PODCAST
How AI is changing the SOC operating model. Listen now →
close
How AI is changing the SOC operating model. Listen now →
close
How AI is changing the SOC operating model. Listen now →
close
Integrate your stack
All your security data and workflows, connected.
Featured Integrations
All Integrations
Log Sources
Cloud
Network
Host
Application
On-Prem
Alert Destinations
Enrichment
Data Lake
Cloud Resources
MCP Servers

Panther Log Forwarder
Get on-premises logs into Panther without the infrastructure overhead.
On-Prem

Google Threat Intelligence
Enrich detections with real-time IoCs from Google Threat Intelligence.
Enrichment

Hex Log Monitoring
Monitor user activity and data access across your Hex workspace.
Application
Anthropic Compliance Log Monitoring
Monitor administrative and security activity across your Anthropic organization.
Application

Slack MCP Server
Send messages and search your Slack workspace directly from Panther AI.
MCP Servers
PagerDuty MCP Server
Manage incidents and on-call schedules directly from Panther AI.
MCP Servers

Notion MCP Server
Search and update your Notion workspace directly from Panther AI.
MCP Servers
GitHub MCP Server
Interact with your repositories and code security tools directly from Panther AI.
MCP Servers

Atlassian MCP Server
Take action in Jira and Confluence directly from Panther AI.
MCP Servers

Island Enterprise Browser Log Monitoring
Monitor browser activity, DLP events, and administrative actions across your enterprise.
Application

SOCRadar Log Monitoring
Bring external threat intelligence into your security operations workflow.
Application

Upwind Log Monitoring
Detect runtime threats across your cloud environment.
Cloud

Iru Log Monitoring
Monitor endpoint management activity across your device fleet.
Host

AWS Network Load Balancer Log Monitoring
Monitor TLS connection activity across your AWS network infrastructure.
Cloud

Amazon Bedrock Model Invocation Log Monitoring
Monitor AI model usage and invocation activity across your AWS environment.
Cloud

Microsoft Entra ID Audit Log Monitoring
Monitor identity activity and authentication events across your Azure environment.
Application

OpenAI Log Monitoring
Monitor administrative and security activity across your OpenAI organization.
Application

Open Threat Exchange (OTX)
Enrich detections with community-driven threat intelligence.
Enrichment

Databricks
Detect and investigate threats in your Databricks data lake
Data Lake

Docusign Log Monitoring
Detect fraud and monitor activity across your eSignature workflows.
Application

Microsoft Intune Log Monitoring
Monitor device compliance and endpoint management activity across your organization.
Application

Axonius Log Monitoring
Gain security visibility across your asset inventory.
Application

Snowflake Audit Log Monitoring
Monitor user activity and queries across your Snowflake instance.
Application

Snowflake Enrichment
Add Snowflake identity and access context to your detections.
Enrichment

Microsoft Defender XDR Log Monitoring
Correlate Defender XDR events with your full security data set.
Application
Orca Security Log Monitoring
Cloud
Mindflow
Automate incident response from your alerts
Alert Destinations

Rapid7 Log Monitoring
Centralize Rapid7 audit activity alongside your full security data set.
Application
Tracebit Log Monitoring
Monitor activity on Tracebit security canaries across your organization
Application

Amazon Security Lake & OSCF Log Monitoring
Inspect your OSCF data for signs of unusual behavior.
Cloud

Proofpoint Log Monitoring
Detect email attacks.
Application
AWS CloudFront Log Monitoring
Analyze CDN traffic for signs of unusual behavior.
Cloud

Thinkst Canary Log Monitoring
Detect lateral movement in your environment.
Application
Wiz Log Monitoring
Protect your cloud security controls.
Cloud
Zscaler Log Monitoring
Monitor application, network, and device access.
Application
Material Security SIEM Integration
Monitor threats in Google Workspace and M365.
Application
Custom Lookup Tables
Enrich log data from custom sources.
Enrichment
Anomali ThreatStream API SIEM Integration
Correlate log data with threat intelligence.
Enrichment

Torq
Trigger automated workflows from your alerts
Alert Destinations

Sublime Security SIEM Integration
Monitor email threats.
Application

Push Security SIEM Integration
Defend against identity attacks.
Host

Blink Ops
Deliver Panther alerts to your automation platform
Alert Destinations

AppOmni SIEM Integration
Monitor your Software as a Service security posture.
Application
Incident.io
Forward Panther alerts to your incident management platform
Alert Destinations

Discord
Route Panther alerts to a Discord channel
Alert Destinations

IPInfo
Enrich detections and reduce false-positive alerts
Enrichment

Splunk
Send Panther alerts to Splunk
Alert Destinations

AWS Security Hub Monitoring
Correlate AWS Security Hub findings.
Cloud

Notion Log Monitoring
Continuously monitor your Notion workspace.
Application

Tenable Vulnerability Scan Monitoring
Gain complete visibility into your network assets.
Application

Envoy Access Log Monitoring
Monitor network activity for suspicious behavior.
Network

Carbon Black Log Monitoring
Monitor endpoint activity for suspicious behavior.
Host

Azure Log Monitoring
Continuously monitor your Azure account.
Cloud

Docker Event Log Monitoring
Gain complete visibility into your Docker system events.
Application

Netskope Log Monitoring
Identify any suspicious cloud-based app or service activity.
Application

Auditd Log Monitoring
Monitor system-level activities in your Linux environment.
Host

Heroku Log Monitoring
Monitor your Heroku applications, infrastructure, and admin actions.
Cloud

Windows Event Log Monitoring
Monitor application, system, and security notifications from Windows machines.
Host

Tailscale Log Monitoring
Monitor your team’s Tailscale network.
Network

Auth0 Log Monitoring
Monitor user authentication and authorization activities in Auth0.
Application

AWS ALB Log Monitoring
Monitor requests sent to your load balancer for suspicious activity.
Cloud

AWS Aurora Log Monitoring
Monitor and detect any suspicious database events.
Cloud

AWS CloudTrail Log Monitoring
Identify any suspicious activity within your AWS infrastructure.
Cloud

AWS CloudWatch Log Monitoring
Monitor any resource changes within your AWS environment.
Cloud

