Skip to main content

Event source integrations reference

AI summary
Lists the event source integrations in Imply Lumi with the receivers, source type assignment, and predefined pipeline for each. Covers log types including AWS, CrowdStrike, FortiGate, PAN, Windows, and Zscaler.

About AI summaries.

This topic provides a reference for the event source integrations available in Imply Lumi. Go to Integrations and see the Connect sources section for integrations that accommodate specific logs and event structures:

Event source integrations

Each integration guides you through configuring a transport mechanism to send a specific log type and has an analogous predefined pipeline that processes the events.

Each section in this topic lists the following information:

  • Receivers: Transport mechanisms you can configure on the integration page.
  • Source type assignment: Value for the sourcetype user attribute for event labeling and pipeline processing.
  • Predefined pipeline: Name of the pipeline created by Lumi to extract key information from your events. Select the predefined pipeline to view an example of the processed event.

A log type isn't limited to the listed receivers. If you use another receiver, ensure that incoming events list the correct sourcetype so the predefined pipeline can transform them. For ways to assign the source type, see Assign Splunk® default fields.

AWS CloudTrail logs

AWS CloudTrail events record actions taken in AWS accounts, including management, data, network activity, and insights events.

AWS VPC flow logs

Amazon VPC flow logs capture metadata about the IP traffic going to and from network interfaces in your Virtual Private Cloud (VPC). Because it's simple to configure AWS to send VPC flows to an S3 bucket, S3 pull is a popular option.

CrowdStrike FDR logs

CrowdStrike Falcon® is an endpoint security platform that generates logs for endpoint telemetry, detections, and Falcon sensor alerts. The Falcon Data Replicator (FDR) collects, enriches, and replicates the logs for use in observability workflows.

FortiGate event logs

FortiGate event logs record system and administrative events, including admin logins, reboots, or VPN status.

FortiGate traffic logs

FortiGate traffic logs record traffic flow information for the traffic that passes through FortiGate to your network.

FortiGate UTM logs

FortiGate UTM logs record security information from Unified Threat Management (UTM) events.

PAN firewall logs

Palo Alto Networks (PAN) Next-Generation Firewall logs store details about system events on the firewall and network traffic events that the firewall monitors. There are multiple formats of PAN firewall logs, each representing a specific event type, such as traffic, threat, or system events.

PAN Traps logs

Palo Alto Networks (PAN) Traps logs originate from the Traps endpoint detection and response agent, now part of Cortex XDR. Traps logs come in several formats (analytics, config, system, and threat) and track information including agent configuration and malware prevention events.

Unix and Linux logs

Unix and Linux logs store information about events that occur on the operating system, such as system activity, kernel errors, and cron jobs.

Windows event logs

Windows event logs capture events for the Microsoft Windows operating system and applications that run on it.

  • Receivers: S3 pull, Splunk - httpout, Splunk - HEC
  • Source type assignment: A Windows-specific value such as WinEventLog or XmlWinEventLog. For the full list, see the pipeline conditions.
    Unlike other log types, the Windows predefined pipeline also matches on Windows-specific source values, such as source=WinEventLog*.
    If your events already carry the source metadata, you don't need to assign a source type.
  • Predefined pipeline: Windows event logs

Zscaler NSS logs

Zscaler Nanolog Streaming Service (NSS) collects and forwards event logs from a Nanolog. Lumi processes Web and Firewall logs from Zscaler NSS. Incoming events must be in key-value pair format using the equality (=) separator. For example, log_subtype=nss_web.

Learn more

See the following topics for more information: