Skip to main content
Google Cloud Documentation
Documentation
  • Get Started
  • Get Started with Google Cloud
  • Product List
  • Cloud Customer Care
  • Featured Products
  • Agent Platform
  • Apigee API Management
  • BigQuery
  • Compute Engine
  • Cloud CDN
  • Cloud Run
  • Cloud Storage
  • Cloud SQL
  • Gemini Enterprise
  • Google Kubernetes Engine
  • Looker
  • Cross-product Tools
  • Access and resources management
  • Costs and usage management
  • Infrastructure as code
  • SDK, languages, frameworks, and tools
  • Technology Areas
  • AI and ML
  • Application development
  • Application hosting
  • Compute
  • Data analytics and pipelines
  • Databases
  • Distributed, hybrid, and multicloud
  • Industry solutions
  • Migration
  • Networking
  • Observability and monitoring
  • Security
  • Storage
/
Console
  • English
  • Deutsch
  • Español
  • Español – América Latina
  • Français
  • Indonesia
  • Italiano
  • Português
  • Português – Brasil
  • עברית
  • 中文 – 简体
  • 中文 – 繁體
  • 日本語
  • 한국어
Sign in
  • Google Security Operations
Start free
Overview Guides Use cases Reference Support Resources
Google Cloud Documentation
  • Documentation
    • More
    • Overview
    • Guides
    • Use cases
    • Reference
    • Support
    • Resources
  • Console
  • Discover
  • Introduction
    • Google SecOps overview
    • Google Unified Security overview
    • Recommended Google Unified Security products
    • Understand the Google SecOps platform
    • Google SecOps architecture
  • Google SecOps lifecycle
    • Collect data
      • Data ingestion overview
      • UDM overview
    • Detect threats
      • Applied Threat Intelligence overview
      • Get started with YARA-L
    • Investigate alerts
      • Investigation and case management overview
      • Investigate alerts and entity context
    • Respond to alerts
      • Playbook automation overview
      • Embed AI agents in playbooks
      • Respond to alerts and cases
    • Manage and monitor
      • Content Hub overview
      • Ingestion metrics overview
      • Dashboards overview
  • Gemini in Google SecOps
    • Overview
    • Access in-product help with Gemini
  • Licensing
    • Google SecOps packages overview
    • Google SecOps Security Tokens overview
  • Get started
  • Access a Google SecOps instance
  • Log in to Google SecOps
  • Navigate the Google SecOps platform
  • Configure user preferences
  • Administer
  • Set up an instance
    • Deploy an instance
    • Understand your billing
    • Configure a Google Cloud project
    • Link an instance to Google Cloud
    • Configure authentication
      • Configure Google Cloud identity
      • Configure third-party identity
      • Change authentication
  • Configure feature access
  • Configure data access
    • Data RBAC overview
    • Configure data RBAC
    • Manage RBAC impact
      • Overview
      • Control access to dashboards
      • Control access to data tables
      • Control access to 1P cases and alerts
      • Control access to reference lists
    • Configure legacy RBAC
  • Configure SOAR access
    • Overview
    • Manage permission groups
      • Overview
      • Understand user groups
      • Create a managed user
      • Create a collaborator user
      • Create a view-only user
    • Manage SOC roles
    • Manage environments
      • Overview
      • Manage environment groups
      • Configure custom environment groups
    • Enable access
      • Enable SOAR access
      • Map users with Cloud identity
      • Map users with third-party identity
      • Apply multiple control access parameters
    • Enable federated access
    • View all users
    • Delete a user account
  • Configure compliance
    • Supported compliance standards
    • Data encryption at rest and in transit
    • Configure CMEK
    • Configure VPC service controls
  • Configure MCP
  • Configure instance settings
    • Manage operational settings