AWS Config Log Monitoring
Monitor the configuration of your AWS resources.
Cloud

AWS EKS Log Monitoring
Monitor your Kubernetes environment for suspicious activity.
Cloud

AWS GuardDuty Log Monitoring
Monitor your AWS environment for malicious activity and unauthorized behavior.
Cloud

AWS S3 Log Monitoring
Monitor all requests made to AWS S3 buckets.
Cloud

AWS Transit Gateway Flow Log Monitoring
Monitor the IP traffic flowing through your transit gateway.
Cloud

AWS VPC Log Monitoring
Monitor the IP traffic going to and from network interfaces in your VPC.
Cloud

AWS WAF Log Monitoring
Investigate traffic that is analyzed by your web Access Control Lists (ACLs).
Cloud

Tines Log Monitoring
Monitor any changes within your Tines tenant.
Application

Bitwarden Log Monitoring
Identify any abnormal user activity in your organization's Bitwarden account.
Application

Sysdig Log Monitoring
Gain complete visibility into Sysdig platform activity.
Application

SentinelOne Log Monitoring
Monitor your endpoint data, network activity, and DNS requests.
Host

MongoDB Atlas Log Monitoring
Monitor events within your MongoDB Atlas organization or project.
Application

Microsoft Graph Log Monitoring
Monitor security alerts across Microsoft products, services, and partners.
Application

Jamf Pro Log Monitoring
Monitor Jamf Pro login events for suspicious activity.
Application

Dropbox Log Monitoring
Identify any suspicious file-sharing activity within your organization.
Application

Snyk Log Monitoring
Monitor for any changes within your Snyk Organization.
Application

Zendesk Log Monitoring
Monitor unusual activity within your Zendesk account.
Application

Asana Log Monitoring
Monitor Asana audit logs to identify suspicious activity in real-time.
Application

Atlassian Log Monitoring
Monitor Atlassian audit logs to identify suspicious activity in real-time.
Application

1Password Log Monitoring
Monitor your password management platform for suspicious activity.
Application

Zoom Log Monitoring
Monitor abnormal user activity within your Zoom account.
Application
Salesforce Log Monitoring
Monitor your sales operations data for suspicious activity.
Application

GitHub Log Monitoring
Identify any vulnerabilities within your GitHub repositories.
Application

Microsoft 365 Log Monitoring
Monitor your team’s communication and collaboration tools for suspicious activity.
Application

Slack Log Monitoring
Monitor your team’s communication platform for suspicious activity.
Application

Tines
Send Panther alerts to Tines and initiate a workflow
Alert Destinations

Duo Security Log Monitoring
Monitor your access management tools for suspicious activity.
Application

Sophos Log Monitoring
Monitor endpoint policy violations and data loss prevention events.
Host

Custom Webhooks
Send alert data to third-party applications
Alert Destinations

Fastly Log Monitoring
Monitor network traffic for signs of suspicious behavior.
Network

Cloudflare Log Monitoring
Inspect network traffic for signs of suspicious behavior.
Network

CrowdStrike Log Monitoring
Gain complete visibility into your managed endpoints.
Host

EC2 Instance
Track real-time changes to your EC2 Instance
Cloud Resources

EC2 AMI
Monitor which AWS accounts can use AMI to launch instances
Cloud Resources

EC2 Volume
Continuously audit your EC2 Volume configurations
Cloud Resources

EC2 Network ACL
Audit changes to AWS Network ACL
Cloud Resources

EC2 Security Group
Audit changes to the security group in your EC2 instances.
Cloud Resources

PagerDuty
Send Panther alerts to PagerDuty and begin an investigation
Alert Destinations

SNS
Send programmatic alerts to emails with Panther via SNS
Alert Destinations

GCP Log Monitoring
Gain complete visibility into activity across your cloud service.
Cloud

Syslog Log Monitoring
Monitor machine and network activity for suspicious behavior.
Host

Fluentd Log Monitoring
Inspect application activity for any signs of suspicious behavior.
Host

Zeek Log Monitoring
Inspect network traffic and DNS protocols for suspicious activity.
Network

Cisco Umbrella Log Monitoring
Identify any suspicious or malicious domain addresses or DNS requests.
Network

Juniper Log Monitoring
Monitor network traffic for attack attempts or probes.
Network

Suricata Log Monitoring
Identify any suspicious traffic or domain activity.
Network

Lacework Log Monitoring
Gain complete visibility into your cloud and container environments.
Application

Teleport Log Monitoring
Inspect all SSH access activity for signs of suspicious behavior.
Application

Apache Log Monitoring
Inspect all web activity for signs of suspicious behavior.
Network

GitLab Log Monitoring
Identify any suspicious behavior within your GitLab environment.
Application

Okta Log Monitoring
Monitor Okta logs to gain complete visibility into your IdP activity.
Application

OneLogin Log Monitoring
Monitor your IdP for suspicious activity.
Application

Google Workspace (G Suite) Log Monitoring
Identify any suspicious activity within your Google Workspace applications.
Application

Box Log Monitoring
Gain complete visibility into your organization’s content management and file sharing.
Application

Snowflake
Build a robust security data lake in Snowflake.
Data Lake

AWS CloudTrail Log Analyzer
Track account changes in real-time and detect suspicious activity
Cloud Resources

S3 Buckets
Detect and alert on unauthorized access to your S3 buckets.
Cloud Resources

EC2 VPC
Capture traffic activity and monitor actual network traffic flows.
Cloud Resources

GuardDuty
Track real-time changes to your AWS GuardDuty
Cloud Resources

Lambda
Track real-time changes to your AWS Lambda
Cloud Resources

WAF Web ACL
Track real-time changes to your WAF ACLs
Cloud Resources

ALB
Audit changes to AWS Application Load Balancer
Cloud Resources

ACM Certificate
Audit changes to AWS Certificate manager
Cloud Resources

Redshift Cluster
Audit changes to AWS Redshift Clusters
Cloud Resources

DynamoDB Table
Continuously monitor AWS DynamoDB tables for compliance
Cloud Resources

Config Recorder
Audit changes to AWS Config Recorder
Cloud Resources

CloudWatch Log group
Track real-time changes to AWS CloudWatch Log group
Cloud Resources

