M ManySignal
MS
KF
Integration

Kafka Integration

Stream any security event topic into ManySignal in real time.

What this integration does

Apache Kafka meets agentic SOC

Apache Kafka is the backbone for high-volume event streaming in many enterprise data platforms. ManySignal's Kafka connector subscribes to one or more Kafka topics and ingests security-relevant events in real time, supporting custom log formats, OCSF, CEF, LEEF, and raw JSON — with schema registry integration for evolving message formats.

Consumer group subscription to configurable Kafka topics

Schema Registry integration for Avro and JSON schema validation

OCSF, CEF, LEEF, and raw JSON message format support

Data collected

  • Any event published to configured Kafka topics
  • Consumer group lag metrics for ingestion health monitoring

Actions supported

  • Publish verdict or action event to Kafka topic
  • Produce alert correlation result to downstream consumer

Getting started

Set up in minutes

  1. 1

    Identify target topics

  2. 2

    Configure authentication

  3. 3

    Connect in ManySignal

Kafka Integration: frequently asked questions

Can ManySignal handle high-throughput Kafka topics?

Yes. ManySignal's Kafka consumer scales horizontally. Configure consumer parallelism based on Kafka partition count. For very high-volume topics, apply upstream topic filtering or sampling to reduce load.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.