      • Define a landing page
      • Rebrand your platform
      • Set time zone
      • Configure email settings
      • Manage preview features
    • Manage data retention
      • Configure SIEM data retention
      • Configure SOAR data retention
    • Monitor and audit platform activity
      • Manage audit logs
      • Monitor user activities
    • Manage administrative assets
      • Create custom lists
      • Create email HTML templates
      • Create email templates
      • Add variables to email templates
      • Create user requests
      • Manage properties metadata
      • Retrieve raw Python logs
    • Manage case settings
      • Manage case stages
      • Configure case naming conventions
      • Create custom fields for cases
      • Manage custom case closure fields
      • Configure the close case dialog
      • Configure the default case view
    • Manage alert settings
      • Configure alert grouping
      • Configure alert overflow
      • Configure the default alert view
      • Exclude entities from alerts
    • Manage case and alert tags
    • Configure networks and multi-tenancy
      • Manage networks
      • Define domains for MSSPs
      • Manage environment load balancing
  • Upgrade and migrate
    • Migrate SOAR to Google Cloud
      • Overview
      • Pre-migration validation guide
      • Manage MSSP migration
      • Migrate SOAR permissions to IAM
      • Map SOAR permissions to IAM
      • Migrate to Chronicle API
      • SOAR API mapping table
      • Migrate remote agent authentication infrastructure
      • Authenticate remote agents with Workload Identity Federation
      • Frequently asked questions
    • Migrate SIEM to Google Cloud
      • SIEM migration overview
      • Migrate to a Google Cloud project
      • Migrate to Google Cloud authentication
      • Migrate from legacy RBAC to feature RBAC
    • Migrate from legacy SIEM APIs to Chronicle API
      • Overview
      • SIEM API endpoint mapping
    • Upgrade cloud storage data feeds to v2
    • Migrate an instance to a BYOP project
    • Migrate from legacy features
      • Migrate CBN alerts to YARA-L alerts
      • Migrate from CrowdStrike Detects API to Alerts API
  • Deprovision
  • Build and integrate
  • Deploy centralized content
    • Content Hub overview
    • Run use cases from the Content Hub
    • Power ups and utilities
      • Connectors
      • Email utilities
      • Enrichment
      • File utilities
      • Functions
      • GitSync
      • Image utilities
      • TemplateEngine
      • Insights
      • Lists
      • Tools
  • Develop custom capabilities
    • Use the IDE
    • Get started
      • Develop your first custom integration
      • Develop your first custom action
      • Develop your first email connector
      • Develop your first use case
    • Build and design custom components
      • Build custom integrations
      • Create custom actions
      • Write automated jobs
    • Build and configure connectors
      • Build connector logic
      • Configure custom connectors
      • Test custom connectors
    • Map and model alerts
    • Publish custom integrations
    • Advanced data modeling
      • Develop custom transformers
      • Configure calculated fields for cases
  • Manage response integrations
    • Configure response integrations
    • Roll back response integrations
    • Upgrade the Python version
    • Manage integration dependencies
    • Support multiple instances
    • Test response integrations
    • Manage secrets with secret managers
  • Manage remote agents
    • Get started
      • Overview
      • Review deployment requirements
      • Review data flow and protocols
    • Deploy remote agents
      • Deploy with Docker
      • Deploy with Podman
      • Deploy on Debian
      • Deploy on RHEL
      • Deploy on CentOS
      • Configure high availability
      • Redeploy connectors