CloudFormation Stack
Track real-time changes to AWS CloudFormation stacks
Cloud Resources

RDS Instance
Get alerted in real-time when a RDS change occurs.
Cloud Resources

Password Policy
Monitor password policies for your AWS account
Cloud Resources

IAM
Track real-time changes to IAM User, Group, Role, and Policy
Cloud Resources

KMS Key
Follow the highest standards of cryptographic practices.
Cloud Resources

ECS Cluster
Gain visibility into specific ECS environments in real-time.
Cloud Resources

OSSEC Log Monitoring
Monitor OSSEC logs to gain complete security visibility into host activity.
Host

Asana
Send Panther alerts to Asana and analyze the issue.
Alert Destinations

OpsGenie
Send Panther alerts to OpsGenie and begin an investigation.
Alert Destinations

Jira
Send Panther alerts to Jira and analyze the issue
Alert Destinations

Slack
Send Panther alerts to a designated Slack channel.
Alert Destinations

GitHub
Send Panther alerts to GitHub and analyze the issue
Alert Destinations

SQS
Send programmatic notifications to emails with Panther via SQS
Alert Destinations

Microsoft Teams
Send Panther alerts to a designated Microsoft Teams channel
Alert Destinations
Nginx Access Log Monitoring
Monitor Nginx access logs and gain complete visibility into web server activity.
Network

Osquery Log Monitoring
Gain complete visibility into your operating system activity.
Host
All Integrations
Log Sources
Cloud
Network
Host
Application
On-Prem
Alert Destinations
Enrichment
Data Lake
Cloud Resources
MCP Servers

Panther Log Forwarder
Get on-premises logs into Panther without the infrastructure overhead.
On-Prem

Google Threat Intelligence
Enrich detections with real-time IoCs from Google Threat Intelligence.
Enrichment

Hex Log Monitoring
Monitor user activity and data access across your Hex workspace.
Application
Anthropic Compliance Log Monitoring
Monitor administrative and security activity across your Anthropic organization.
Application

Slack MCP Server
Send messages and search your Slack workspace directly from Panther AI.
MCP Servers
PagerDuty MCP Server
Manage incidents and on-call schedules directly from Panther AI.
MCP Servers

Notion MCP Server
Search and update your Notion workspace directly from Panther AI.
MCP Servers
GitHub MCP Server
Interact with your repositories and code security tools directly from Panther AI.
MCP Servers

Atlassian MCP Server
Take action in Jira and Confluence directly from Panther AI.
MCP Servers

Island Enterprise Browser Log Monitoring
Monitor browser activity, DLP events, and administrative actions across your enterprise.
Application

SOCRadar Log Monitoring
Bring external threat intelligence into your security operations workflow.
Application

Upwind Log Monitoring
Detect runtime threats across your cloud environment.
Cloud

Iru Log Monitoring
Monitor endpoint management activity across your device fleet.
Host

AWS Network Load Balancer Log Monitoring
Monitor TLS connection activity across your AWS network infrastructure.
Cloud

Amazon Bedrock Model Invocation Log Monitoring
Monitor AI model usage and invocation activity across your AWS environment.
Cloud

Microsoft Entra ID Audit Log Monitoring
Monitor identity activity and authentication events across your Azure environment.
Application

OpenAI Log Monitoring
Monitor administrative and security activity across your OpenAI organization.
Application

Open Threat Exchange (OTX)
Enrich detections with community-driven threat intelligence.
Enrichment

Databricks
Detect and investigate threats in your Databricks data lake
Data Lake

Docusign Log Monitoring
Detect fraud and monitor activity across your eSignature workflows.
Application

Microsoft Intune Log Monitoring
Monitor device compliance and endpoint management activity across your organization.
Application

Axonius Log Monitoring
Gain security visibility across your asset inventory.
Application

Snowflake Audit Log Monitoring
Monitor user activity and queries across your Snowflake instance.
Application

Snowflake Enrichment
Add Snowflake identity and access context to your detections.
Enrichment

Microsoft Defender XDR Log Monitoring
Correlate Defender XDR events with your full security data set.
Application
Orca Security Log Monitoring
Cloud
Mindflow
Automate incident response from your alerts
Alert Destinations

Rapid7 Log Monitoring
Centralize Rapid7 audit activity alongside your full security data set.
Application
Tracebit Log Monitoring
Monitor activity on Tracebit security canaries across your organization
Application

Amazon Security Lake & OSCF Log Monitoring
Inspect your OSCF data for signs of unusual behavior.
Cloud

Proofpoint Log Monitoring
Detect email attacks.
Application
AWS CloudFront Log Monitoring
Analyze CDN traffic for signs of unusual behavior.
Cloud

Thinkst Canary Log Monitoring
Detect lateral movement in your environment.
Application
Wiz Log Monitoring
Protect your cloud security controls.
Cloud
Zscaler Log Monitoring
Monitor application, network, and device access.
Application
Material Security SIEM Integration
Monitor threats in Google Workspace and M365.
Application
Custom Lookup Tables
Enrich log data from custom sources.
Enrichment
Anomali ThreatStream API SIEM Integration
Correlate log data with threat intelligence.
Enrichment

Torq
Trigger automated workflows from your alerts
Alert Destinations

Sublime Security SIEM Integration
Monitor email threats.
Application

Push Security SIEM Integration
Defend against identity attacks.
Host

Blink Ops
Deliver Panther alerts to your automation platform
Alert Destinations

AppOmni SIEM Integration
Monitor your Software as a Service security posture.
Application
Incident.io
Forward Panther alerts to your incident management platform
Alert Destinations

Discord
Route Panther alerts to a Discord channel
Alert Destinations

IPInfo
Enrich detections and reduce false-positive alerts
Enrichment

Splunk
Send Panther alerts to Splunk
Alert Destinations

AWS Security Hub Monitoring
Correlate AWS Security Hub findings.
Cloud

Notion Log Monitoring
Continuously monitor your Notion workspace.
Application

Tenable Vulnerability Scan Monitoring
Gain complete visibility into your network assets.
Application

Envoy Access Log Monitoring
Monitor network activity for suspicious behavior.
Network

Carbon Black Log Monitoring
Monitor endpoint activity for suspicious behavior.
Host

