Supported Integrations (Security Data Lake)

Prev Next

Red Canary supports a diverse array of security providers for both Managed Detection and Response (MDR) and storage in the Security Data Lake.

To add your data to the data lake, you can enable storage on any of your active MDR integrations. Alternatively, you can configure a data lake-only integration — this enables Security Data Lake support for data sources without a product-specific integration or in cases where you need to store additional data that isn’t used for MDR.

MDR integrations

On the Integrations page in the Red Canary portal, there are many product-specific MDR integrations specified. For core anchor integrations, Red Canary can help you with configuration of that integration. For other integrations, Red Canary can help with troubleshooting, but cannot guide the setup of the external data source.

Integrations with configuration support

Provider

Supported Platform

Class of Security Data

Data Lake Use Case

Amazon Web Services

AWS

Cloud

Retention, Search, Context

Broadcom

Carbon Black Cloud

EDR

Retention, Search, Context

Broadcom

Carbon Black EDR

EDR

Retention, Search, Context

CrowdStrike

Falcon Insight XDR

EDR

Retention, Search, Context

Google

Cloud Platform (GCP)

Cloud

Retention, Search, Context

Google

Workspace

SaaS

Retention, Search, Context

Microsoft

Azure

Cloud

Retention, Search, Context

Microsoft

Defender for Endpoint

EDR

Retention, Search, Context

Microsoft

Entra ID

Identity

Retention, Search, Context

Microsoft

Office 365 Management API

SaaS

Retention, Search, Context

Okta

Workforce Identity

Identity

Retention, Search, Context

Palo Alto Networks

Cortex XDR

EDR

Retention, Search, Context

Red Canary

Linux EDR

EDR

Retention, Search, Context

SentinelOne

Singularity

EDR

Retention, Search, Context

Trend Micro

Vision One

EDR

Retention, Search, Context

Self-configured integrations

Provider

Supported Platform

Class of Security Data

Data Lake Use Case

Cisco

Duo

Identity

Retention, Search, Context

Cisco

Firepower

Network

Retention, Search, Context

Cisco

Meraki

Network

Retention, Search, Context

Cisco

Umbrella

Network

Retention, Search, Context

CrowdStrike

Falcon Identity Protection

Identity

Retention, Search, Context

Darktrace

ActiveAI Security Platform

Network

Retention, Search, Context

Dragos

Platform

Operational Technology (OT)

Retention, Search, Context

ExtraHop

RevealX

Network

Retention, Search, Context

ExtraHop

Enterprise

Network

Retention, Search, Context

Fortinet

FortiAnalyzer

Network

Retention, Search, Context

Fortinet

FortiGate

Network

Retention, Search, Context

Fortinet

Lacework FortiCNAPP

Cloud

Retention, Search, Context

Jamf

Pro/Protect

EDR

Retention, Search, Context

Microsoft

Defender for Cloud

Cloud

Retention, Search, Context

Microsoft

Defender for Cloud Apps

Identity

Retention, Search, Context

Microsoft

Defender for Identity

Identity

Retention, Search, Context

Microsoft

Defender for Office 365

Email

Retention, Search, Context

Microsoft

Entra ID Protection

Identity

Retention, Search, Context

Microsoft

Sentinel

SIEM

Retention, Search, Context

Palo Alto Networks

PAN-OS

Network

Retention, Search, Context

Palo Alto Networks

Threat Prevention

Network

Retention, Search, Context

Palo Alto Networks

Wildfire

Network

Retention, Search, Context

Proofpoint

Targeted Attack Protection (TAP)

Email

Retention, Search, Context

Wiz

Wiz

Cloud

Retention, Search, Context

In addition to the list of investigated sources above, there are also hundreds of contextual sources (marked as “stored only” in the Red Canary portal). The list of contextual integrations is too long to list, so to check if a product-specific integration is available, log into your Red Canary portal, navigate to the Integrations page, and search for the desired source platform. If there is a tile available, the data can be stored in the Security Data Lake.

Enabling data lake retention on an MDR integration

  1. From your Red Canary portal, navigate to Integrations and select the integration of interest.

  2. Find Customize how this data is retained, and select Store in the Security Data Lake.

  3. Specify the desired data retention period in days and click Save.

Data Lake-only integrations

For all data lake-only integrations, Red Canary can help with troubleshooting, but cannot guide the setup of the external data source.

For a few external sources, there are dedicated product-specific integrations offered. For other situations where you need a data lake-only integration, we recommend using a generic integration. If a data source can be configured to write logs to an Amazon S3 bucket or securely forward logs to an external syslog server, it can be integrated with the Security Data Lake using a generic integration. If you need help validating if a specific data source is supported, please contact your Red Canary account representative.

Product-specific integrations

Provider

Supported Platform

Class of Security Data

Data Lake Use Case

Cisco

Cisco Adaptive Security Appliance (ASA)

Network

Retention, Search, Context

Cisco

Cisco Firepower Threat Defense (FTD)

Network

Retention, Search, Context

Zscaler

Zscaler Internet Access (ZIA)

Network

Retention, Search, Context

Generic integrations

Ingest Method

Data Format

Example Sources

Data Lake Use Case

Amazon S3 (Red Canary managed)

Line-delimited JSON (Plain text supported for retention-only)

Cloudflare, Logstash

Retention, Search, Context

Amazon S3 (Self-managed)

Line-delimited JSON (Plain text supported for retention-only)

AWS, Cato Networks, Netskope

Retention, Search, Context

Syslog

RFC 3164 or RFC 5424

NetScaler WAF, NXLog, PAN-OS, rsyslog, syslog-ng, Zscaler Private Access

Retention, Search, Context

Configuring a data lake-only integration

Depending on the data source you are interested in configuring, follow the desired link in the tables above to see setup instructions, prerequisites, available search fields, etc.

When would I use an MDR integration versus a data lake-only integration?

If you have data you are sending to Red Canary for MDR that you would also like to store long-term (e.g.: to comply with data retention policies), enabling data lake storage on your existing MDR integration ensures that you only have to send the data once, and can minimize the setup needed.

When would I use a data lake-only integration versus an MDR integration?

There are a few instances where a data lake-only integration is a preferred approach:

  1. When the data being sent to Red Canary for MDR does not contain all the logs you need to store. For example, if you have configured a PAN-OS integration to forward Wildfire alerts for investigation, but you would like to retain additional firewall logs for long-term retention, you can set up a generic syslog integration that forwards the firewall telemetry of interest.

  2. When there is not a product-specific MDR integration available. While Red Canary offers hundreds of MDR integrations, there are many more security products our customers use than we can directly support. For many of those products, they can be configured to forward logs via Amazon S3, syslog, or a third-party log collector. For help validating the best integration path for a specific data source, please contact your Red Canary account representative.