Integration Category
SIEM & Log Platform Integrations
Splunk, Elastic, Microsoft Sentinel, Google SecOps — ManySignal integrates with your existing SIEM during migration, or as an AI triage layer on top of legacy detection platforms.
SIEM and log platform integrations
Splunk
Search results, notable events, saved searches via HEC and REST API
Elastic Security
Alerts, detection signals, and raw events from Elasticsearch
Microsoft Sentinel
Sentinel incidents, alerts, and Log Analytics workspace events
Google SecOps
Chronicle detections, UDM events, and SOAR case data
IBM QRadar
Offenses, events, and flow data via REST API
Sumo Logic
Cloud SIEM signals and log search results
Datadog
Security signals, logs, and cloud SIEM detections
Chronicle
UDM event stream and detection alert ingestion
SIEM integration FAQs
Why would I integrate ManySignal with an existing SIEM?
Common scenarios: (1) Using ManySignal as an AI triage layer on top of an existing SIEM during migration. (2) Ingesting existing SIEM detections into ManySignal for correlated investigation with identity and endpoint context. (3) Using ManySignal for specific high-priority alert types while retaining the SIEM for compliance log storage.
Can ManySignal replace my SIEM entirely?
Yes. ManySignal handles log ingestion, OCSF normalisation, detection, correlation, and AI triage — the full SIEM stack — without requiring a separate SIEM. Many organisations use the SIEM integration for a 30-day migration period, then decommission the legacy SIEM.
How does ManySignal connect to Splunk?
ManySignal connects to Splunk via the Splunk HEC (HTTP Event Collector) for event forwarding, or the Splunk REST API for searching and forwarding notable events and search results to ManySignal for AI triage.
Does ManySignal ingest Elasticsearch raw events?
Yes. ManySignal connects to Elasticsearch via the REST API to pull detection signals, security alerts, and raw events from specified indices. OCSF normalisation is applied on ingestion.
Can I use both a SIEM and ManySignal simultaneously?
Yes. This is the standard migration pattern: both platforms ingest the same log sources for 30 days. You compare detection quality and analyst experience, then cut over to ManySignal exclusively when ready.
Does ManySignal support Microsoft Sentinel as a data source?
Yes. ManySignal can ingest Sentinel incidents and alerts via the Microsoft Graph Security API, and raw Log Analytics events via the Logs Ingestion API. This supports both a migration path and a hybrid deployment.
Can ManySignal enhance Splunk detections with AI triage?
Yes. Configure Splunk to forward notable events to ManySignal via HEC. ManySignal performs AI investigation and verdict on each notable event, correlating it with identity, cloud, and endpoint context from ManySignal's own connectors.
What is the performance impact of dual-ingestion during migration?
Log source dual-shipping (sending to both SIEM and ManySignal) adds minimal overhead to the log source. ManySignal's ingestion pipeline is designed to handle high-volume parallel ingestion without impacting existing SIEM performance.
Does ManySignal support Datadog Cloud SIEM?
Yes. Datadog Security Signals and log events are ingested by ManySignal via the Datadog API. ManySignal correlates Datadog signals with Okta, AWS CloudTrail, and endpoint events for richer investigation context.
How long should I run both SIEM and ManySignal in parallel?
30 days is the typical parallel run period. This gives your team time to validate detection coverage, build analyst confidence in ManySignal, and complete detection rule migration. Some organisations extend to 60 days for complex environments.
Migrate from your SIEM to ManySignal
Start a 30-day parallel evaluation — keep your SIEM running while ManySignal's AI agents work your alert queue.