Azure Log Monitoring
Continuously monitor your Azure account.
Cloud

Docker Event Log Monitoring
Gain complete visibility into your Docker system events.
Application

Netskope Log Monitoring
Identify any suspicious cloud-based app or service activity.
Application

Auditd Log Monitoring
Monitor system-level activities in your Linux environment.
Host

Heroku Log Monitoring
Monitor your Heroku applications, infrastructure, and admin actions.
Cloud

Windows Event Log Monitoring
Monitor application, system, and security notifications from Windows machines.
Host

Tailscale Log Monitoring
Monitor your team’s Tailscale network.
Network

Auth0 Log Monitoring
Monitor user authentication and authorization activities in Auth0.
Application

AWS ALB Log Monitoring
Monitor requests sent to your load balancer for suspicious activity.
Cloud

AWS Aurora Log Monitoring
Monitor and detect any suspicious database events.
Cloud

AWS CloudTrail Log Monitoring
Identify any suspicious activity within your AWS infrastructure.
Cloud

AWS CloudWatch Log Monitoring
Monitor any resource changes within your AWS environment.
Cloud

AWS Config Log Monitoring
Monitor the configuration of your AWS resources.
Cloud

AWS EKS Log Monitoring
Monitor your Kubernetes environment for suspicious activity.
Cloud

AWS GuardDuty Log Monitoring
Monitor your AWS environment for malicious activity and unauthorized behavior.
Cloud

AWS S3 Log Monitoring
Monitor all requests made to AWS S3 buckets.
Cloud

AWS Transit Gateway Flow Log Monitoring
Monitor the IP traffic flowing through your transit gateway.
Cloud

AWS VPC Log Monitoring
Monitor the IP traffic going to and from network interfaces in your VPC.
Cloud

AWS WAF Log Monitoring
Investigate traffic that is analyzed by your web Access Control Lists (ACLs).
Cloud

Tines Log Monitoring
Monitor any changes within your Tines tenant.
Application

Bitwarden Log Monitoring
Identify any abnormal user activity in your organization's Bitwarden account.
Application

Sysdig Log Monitoring
Gain complete visibility into Sysdig platform activity.
Application

SentinelOne Log Monitoring
Monitor your endpoint data, network activity, and DNS requests.
Host

MongoDB Atlas Log Monitoring
Monitor events within your MongoDB Atlas organization or project.
Application

Microsoft Graph Log Monitoring
Monitor security alerts across Microsoft products, services, and partners.
Application

Jamf Pro Log Monitoring
Monitor Jamf Pro login events for suspicious activity.
Application

Dropbox Log Monitoring
Identify any suspicious file-sharing activity within your organization.
Application

Snyk Log Monitoring
Monitor for any changes within your Snyk Organization.
Application

Zendesk Log Monitoring
Monitor unusual activity within your Zendesk account.
Application

Asana Log Monitoring
Monitor Asana audit logs to identify suspicious activity in real-time.
Application

Atlassian Log Monitoring
Monitor Atlassian audit logs to identify suspicious activity in real-time.
Application

1Password Log Monitoring
Monitor your password management platform for suspicious activity.
Application

Zoom Log Monitoring
Monitor abnormal user activity within your Zoom account.
Application
Salesforce Log Monitoring
Monitor your sales operations data for suspicious activity.
Application

GitHub Log Monitoring
Identify any vulnerabilities within your GitHub repositories.
Application

Microsoft 365 Log Monitoring
Monitor your team’s communication and collaboration tools for suspicious activity.
Application

Slack Log Monitoring
Monitor your team’s communication platform for suspicious activity.
Application

Tines
Send Panther alerts to Tines and initiate a workflow
Alert Destinations

Duo Security Log Monitoring
Monitor your access management tools for suspicious activity.
Application

Sophos Log Monitoring
Monitor endpoint policy violations and data loss prevention events.
Host

Custom Webhooks
Send alert data to third-party applications
Alert Destinations

Fastly Log Monitoring
Monitor network traffic for signs of suspicious behavior.
Network

Cloudflare Log Monitoring
Inspect network traffic for signs of suspicious behavior.
Network

CrowdStrike Log Monitoring
Gain complete visibility into your managed endpoints.
Host

EC2 Instance
Track real-time changes to your EC2 Instance
Cloud Resources

EC2 AMI
Monitor which AWS accounts can use AMI to launch instances
Cloud Resources

EC2 Volume
Continuously audit your EC2 Volume configurations
Cloud Resources

EC2 Network ACL
Audit changes to AWS Network ACL
Cloud Resources

EC2 Security Group
Audit changes to the security group in your EC2 instances.
Cloud Resources

PagerDuty
Send Panther alerts to PagerDuty and begin an investigation
Alert Destinations

SNS
Send programmatic alerts to emails with Panther via SNS
Alert Destinations

GCP Log Monitoring
Gain complete visibility into activity across your cloud service.
Cloud

Syslog Log Monitoring
Monitor machine and network activity for suspicious behavior.
Host

Fluentd Log Monitoring
Inspect application activity for any signs of suspicious behavior.
Host

Zeek Log Monitoring
Inspect network traffic and DNS protocols for suspicious activity.
Network

Cisco Umbrella Log Monitoring
Identify any suspicious or malicious domain addresses or DNS requests.
Network

Juniper Log Monitoring
Monitor network traffic for attack attempts or probes.
Network

Suricata Log Monitoring
Identify any suspicious traffic or domain activity.
Network

Lacework Log Monitoring
Gain complete visibility into your cloud and container environments.
Application

Teleport Log Monitoring
Inspect all SSH access activity for signs of suspicious behavior.
Application

Apache Log Monitoring
Inspect all web activity for signs of suspicious behavior.
Network

GitLab Log Monitoring
Identify any suspicious behavior within your GitLab environment.
Application

Okta Log Monitoring
Monitor Okta logs to gain complete visibility into your IdP activity.
Application

OneLogin Log Monitoring
Monitor your IdP for suspicious activity.
Application

Google Workspace (G Suite) Log Monitoring
Identify any suspicious activity within your Google Workspace applications.
Application

Box Log Monitoring
Gain complete visibility into your organization’s content management and file sharing.
Application