      • Configure Workload Identity Federation
    • Configure and validate connectivity
      • Configure the Installer and Docker
      • Configure remote execution
      • Test the connection flow
    • Manage and upgrade remote agents
      • Remote agent scaling strategy
      • Monitor and manage remote agents
      • Perform a standard upgrade
      • Major upgrade with Docker
      • Major upgrade with Podman
      • Major upgrade with RHEL
      • Major upgrade with CentOS
      • Redeploy remote agents
    • Troubleshoot remote agents
  • Collaborate and share
    • Contribute community response integrations
    • Become a technology partner
  • Ingest
  • Prepare for data ingestion
    • Overview
    • Ingestion methods and data types
    • Ingest and parse log data
    • Parsers overview
    • Data feeds overview
    • Data enrichment and aliasing overview
  • Collect data
    • Work with the feeds UI
    • Create an Azure event hub feed
    • Ingest data with API connectors
    • Ingest data with the Ingestion API
    • Ingest Google Cloud logs
    • Collect data using webhooks
      • Set up a SOAR webhook
      • Set up a SIEM webhook
    • Deploy the Bindplane agent for collection
    • Collect data using SOAR connectors
      • Ingest data using SOAR connectors
      • Map custom date and time in Elasticsearch
      • Define environments in SOAR connectors
    • Collect data using legacy forwarders
      • Install and configure the forwarder
      • Configure forwarders in the platform
      • Manage forwarder configurations manually
      • Install Windows forwarder executable
    • Ingest logs with Cloud Run functions
    • Configure partner-hosted integrations
  • Configure log types and parsers
    • Default parsers and log types overview
    • List of default parser configuration guides
    • Request prebuilt and create custom log types
    • Support policy for standard parsers
    • Premium parsers
      • Apigee logs
      • AWS CloudTrail logs
      • AWS EC2 Hosts logs
      • AWS EC2 Instance logs
      • Chrome management logs
      • Cisco ASA firewall logs
      • Cloud SQL context Logs
      • Resource Manager context logs
      • CrowdStrike Falcon logs
      • Duo Activity logs
      • Fluentd logs
      • Fortinet Firewall logs
      • Google Cloud Abuse Events logs
      • Google Cloud Audit Logs
      • Google Cloud BigQuery context logs
      • Google Cloud DNS logs
      • Google Cloud Firewall logs
      • Google Cloud IAM context logs
      • Google Cloud Kubernetes context logs
      • Google Cloud Load Balancing logs
      • Google Cloud NAT logs
      • Google Cloud Run functions logs
      • Google Cloud SQL logs
      • Google Kubernetes Engine (GKE) logs
      • Google Workspace logs
      • Jamf parsers overview
      • Jamf Protect logs
      • Jamf Telemetry logs
      • Jamf Telemetry v2 logs
      • Jamf Threat Events logs
      • Microsoft 365 logs
      • Microsoft Defender for Endpoint logs
      • Microsoft Graph API alerts logs
      • Microsoft Windows AD logs
      • Microsoft Windows DHCP logs
      • Microsoft Windows DNS logs
      • Microsoft Windows Event logs
      • Microsoft Windows Sysmon logs
      • Network Connectivity Center context logs
      • NIX System logs
      • OCSF logs
      • OSSEC logs
      • osquery logs
      • Palo Alto Networks firewall logs
      • Security Command Center findings
      • SentinelOne Alert logs
      • SentinelOne Cloud Funnel logs
      • Splunk CIM logs
      • Zeek (Bro) logs
      • Zscaler CASB logs
      • Zscaler parsers overview
      • Zscaler Deception logs
      • Zscaler DLP logs
      • Zscaler DNS logs
      • Zscaler Firewall logs
      • Zscaler Internet Access logs
      • Zscaler Tunnel logs
      • Zscaler VPN logs
      • Zscaler Web Proxy logs
      • Zscaler ZPA logs
      • Zscaler ZPA Audit logs
      • Zscaler Email DLP
    • Standard Parsers A - B - C
