ONWATCH / INTEGRATIONS
Integrations catalog.
The systems OnWatch is designed to connect to, what each would collect, and what access it needs. Nothing below is a claim of confirmed support.

STATUS
Verification required
Every named vendor is a candidate — verification required / not confirmed supported. Compatibility, versions and response actions are confirmed in writing during scoping. Response actions never run without your authorization.
CATALOG
By source
| Source | Candidate vendors | Status | Purpose / data collected | Read-only vs response action | Permissions / licensing | Setup / health / failure | Versions / limits |
|---|---|---|---|---|---|---|---|
| Identity | Microsoft Entra ID, Okta, Google Workspace identity | Verification required | Sign-in and audit logs, MFA and admin changes, risky users | Read-only proposed; account disable/session revoke = response action, only if verified and authorized | Tenant admin consent to audit/sign-in log APIs; premium licence tier may be required for some logs | Scoping confirms tenant, app registration and log retention; health = log freshness check; failure alerts to IGH | Supported API versions and retention to be documented |
| Microsoft 365 / Exchange Online, Google Workspace Gmail | Verification required | Mailbox audit, forwarding/inbox rules, message trace | Read-only proposed; message purge = response action if verified | Admin consent to audit and message trace APIs; audit logging must be enabled | Confirm audit settings; health = ingestion lag | Log latency and retention set by provider tier | |
| Endpoints | Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne | Verification required | EDR alerts, process and device telemetry | Read-only proposed; host isolation = response action if verified and authorized | API client with alert/device read scopes; isolation scope only with written approval | Customer-owned licence required; health = device check-in and alert flow | Supported console/API versions to be documented |
| Cloud | AWS CloudTrail, Azure Activity/Monitor, Google Cloud Audit Logs | Verification required | Control-plane activity, IAM changes, configuration drift | Read-only | Read-only role / log export destination | Account/subscription list confirmed during scoping; health = trail/export status | Multi-account coverage and regions to be documented |
| Network | Palo Alto Networks, Fortinet FortiGate, Cisco firewalls | Verification required | Firewall/VPN logs, remote-access sessions | Read-only (log forwarding); block rules not proposed | Syslog/API forwarding configured by customer | Collector location agreed; health = event rate baseline | Enterprise IT only — no OT/ICS network monitoring |
| Logs | Syslog, Windows Event Forwarding, existing SIEM export | Verification required | Server and application logs | Read-only | Forwarding configuration by customer | Parsing validated per source; health = parse error rate | Volume and retention depend on agreement |
Scroll sideways on small screens. Not listed? Ask during scoping.
Check your stack
We’ll confirm what can connect before you commit.