Snowflake
Build a robust security data lake in Snowflake.
Data Lake

AWS CloudTrail Log Analyzer
Track account changes in real-time and detect suspicious activity
Cloud Resources

S3 Buckets
Detect and alert on unauthorized access to your S3 buckets.
Cloud Resources

EC2 VPC
Capture traffic activity and monitor actual network traffic flows.
Cloud Resources

GuardDuty
Track real-time changes to your AWS GuardDuty
Cloud Resources

Lambda
Track real-time changes to your AWS Lambda
Cloud Resources

WAF Web ACL
Track real-time changes to your WAF ACLs
Cloud Resources

ALB
Audit changes to AWS Application Load Balancer
Cloud Resources

ACM Certificate
Audit changes to AWS Certificate manager
Cloud Resources

Redshift Cluster
Audit changes to AWS Redshift Clusters
Cloud Resources

DynamoDB Table
Continuously monitor AWS DynamoDB tables for compliance
Cloud Resources

Config Recorder
Audit changes to AWS Config Recorder
Cloud Resources

CloudWatch Log group
Track real-time changes to AWS CloudWatch Log group
Cloud Resources

CloudFormation Stack
Track real-time changes to AWS CloudFormation stacks
Cloud Resources

RDS Instance
Get alerted in real-time when a RDS change occurs.
Cloud Resources

Password Policy
Monitor password policies for your AWS account
Cloud Resources

IAM
Track real-time changes to IAM User, Group, Role, and Policy
Cloud Resources

KMS Key
Follow the highest standards of cryptographic practices.
Cloud Resources

ECS Cluster
Gain visibility into specific ECS environments in real-time.
Cloud Resources

OSSEC Log Monitoring
Monitor OSSEC logs to gain complete security visibility into host activity.
Host

Asana
Send Panther alerts to Asana and analyze the issue.
Alert Destinations

OpsGenie
Send Panther alerts to OpsGenie and begin an investigation.
Alert Destinations

Jira
Send Panther alerts to Jira and analyze the issue
Alert Destinations

Slack
Send Panther alerts to a designated Slack channel.
Alert Destinations

GitHub
Send Panther alerts to GitHub and analyze the issue
Alert Destinations

SQS
Send programmatic notifications to emails with Panther via SQS
Alert Destinations

Microsoft Teams
Send Panther alerts to a designated Microsoft Teams channel
Alert Destinations
Nginx Access Log Monitoring
Monitor Nginx access logs and gain complete visibility into web server activity.
Network

Osquery Log Monitoring
Gain complete visibility into your operating system activity.
Host
All Integrations
Log Sources
Cloud
Network
Host
Application
On-Prem
Alert Destinations
Enrichment
Data Lake
Cloud Resources
MCP Servers

Panther Log Forwarder
Get on-premises logs into Panther without the infrastructure overhead.
On-Prem

Google Threat Intelligence
Enrich detections with real-time IoCs from Google Threat Intelligence.
Enrichment

Hex Log Monitoring
Monitor user activity and data access across your Hex workspace.
Application
Anthropic Compliance Log Monitoring
Monitor administrative and security activity across your Anthropic organization.
Application

Slack MCP Server
Send messages and search your Slack workspace directly from Panther AI.
MCP Servers
PagerDuty MCP Server
Manage incidents and on-call schedules directly from Panther AI.
MCP Servers

Notion MCP Server
Search and update your Notion workspace directly from Panther AI.
MCP Servers
GitHub MCP Server
Interact with your repositories and code security tools directly from Panther AI.
MCP Servers

Atlassian MCP Server
Take action in Jira and Confluence directly from Panther AI.
MCP Servers

Island Enterprise Browser Log Monitoring
Monitor browser activity, DLP events, and administrative actions across your enterprise.
Application

SOCRadar Log Monitoring
Bring external threat intelligence into your security operations workflow.
Application

Upwind Log Monitoring
Detect runtime threats across your cloud environment.
Cloud

Iru Log Monitoring
Monitor endpoint management activity across your device fleet.
Host

AWS Network Load Balancer Log Monitoring
Monitor TLS connection activity across your AWS network infrastructure.
Cloud

Amazon Bedrock Model Invocation Log Monitoring
Monitor AI model usage and invocation activity across your AWS environment.
Cloud

Microsoft Entra ID Audit Log Monitoring
Monitor identity activity and authentication events across your Azure environment.
Application

OpenAI Log Monitoring
Monitor administrative and security activity across your OpenAI organization.
Application

Open Threat Exchange (OTX)
Enrich detections with community-driven threat intelligence.
Enrichment

Databricks
Detect and investigate threats in your Databricks data lake
Data Lake

Docusign Log Monitoring
Detect fraud and monitor activity across your eSignature workflows.
Application

Microsoft Intune Log Monitoring
Monitor device compliance and endpoint management activity across your organization.
Application

Axonius Log Monitoring
Gain security visibility across your asset inventory.
Application

Snowflake Audit Log Monitoring
Monitor user activity and queries across your Snowflake instance.
Application

Snowflake Enrichment
Add Snowflake identity and access context to your detections.
Enrichment

Microsoft Defender XDR Log Monitoring
Correlate Defender XDR events with your full security data set.
Application
Orca Security Log Monitoring
Cloud
Mindflow
Automate incident response from your alerts
Alert Destinations

Rapid7 Log Monitoring
Centralize Rapid7 audit activity alongside your full security data set.
Application
Tracebit Log Monitoring
Monitor activity on Tracebit security canaries across your organization
Application

Amazon Security Lake & OSCF Log Monitoring
Inspect your OSCF data for signs of unusual behavior.
Cloud

Proofpoint Log Monitoring
Detect email attacks.
Application
AWS CloudFront Log Monitoring
Analyze CDN traffic for signs of unusual behavior.
Cloud

Thinkst Canary Log Monitoring
Detect lateral movement in your environment.
Application
Wiz Log Monitoring
Protect your cloud security controls.
Cloud
Zscaler Log Monitoring
Monitor application, network, and device access.
Application
Material Security SIEM Integration
Monitor threats in Google Workspace and M365.
Application
Custom Lookup Tables
Enrich log data from custom sources.
Enrichment
Anomali ThreatStream API SIEM Integration
Correlate log data with threat intelligence.
Enrichment