      • A10 Network Load Balancer logs
      • Abnormal Security logs
      • Absolute Secure Endpoint logs
      • Acalvio logs
      • Active Countermeasures AI-Hunter logs
      • ADVA Fiber Service Platform logs
      • Agiloft logs
      • AIDE (Advanced Intrusion Detection Environment) logs
      • Airlock Digital Application Allowlisting logs
      • AIX system logs
      • Akamai Cloud Monitor logs
      • Akamai DataStream 2 logs
      • Akamai DNS logs
      • Akamai EAA (Enterprise Application Access) logs
      • Akamai SIEM Connector logs
      • Akamai WAF logs
      • Akeyless Vault logs
      • Alcatel switch logs
      • AlphaSOC alert logs
      • AlgoSec Security Management logs
      • Alveo Risk Data Management logs
      • Amazon CloudFront logs
      • AMD Pensando DSS firewall logs
      • Anomali ThreatStream IOC logs
      • Ansible AWX logs
      • Apache logs
      • Apache Cassandra logs
      • Apache Hadoop logs
      • Apache Tomcat logs
      • Appian Cloud logs
      • Apple macOS syslog data
      • AppOmni logs
      • Aqua Security logs
      • Arbor Edge Defense logs
      • Archer IRM logs
      • ArcSight CEF logs
      • Arista VeloCloud SD-WAN logs
      • Arista switch logs
      • Area 1 logs
      • Armis Activities logs
      • Armis Alerts logs
      • Armis Devices logs
      • Armis Vulnerabilities logs
      • Array Networks SSL VPN logs
      • Aruba AirWave logs
      • Aruba ClearPass logs
      • Aruba EdgeConnect SD-WAN logs
      • Aruba IPS logs
      • Aruba switch logs
      • Aruba Wireless Controller and Access Point logs
      • Asset Panda logs
      • Atlassian Bitbucket logs
      • Atlassian Cloud Admin Audit logs
      • Atlassian Confluence logs
      • Atlassian Jira logs
      • Attivo Networks BOTsink logs
      • Auth0 logs
      • Automation Anywhere logs
      • Avatier logs
      • Avaya Aura logs
      • Avigilon Access Control Manager logs
      • Aware audit logs
      • Aware Signals logs
      • AWS API Gateway access logs
      • AWS Aurora logs
      • AWS CloudWatch logs
      • AWS Config logs
      • AWS Control Tower logs
      • AWS ECS Metrics logs
      • AWS Elastic Load Balancing logs
      • AWS Elastic MapReduce logs
      • AWS GuardDuty logs
      • AWS IAM logs
      • AWS Inspector logs
      • AWS Key Management Service logs
      • AWS AWS Lambda Function logs
      • AWS Macie logs
      • AWS Network Firewall logs
      • AWS RDS logs
      • AWS Redshift logs
      • AWS Route 53 logs
      • AWS S3 server access logs
      • AWS Security Hub logs
      • AWS Session Manager logs
      • AWS VPC Flow logs
      • AWS VPC Transit Gateway flow logs
      • AWS VPN logs
      • AWS WAF logs
      • Azion firewall logs
      • Azure AD Sign-In logs
      • Azure API Management logs
      • Azure APP Service logs
      • Azure Application Gateway logs
      • Azure Cosmos DB logs
      • Azure Firewall logs
      • Azure NSG Flow logs
      • Azure Storage Audit logs
      • Azure VPN logs
      • Azure WAF logs
      • Barracuda CloudGen Firewall logs
      • Barracuda Email Security Gateway logs
      • Barracuda WAF logs
      • Barracuda Web Filter logs
      • BeyondTrust BeyondInsight logs
      • BeyondTrust EPM logs
      • BeyondTrust Privileged Identity logs
      • BeyondTrust Remote Support logs
      • BeyondTrust Secure Remote Access logs
      • Big Switch BigCloudFabric logs
      • Bitdefender logs
      • Bitwarden Enterprise event logs
      • BloxOne Threat Defense logs
      • BlueCat DDI logs
      • BlueCat Edge logs
      • Blue Coat ProxySG logs
      • BMC AMI Defender logs
      • BMC Client Management logs
      • BMC Helix Discovery logs
      • Box Collaboration JSON logs
      • Broadcom CA PAM logs
      • Broadcom SSL VA logs
      • Broadcom Support Portal Audit logs
      • Broadcom Symantec SiteMinder Web Access logs
      • Brocade ServerIron logs
      • Brocade switch logs
      • CA ACF2 logs
      • CA LDAP logs
      • Cambium Networks logs
      • Carbon Black App Control logs
      • Carbon Black EDR logs
      • Cato Networks logs
      • Censys logs
      • Centripetal Networks IOC logs
      • Cequence Bot Defense logs
      • Check Point Audit logs
      • Check Point EDR logs
      • Check Point firewall logs
      • Check Point Harmony logs
      • Check Point SmartDefense logs
      • ChromeOS XDR logs
      • Cimcor CimTrak logs
      • CipherTrust Manager logs
      • CircleCI audit logs
      • CIS Albert alert logs
      • Cisco AMP for Endpoints logs
      • Cisco APIC logs
      • Cisco Application Centric Infrastructure (ACI) logs
      • Cisco Application Control Engine (ACE) logs
      • Cisco CallManager logs
      • Cisco CloudLock CASB logs
      • Cisco CTS logs
      • Cisco DNA Center Platform logs
      • Cisco eStreamer logs
      • Cisco Firepower NGFW logs
      • Cisco FireSIGHT Management Center logs
      • Cisco Firewall Service Module (FWSM) logs
      • Cisco Identity Intelligence logs
      • Cisco IronPort logs
      • Cisco IOS logs
      • Cisco ISE logs
      • Cisco Meraki logs
      • Cisco PIX logs
      • Cisco Prime logs
      • Cisco Router logs
      • Cisco Secure Access logs
      • Cisco Secure ACS logs
      • Cisco Secure Email Gateway logs
      • Cisco Secure Workload logs
      • Cisco Stealthwatch logs
      • Cisco Switch logs
      • Cisco UCS logs
      • Cisco Umbrella Audit logs
      • Cisco Umbrella Cloud Firewall logs
      • Cisco Umbrella DNS logs
      • Cisco Umbrella IP logs
      • Cisco Umbrella Web Proxy logs
      • Cisco VCS logs
      • Cisco Vision Dynamic Signage Director logs
      • Cisco vManage SD-WAN logs
      • Cisco VPN logs
      • Cisco Web Security Applicance (WSA) logs
      • Cisco Wireless Intrusion Prevention System (WIPS) logs
      • Cisco Wireless LAN Controller (WLC) logs
      • Cisco Wireless Security Management (WiSM) logs
      • Citrix Analytics logs
      • Citrix Monitor Service logs
      • Citrix Receiver logs
      • Citrix StoreFront logs
      • ClamAV logs
      • Claroty CTD logs
      • Claroty xDome for Healthcare logs
      • Claroty xDome logs
      • Cloud Identity Devices logs
      • Cloud Identity Device Users logs
      • Cloud Intrusion Detection System (Cloud IDS) logs
      • Cloud Monitoring alerting activity logs
      • Cloud Next Generation Firewall logs
      • Cloud Run logs
      • Cloud Storage Context logs
      • Cloudflare logs
      • Cloudflare Page Shield logs
      • Cloudflare WAF logs
      • Cloudian HyperStore logs
      • CloudM logs
      • CloudPassage Halo logs
      • Code42 Incydr core datasets
      • Cofense logs
      • Cohesity logs
      • Colinet Trotta GAUS SEGUROS logs
      • Comforte SecurDPS logs
      • Commvault logs
      • CommVault Backup and Recovery logs
      • Comodo AV logs
      • Compute Engine context logs
      • Context Access Aware data
      • Corelight Sensor logs
      • COVID-19 Cyber Threat Coalition IOC logs
      • Cribl Stream logs
      • CrowdStrike Falcon logs in CEF
      • CrowdStrike Falcon Stream logs
      • CrowdStrike FileVantage logs
      • CrowdStrike IDP Services logs
      • CrowdStrike IOC logs
      • CrushFTP logs
      • CSV Custom IOC files
      • Custom Application Access logs
      • Custom DNS logs
      • Custom Security Data Analytics logs
      • Cyber 2.0 IDS logs
      • CyberArk EPM logs
      • CyberArk logs
      • CyberArk PAM logs
      • CyberArk Privilege Cloud logs
      • CyberArk Privileged Threat Analytics logs
      • Cybereason EDR logs
      • CyberGatekeeper NAC logs
      • CyberX logs
      • Cylance PROTECT logs
      • Cynet 360 AutoXDR logs
      • Cyolo OT logs
    • Standard Parsers D - E - F - G
      • D3 Banking logs
      • Datadog logs
