds.

batch_size

Up to 1,000 events per batch, compressed in transit. Fewer, larger requests mean lower ingest overhead on both ends.

flush_interval_seconds

Tune latency against efficiency from 5 to 300 seconds. Real-time for alerts, relaxed for bulk audit events.

retry_attempts

Automatic retry with local caching behind it. A SIEM outage or a network blip delays delivery; it does not lose events.

Integrations

Fourteen platforms,
native format for each

Not a generic syslog dump. Events arrive in the format each platform expects — ECS for Elastic, UDM for Chronicle, ASFF for Security Hub — so detection rules work on day one.

Splunk

Send audit events via HTTP Event Collector (HEC) to Splunk Enterprise or Splunk Cloud.

HEC IntegrationCustom IndexSource Types

Microsoft Sentinel

Forward events to Azure Sentinel workspace using the Data Collector API.

Log AnalyticsCustom TablesKQL Queries

IBM QRadar

Integrate with IBM QRadar SIEM for advanced threat detection and correlation.

Log SourceEvent MappingOffense Rules

Elastic Security

Stream events to Elasticsearch for analysis with Elastic Security and Kibana.

Index TemplatesECS FormatDetection Rules

CrowdStrike Falcon

Enhance endpoint protection with database activity context in Falcon LogScale.

LogScaleThreat IntelCorrelation

Palo Alto Cortex XSIAM

Forward database events to Cortex XSIAM for AI-powered security operations.

XQL QueriesXSOAR PlaybooksAI Analytics

Google Chronicle

Send events to Chronicle Security Operations for threat detection at scale.

UDM FormatYARA-L RulesEntity Graphs

AWS Security Hub

Consolidate database security findings with AWS Security Hub.

ASFF FormatFindingsInsights

Datadog Security

Monitor database activity alongside infrastructure with Datadog Security Monitoring.

Cloud SIEMDetection RulesDashboards

Sumo Logic

Ingest audit logs to Sumo Logic for cloud-native security analytics.

HTTP SourceField ExtractionDashboards

ServiceNow SecOps

Create security incidents from database alerts in ServiceNow Security Operations.

Security IncidentsWorkflowsCMDB Integration

SentinelOne

Correlate database activity with endpoint data in SentinelOne Singularity.

XDR PlatformDeep VisibilityStorylines

Trellix

Feed database audit events to Trellix XDR for extended detection and response.

XDR PlatformThreat IntelInvestigation

LogRhythm

Integrate with LogRhythm SIEM for log management and security analytics.

Log CollectionAI EngineSmartResponse

Setup guides, field mappings, and sample payloads live in theSIEM integration docs. Running something not listed? Any HTTP endpoint works viawebhooks.

Pipeline

What happens between
the query and the alert

1

Capture

Native audit mechanisms are read in real time across 20+ engines. Nothing is installed on your database hosts.

2

Normalize and enrich

Every event is parsed into one common schema and enriched with user context, geo-IP, and data classification tags. Your SIEM gets one field layout, not twenty dialects.

3

Score with AI

Behavioral baselines and ML detection run before anything egresses, so you can forward conclusions rather than raw noise.

4

Mask and forward

Sensitive values are masked before leaving your network, then batched over TLS 1.3 to every configured destination.

Local caching sits behind every destination. A SIEM outage delays delivery — it never loses events.

No SIEM Required

Don't have a SIEM?
You don't need to buy one.

Plenty of teams land here because an auditor asked for database monitoring, not because they run a SOC. Search, dashboards, alerting, and retention are already in the platform.

  • Full-text search across billions of events, answering in seconds
  • Saved queries and dashboards for auditors and DBAs
  • Real-time alerting to Slack, Teams, email, PagerDuty, or any webhook
  • Retention windows to 7 years on immutable object storage
  • Role-based access so auditors see evidence without touching data
  • Compliance reports pre-built for 57 frameworks
Already Built In

Forwarding is not a connector
you license on top

Destinations are configured in the same console as your audit policies, under the same role-based access, streamed by the same collector already reading your databases. Nothing new to deploy, and no separate integration tier to negotiate at renewal.

Cost

SIEMs bill by the gigabyte, and database logs are the highest-volume source you have. Filtering and scoring at the collector is why teams forward a fraction of the volume and keep the full trail anyway.

Ease of use

Paste an endpoint and a token, pick your filters, save. Most integrations are running in under ten minutes — no professional-services engagement to build a parser.

Runs local

Self-hosted and air-gapped deployments forward to an on-premise SIEM with no cloud hop, or keep everything in-platform. Masking happens before egress either way.

AI before the handoff

Correlation rules written in a SIEM cannot see database intent. Ours baseline every user and application, then forward scored detections your analysts can action immediately.

Work out what you'd actually forward

Enter your business email and tell us which SIEM you run. We'll come back with the event volume you'd ship, the volume you'd keep local, and what that does to your ingest bill.