Torq
Trigger automated workflows from your alerts
Alert Destinations

Sublime Security SIEM Integration
Monitor email threats.
Application

Push Security SIEM Integration
Defend against identity attacks.
Host

Blink Ops
Deliver Panther alerts to your automation platform
Alert Destinations

AppOmni SIEM Integration
Monitor your Software as a Service security posture.
Application
Incident.io
Forward Panther alerts to your incident management platform
Alert Destinations

Discord
Route Panther alerts to a Discord channel
Alert Destinations

IPInfo
Enrich detections and reduce false-positive alerts
Enrichment

Splunk
Send Panther alerts to Splunk
Alert Destinations

AWS Security Hub Monitoring
Correlate AWS Security Hub findings.
Cloud

Notion Log Monitoring
Continuously monitor your Notion workspace.
Application

Tenable Vulnerability Scan Monitoring
Gain complete visibility into your network assets.
Application

Envoy Access Log Monitoring
Monitor network activity for suspicious behavior.
Network

Carbon Black Log Monitoring
Monitor endpoint activity for suspicious behavior.
Host

Azure Log Monitoring
Continuously monitor your Azure account.
Cloud

Docker Event Log Monitoring
Gain complete visibility into your Docker system events.
Application

Netskope Log Monitoring
Identify any suspicious cloud-based app or service activity.
Application

Auditd Log Monitoring
Monitor system-level activities in your Linux environment.
Host

Heroku Log Monitoring
Monitor your Heroku applications, infrastructure, and admin actions.
Cloud

Windows Event Log Monitoring
Monitor application, system, and security notifications from Windows machines.
Host

Tailscale Log Monitoring
Monitor your team’s Tailscale network.
Network

Auth0 Log Monitoring
Monitor user authentication and authorization activities in Auth0.
Application

AWS ALB Log Monitoring
Monitor requests sent to your load balancer for suspicious activity.
Cloud

AWS Aurora Log Monitoring
Monitor and detect any suspicious database events.
Cloud

AWS CloudTrail Log Monitoring
Identify any suspicious activity within your AWS infrastructure.
Cloud

AWS CloudWatch Log Monitoring
Monitor any resource changes within your AWS environment.
Cloud

AWS Config Log Monitoring
Monitor the configuration of your AWS resources.
Cloud

AWS EKS Log Monitoring
Monitor your Kubernetes environment for suspicious activity.
Cloud

AWS GuardDuty Log Monitoring
Monitor your AWS environment for malicious activity and unauthorized behavior.
Cloud

AWS S3 Log Monitoring
Monitor all requests made to AWS S3 buckets.
Cloud

AWS Transit Gateway Flow Log Monitoring
Monitor the IP traffic flowing through your transit gateway.
Cloud

AWS VPC Log Monitoring
Monitor the IP traffic going to and from network interfaces in your VPC.
Cloud

AWS WAF Log Monitoring
Investigate traffic that is analyzed by your web Access Control Lists (ACLs).
Cloud

Tines Log Monitoring
Monitor any changes within your Tines tenant.
Application

Bitwarden Log Monitoring
Identify any abnormal user activity in your organization's Bitwarden account.
Application

Sysdig Log Monitoring
Gain complete visibility into Sysdig platform activity.
Application

SentinelOne Log Monitoring
Monitor your endpoint data, network activity, and DNS requests.
Host

MongoDB Atlas Log Monitoring
Monitor events within your MongoDB Atlas organization or project.
Application

Microsoft Graph Log Monitoring
Monitor security alerts across Microsoft products, services, and partners.
Application

Jamf Pro Log Monitoring
Monitor Jamf Pro login events for suspicious activity.
Application

Dropbox Log Monitoring
Identify any suspicious file-sharing activity within your organization.
Application

Snyk Log Monitoring
Monitor for any changes within your Snyk Organization.
Application

Zendesk Log Monitoring
Monitor unusual activity within your Zendesk account.
Application

Asana Log Monitoring
Monitor Asana audit logs to identify suspicious activity in real-time.
Application

Atlassian Log Monitoring
Monitor Atlassian audit logs to identify suspicious activity in real-time.
Application

1Password Log Monitoring
Monitor your password management platform for suspicious activity.
Application

Zoom Log Monitoring
Monitor abnormal user activity within your Zoom account.
Application
Salesforce Log Monitoring
Monitor your sales operations data for suspicious activity.
Application

GitHub Log Monitoring
Identify any vulnerabilities within your GitHub repositories.
Application

Microsoft 365 Log Monitoring
Monitor your team’s communication and collaboration tools for suspicious activity.
Application

Slack Log Monitoring
Monitor your team’s communication platform for suspicious activity.
Application

Tines
Send Panther alerts to Tines and initiate a workflow
Alert Destinations

Duo Security Log Monitoring
Monitor your access management tools for suspicious activity.
Application

Sophos Log Monitoring
Monitor endpoint policy violations and data loss prevention events.
Host

Custom Webhooks
Send alert data to third-party applications
Alert Destinations

Fastly Log Monitoring
Monitor network traffic for signs of suspicious behavior.
Network

Cloudflare Log Monitoring
Inspect network traffic for signs of suspicious behavior.
Network

CrowdStrike Log Monitoring
Gain complete visibility into your managed endpoints.
Host

EC2 Instance
Track real-time changes to your EC2 Instance
Cloud Resources

EC2 AMI
Monitor which AWS accounts can use AMI to launch instances
Cloud Resources

EC2 Volume
Continuously audit your EC2 Volume configurations
Cloud Resources

EC2 Network ACL
Audit changes to AWS Network ACL
Cloud Resources

EC2 Security Group
Audit changes to the security group in your EC2 instances.
Cloud Resources

PagerDuty
Send Panther alerts to PagerDuty and begin an investigation
Alert Destinations

SNS
Send programmatic alerts to emails with Panther via SNS
Alert Destinations

GCP Log Monitoring
Gain complete visibility into activity across your cloud service.
Cloud

Syslog Log Monitoring
Monitor machine and network activity for suspicious behavior.
Host

Fluentd Log Monitoring
Inspect application activity for any signs of suspicious behavior.
Host