      • Dataminr Alerts logs
      • Darktrace logs
      • Deep Instinct EDR logs
      • Delinea Distributed Engine logs
      • Delinea PAM logs
      • Delinea Secret Server logs
      • Delinea SSO logs
      • Dell CyberSense logs
      • Dell ECS logs
      • Dell EMC Data Domain logs
      • Dell EMC Isilon NAS logs
      • Dell EMC PowerStore logs
      • Dell OpenManage logs
      • Dell switch logs
      • Desynova Contido logs
      • DHS IOC logs
      • DigiCert audit logs
      • Digi Modems logs
      • DigitalArts i-Filter logs
      • Digital Guardian EDR logs
      • Digital Shadows Indicators logs
      • Digital Shadows SearchLight logs
      • DMP Entre logs
      • DNSFilter logs
      • DomainTools Iris Investigate results
      • Dope Security SWG logs
      • Druva Backup logs
      • Duo administrator logs
      • Duo authentication logs
      • Duo entity context logs
      • Duo Telephony logs
      • Duo User context logs
      • Edgio WAF logs
      • EfficientIP DDI logs
      • Elastic Auditbeat logs
      • Elastic Defend logs
      • Elastic Packet Beats logs
      • Elasticsearch logs
      • Elastic Windows Event Log Beats logs
      • Endpoint Protector DLP logs
      • Entrust nShield HSM audit logs
      • Epic Systems logs
      • Ergon Informatik Airlock IAM logs
      • ESET AV logs
      • ESET EDR logs
      • ESET Threat Intelligence logs
      • Evision FircoSoft logs
      • ExtraHop DNS logs
      • ExtraHop RevealX logs
      • Extreme switch logs
      • Extreme Wireless logs
      • F5 AFM logs
      • F5 ASM logs
      • F5 BIG-IP APM logs
      • F5 BIG-IP ASM logs
      • F5 BIG-IP LTM logs
      • F5 DNS logs
      • F5 Distributed Cloud Services logs
      • F5 Shape logs
      • F5 Silverline logs
      • F5 VPN logs
      • Falco IDS logs
      • Fastly CDN logs
      • Fastly WAF logs
      • Fidelis Network logs
      • File Scanning Framework logs
      • FileZilla FTP logs
      • FingerprintJS logs
      • FireEye alert logs
      • FireEye eMPS logs
      • FireEye ETP logs
      • FireEye HX logs
      • FireEye HX Audit logs
      • FireEye NX logs
      • FireEye NX Audit logs
      • FireEye PX logs
      • Fivetran logs
      • Forcepoint CASB logs
      • Forcepoint DLP logs
      • Forcepoint Email Security logs
      • Forcepoint Mail Relay logs
      • Forcepoint NGFW logs
      • Forcepoint Web Security logs
      • Forescout eyeInspect logs
      • Forescout NAC logs
      • ForgeRock OpenAM logs
      • ForgeRock OpenDJ logs
      • ForgeRock OpenIDM logs
      • Forseti Open Source logs
      • Fortinet DHCP logs
      • Fortinet FortiAnalyzer logs
      • Fortinet FortiAuthenticator logs
      • Fortinet FortiClient logs
      • Fortinet FortiDDoS logs
      • Fortinet FortiEDR logs
      • Fortinet FortiMail logs
      • Fortinet FortiManager logs
      • Fortinet FortiNAC logs
      • Fortinet FortiSASE logs
      • Fortinet FortiSandbox logs
      • Fortinet Switch logs
      • Fortinet Web Proxy logs
      • FortiWeb WAF logs
      • Fortra Digital Guardian DLP logs
      • Fortra Powertech SIEM Agent logs
      • GitGuardian Enterprise logs
      • GitHub audit logs
      • GitLab logs
      • Gmail logs
      • Google App Engine logs
      • Google Cloud IoT logs
      • Google Cloud Compute context logs
      • Google Cloud Compute logs
      • Google Cloud DNS Threat Detector logs
      • Google Cloud Identity Context logs
      • Google Cloud IDS logs
      • Google Cloud Looker Audit logs
      • Google Cloud Secure Web Proxy logs
      • Google Cloud VPC Flow logs
      • Group-IB Threat Intelligence logs
      • Guardicore Centra logs
    • Standard Parsers H - I - J - K
      • H3C Comware Platform Switch logs
      • HackerOne logs
      • Halcyon Anti-Ransomware logs
      • HAProxy logs
      • Harness IO audit logs
      • HashiCorp audit logs
      • HCL BigFix logs
