Skip to content
Active incident? 24/7 Incident Response hotline(877) 446-8422 · Request urgent callback

ONWATCH / INTEGRATIONS

Integrations catalog.

The systems OnWatch is designed to connect to, what each would collect, and what access it needs. Nothing below is a claim of confirmed support.

Illustrative IGH agent in a grey tech jacket and IGH headset

STATUS

Verification required

Every named vendor is a candidate — verification required / not confirmed supported. Compatibility, versions and response actions are confirmed in writing during scoping. Response actions never run without your authorization.

CATALOG

By source

SourceCandidate vendorsStatusPurpose / data collectedRead-only vs response actionPermissions / licensingSetup / health / failureVersions / limits
IdentityMicrosoft Entra ID, Okta, Google Workspace identityVerification requiredSign-in and audit logs, MFA and admin changes, risky usersRead-only proposed; account disable/session revoke = response action, only if verified and authorizedTenant admin consent to audit/sign-in log APIs; premium licence tier may be required for some logsScoping confirms tenant, app registration and log retention; health = log freshness check; failure alerts to IGHSupported API versions and retention to be documented
EmailMicrosoft 365 / Exchange Online, Google Workspace GmailVerification requiredMailbox audit, forwarding/inbox rules, message traceRead-only proposed; message purge = response action if verifiedAdmin consent to audit and message trace APIs; audit logging must be enabledConfirm audit settings; health = ingestion lagLog latency and retention set by provider tier
EndpointsMicrosoft Defender for Endpoint, CrowdStrike Falcon, SentinelOneVerification requiredEDR alerts, process and device telemetryRead-only proposed; host isolation = response action if verified and authorizedAPI client with alert/device read scopes; isolation scope only with written approvalCustomer-owned licence required; health = device check-in and alert flowSupported console/API versions to be documented
CloudAWS CloudTrail, Azure Activity/Monitor, Google Cloud Audit LogsVerification requiredControl-plane activity, IAM changes, configuration driftRead-onlyRead-only role / log export destinationAccount/subscription list confirmed during scoping; health = trail/export statusMulti-account coverage and regions to be documented
NetworkPalo Alto Networks, Fortinet FortiGate, Cisco firewallsVerification requiredFirewall/VPN logs, remote-access sessionsRead-only (log forwarding); block rules not proposedSyslog/API forwarding configured by customerCollector location agreed; health = event rate baselineEnterprise IT only — no OT/ICS network monitoring
LogsSyslog, Windows Event Forwarding, existing SIEM exportVerification requiredServer and application logsRead-onlyForwarding configuration by customerParsing validated per source; health = parse error rateVolume and retention depend on agreement

Scroll sideways on small screens. Not listed? Ask during scoping.

Check your stack

We’ll confirm what can connect before you commit.