Zeek Log Monitoring
Inspect network traffic and DNS protocols for suspicious activity.
Network

Cisco Umbrella Log Monitoring
Identify any suspicious or malicious domain addresses or DNS requests.
Network

Juniper Log Monitoring
Monitor network traffic for attack attempts or probes.
Network

Suricata Log Monitoring
Identify any suspicious traffic or domain activity.
Network

Lacework Log Monitoring
Gain complete visibility into your cloud and container environments.
Application

Teleport Log Monitoring
Inspect all SSH access activity for signs of suspicious behavior.
Application

Apache Log Monitoring
Inspect all web activity for signs of suspicious behavior.
Network

GitLab Log Monitoring
Identify any suspicious behavior within your GitLab environment.
Application

Okta Log Monitoring
Monitor Okta logs to gain complete visibility into your IdP activity.
Application

OneLogin Log Monitoring
Monitor your IdP for suspicious activity.
Application

Google Workspace (G Suite) Log Monitoring
Identify any suspicious activity within your Google Workspace applications.
Application

Box Log Monitoring
Gain complete visibility into your organization’s content management and file sharing.
Application

Snowflake
Build a robust security data lake in Snowflake.
Data Lake

AWS CloudTrail Log Analyzer
Track account changes in real-time and detect suspicious activity
Cloud Resources

S3 Buckets
Detect and alert on unauthorized access to your S3 buckets.
Cloud Resources

EC2 VPC
Capture traffic activity and monitor actual network traffic flows.
Cloud Resources

GuardDuty
Track real-time changes to your AWS GuardDuty
Cloud Resources

Lambda
Track real-time changes to your AWS Lambda
Cloud Resources

WAF Web ACL
Track real-time changes to your WAF ACLs
Cloud Resources

ALB
Audit changes to AWS Application Load Balancer
Cloud Resources

ACM Certificate
Audit changes to AWS Certificate manager
Cloud Resources

Redshift Cluster
Audit changes to AWS Redshift Clusters
Cloud Resources

DynamoDB Table
Continuously monitor AWS DynamoDB tables for compliance
Cloud Resources

Config Recorder
Audit changes to AWS Config Recorder
Cloud Resources

CloudWatch Log group
Track real-time changes to AWS CloudWatch Log group
Cloud Resources

CloudFormation Stack
Track real-time changes to AWS CloudFormation stacks
Cloud Resources

RDS Instance
Get alerted in real-time when a RDS change occurs.
Cloud Resources

Password Policy
Monitor password policies for your AWS account
Cloud Resources

IAM
Track real-time changes to IAM User, Group, Role, and Policy
Cloud Resources

KMS Key
Follow the highest standards of cryptographic practices.
Cloud Resources

ECS Cluster
Gain visibility into specific ECS environments in real-time.
Cloud Resources

OSSEC Log Monitoring
Monitor OSSEC logs to gain complete security visibility into host activity.
Host

Asana
Send Panther alerts to Asana and analyze the issue.
Alert Destinations

OpsGenie
Send Panther alerts to OpsGenie and begin an investigation.
Alert Destinations

Jira
Send Panther alerts to Jira and analyze the issue
Alert Destinations

Slack
Send Panther alerts to a designated Slack channel.
Alert Destinations

GitHub
Send Panther alerts to GitHub and analyze the issue
Alert Destinations

SQS
Send programmatic notifications to emails with Panther via SQS
Alert Destinations

Microsoft Teams
Send Panther alerts to a designated Microsoft Teams channel
Alert Destinations
Nginx Access Log Monitoring
Monitor Nginx access logs and gain complete visibility into web server activity.
Network

Osquery Log Monitoring
Gain complete visibility into your operating system activity.
Host
All Integrations
Log Sources
Cloud
Network
Host
Application
On-Prem
Alert Destinations
Enrichment
Data Lake
Cloud Resources
MCP Servers

Panther Log Forwarder
Get on-premises logs into Panther without the infrastructure overhead.
On-Prem

Google Threat Intelligence
Enrich detections with real-time IoCs from Google Threat Intelligence.
Enrichment

Hex Log Monitoring
Monitor user activity and data access across your Hex workspace.
Application
Anthropic Compliance Log Monitoring
Monitor administrative and security activity across your Anthropic organization.
Application

Slack MCP Server
Send messages and search your Slack workspace directly from Panther AI.
MCP Servers
PagerDuty MCP Server
Manage incidents and on-call schedules directly from Panther AI.
MCP Servers

Notion MCP Server
Search and update your Notion workspace directly from Panther AI.
MCP Servers
GitHub MCP Server
Interact with your repositories and code security tools directly from Panther AI.
MCP Servers

Atlassian MCP Server
Take action in Jira and Confluence directly from Panther AI.
MCP Servers

Island Enterprise Browser Log Monitoring
Monitor browser activity, DLP events, and administrative actions across your enterprise.
Application

SOCRadar Log Monitoring
Bring external threat intelligence into your security operations workflow.
Application

Upwind Log Monitoring
Detect runtime threats across your cloud environment.
Cloud

Iru Log Monitoring
Monitor endpoint management activity across your device fleet.
Host

AWS Network Load Balancer Log Monitoring
Monitor TLS connection activity across your AWS network infrastructure.
Cloud

Amazon Bedrock Model Invocation Log Monitoring
Monitor AI model usage and invocation activity across your AWS environment.
Cloud

Microsoft Entra ID Audit Log Monitoring
Monitor identity activity and authentication events across your Azure environment.
Application

OpenAI Log Monitoring
Monitor administrative and security activity across your OpenAI organization.
Application

Open Threat Exchange (OTX)
Enrich detections with community-driven threat intelligence.
Enrichment

Databricks
Detect and investigate threats in your Databricks data lake
Data Lake

Docusign Log Monitoring
Detect fraud and monitor activity across your eSignature workflows.
Application

Microsoft Intune Log Monitoring
Monitor device compliance and endpoint management activity across your organization.
Application

Axonius Log Monitoring
Gain security visibility across your asset inventory.
Application

Snowflake Audit Log Monitoring
Monitor user activity and queries across your Snowflake instance.
Application

Snowflake Enrichment
Add Snowflake identity and access context to your detections.
Enrichment