      • HID DigitalPersona logs
      • Hillstone Firewall logs
      • Hitachi Content Platform logs
      • Honeyd logs
      • HP Linux logs
      • HP ProCurve logs
      • Huawei Switch logs
      • HPE Aruba Networking Central logs
      • HPE BladeSystem c7000 logs
      • HPE Nimble Storage OS logs
      • HUMAN Security logs
      • HYPR MFA logs
      • IBM AS/400 logs
      • IBM CICS logs
      • IBM DB2 logs
      • IBM Guardium logs
      • IBM Informix logs
      • IBM MaaS360 logs
      • IBM Mainframe Storage logs
      • IBM OpenPages logs
      • IBM QRadar logs
      • IBM Security Access Manager logs
      • IBM Security Identity Manager logs
      • IBM Security Verify SaaS logs
      • IBM Tivoli logs
      • IBM Verify Identity Access logs
      • IBM WebSphere Application Server logs
      • iBoss Web Proxy logs
      • Identity and Access Management (IAM) Analysis context logs
      • Illumio Core logs
      • Imperva Advanced Bot Protection logs
      • Imperva Attack Analytics logs
      • Imperva Audit Trail logs
      • Imperva CEF logs
      • Imperva Database logs
      • Imperva Data Risk Analytics (DRA) logs
      • Imperva FlexProtect logs
      • Imperva SecureSphere Management logs
      • Imperva WAF logs
      • Infoblox logs
      • Infoblox RPZ logs
      • Intel 471 Malware Intelligence logs
      • Intel 471 Watcher Alerts logs
      • Intel Endpoint Management Assistant logs
      • InterSystems Caché logs
      • ION Spectrum logs
      • IONIX Attack Surface Management logs
      • Island Enterprise Browser logs
      • Jamf Pro context logs
      • JAMF Security Cloud logs
      • Jenkins logs
      • JFrog Artifactory logs
      • JumpCloud Directory Insights logs
      • Juniper Junos logs
      • Juniper NetScreen Firewall logs
      • Kaseya Datto File Protection logs
      • Kaspersky AV logs
      • Kea DHCP logs
      • Keeper Enterprise Security logs
      • Kemp Load Balancer logs
      • Keycloak logs
      • Kiteworks (formally Accellion) logs
      • Kong Gateway logs
      • Kyriba Treasury Management logs
    • Standard Parsers L - M - N
      • Lacework Cloud Security logs
      • LenelS2 OnGuard logs
      • LimaCharlie EDR logs
      • LinkShadow NDR logs
      • Linux auditd and AIX systems logs
      • LogonBox logs
      • Lookout Mobile Endpoint Security logs
      • Lucid audit logs
      • ManageEngine AD360 logs
      • ManageEngine ADAudit Plus logs
      • ManageEngine ADManager Plus logs
      • ManageEngine Exchange Reporter Plus logs
      • ManageEngine Log360 logs
      • Mandiant Threat Intelligence Custom IOC logs
      • McAfee DLP logs
      • McAfee Firewall Enterprise logs
      • McAfee Web Gateway logs
      • Menlo Security Isolation Platform (MSIP) logs
      • Metabase logs
      • Micro Focus NetIQ Access Manager logs
      • Microsoft Azure Activity logs
      • Microsoft Azure AD logs
      • Microsoft Azure AD Audit logs
      • Microsoft Azure AD Context logs
      • Microsoft Azure DevOps audit logs
      • Microsoft Azure Key Vault logging logs
      • Microsoft Azure Resource logs
      • Microsoft Defender for Cloud Alert logs
      • Microsoft Defender for Endpoint logs
      • Microsoft Defender for Endpoint on iOS logs
      • Microsoft Defender for Identity logs
      • Microsoft Defender for Office 365 logs
      • Microsoft Dynamics 365 User Activity logs
      • Microsoft Exchange logs
      • Microsoft Graph Activity logs
      • Microsoft IAS / Network Policy Server (NPS) logs
      • Microsoft IIS logs
      • Microsoft Intune logs
      • Microsoft Intune Context logs
      • Microsoft LAPS logs
      • Microsoft Network Policy Server (NPS) logs
      • Microsoft Sentinel logs
      • Microsoft SharePoint (Office 365) logs
      • Microsoft SQL Server logs
      • Microsoft System Center Endpoint Protection (SCEP) logs
      • Microsoft Windows Defender ATP logs