Microsoft Defender XDR Log Monitoring
Correlate Defender XDR events with your full security data set.
Application
Orca Security Log Monitoring
Cloud
Mindflow
Automate incident response from your alerts
Alert Destinations

Rapid7 Log Monitoring
Centralize Rapid7 audit activity alongside your full security data set.
Application
Tracebit Log Monitoring
Monitor activity on Tracebit security canaries across your organization
Application

Amazon Security Lake & OSCF Log Monitoring
Inspect your OSCF data for signs of unusual behavior.
Cloud

Proofpoint Log Monitoring
Detect email attacks.
Application
AWS CloudFront Log Monitoring
Analyze CDN traffic for signs of unusual behavior.
Cloud

Thinkst Canary Log Monitoring
Detect lateral movement in your environment.
Application
Wiz Log Monitoring
Protect your cloud security controls.
Cloud
Zscaler Log Monitoring
Monitor application, network, and device access.
Application
Material Security SIEM Integration
Monitor threats in Google Workspace and M365.
Application
Custom Lookup Tables
Enrich log data from custom sources.
Enrichment
Anomali ThreatStream API SIEM Integration
Correlate log data with threat intelligence.
Enrichment

Torq
Trigger automated workflows from your alerts
Alert Destinations

Sublime Security SIEM Integration
Monitor email threats.
Application

Push Security SIEM Integration
Defend against identity attacks.
Host

Blink Ops
Deliver Panther alerts to your automation platform
Alert Destinations

AppOmni SIEM Integration
Monitor your Software as a Service security posture.
Application
Incident.io
Forward Panther alerts to your incident management platform
Alert Destinations

Discord
Route Panther alerts to a Discord channel
Alert Destinations

IPInfo
Enrich detections and reduce false-positive alerts
Enrichment

Splunk
Send Panther alerts to Splunk
Alert Destinations

AWS Security Hub Monitoring
Correlate AWS Security Hub findings.
Cloud

Notion Log Monitoring
Continuously monitor your Notion workspace.
Application

Tenable Vulnerability Scan Monitoring
Gain complete visibility into your network assets.
Application

Envoy Access Log Monitoring
Monitor network activity for suspicious behavior.
Network

Carbon Black Log Monitoring
Monitor endpoint activity for suspicious behavior.
Host

Azure Log Monitoring
Continuously monitor your Azure account.
Cloud

Docker Event Log Monitoring
Gain complete visibility into your Docker system events.
Application

Netskope Log Monitoring
Identify any suspicious cloud-based app or service activity.
Application

Auditd Log Monitoring
Monitor system-level activities in your Linux environment.
Host

Heroku Log Monitoring
Monitor your Heroku applications, infrastructure, and admin actions.
Cloud

Windows Event Log Monitoring
Monitor application, system, and security notifications from Windows machines.
Host

Tailscale Log Monitoring
Monitor your team’s Tailscale network.
Network

Auth0 Log Monitoring
Monitor user authentication and authorization activities in Auth0.
Application

AWS ALB Log Monitoring
Monitor requests sent to your load balancer for suspicious activity.
Cloud

AWS Aurora Log Monitoring
Monitor and detect any suspicious database events.
Cloud

AWS CloudTrail Log Monitoring
Identify any suspicious activity within your AWS infrastructure.
Cloud

AWS CloudWatch Log Monitoring
Monitor any resource changes within your AWS environment.
Cloud

AWS Config Log Monitoring
Monitor the configuration of your AWS resources.
Cloud

AWS EKS Log Monitoring
Monitor your Kubernetes environment for suspicious activity.
Cloud

AWS GuardDuty Log Monitoring
Monitor your AWS environment for malicious activity and unauthorized behavior.
Cloud

AWS S3 Log Monitoring
Monitor all requests made to AWS S3 buckets.
Cloud

AWS Transit Gateway Flow Log Monitoring
Monitor the IP traffic flowing through your transit gateway.
Cloud

AWS VPC Log Monitoring
Monitor the IP traffic going to and from network interfaces in your VPC.
Cloud

AWS WAF Log Monitoring
Investigate traffic that is analyzed by your web Access Control Lists (ACLs).
Cloud

Tines Log Monitoring
Monitor any changes within your Tines tenant.
Application

Bitwarden Log Monitoring
Identify any abnormal user activity in your organization's Bitwarden account.
Application

Sysdig Log Monitoring
Gain complete visibility into Sysdig platform activity.
Application

SentinelOne Log Monitoring
Monitor your endpoint data, network activity, and DNS requests.
Host

MongoDB Atlas Log Monitoring
Monitor events within your MongoDB Atlas organization or project.
Application

Microsoft Graph Log Monitoring
Monitor security alerts across Microsoft products, services, and partners.
Application

Jamf Pro Log Monitoring
Monitor Jamf Pro login events for suspicious activity.
Application

Dropbox Log Monitoring
Identify any suspicious file-sharing activity within your organization.
Application

Snyk Log Monitoring
Monitor for any changes within your Snyk Organization.
Application

Zendesk Log Monitoring
Monitor unusual activity within your Zendesk account.
Application

Asana Log Monitoring
Monitor Asana audit logs to identify suspicious activity in real-time.
Application

Atlassian Log Monitoring
Monitor Atlassian audit logs to identify suspicious activity in real-time.
Application

1Password Log Monitoring
Monitor your password management platform for suspicious activity.
Application

Zoom Log Monitoring
Monitor abnormal user activity within your Zoom account.
Application
Salesforce Log Monitoring
Monitor your sales operations data for suspicious activity.
Application

GitHub Log Monitoring
Identify any vulnerabilities within your GitHub repositories.
Application

Microsoft 365 Log Monitoring
Monitor your team’s communication and collaboration tools for suspicious activity.
Application

Slack Log Monitoring
Monitor your team’s communication platform for suspicious activity.
Application

Tines
Send Panther alerts to Tines and initiate a workflow
Alert Destinations

Duo Security Log Monitoring
Monitor your access management tools for suspicious activity.
Application

Sophos Log Monitoring
Monitor endpoint policy violations and data loss prevention events.
Host

Custom Webhooks
Send alert data to third-party applications
Alert Destinations

Fastly Log Monitoring
Monitor network traffic for signs of suspicious behavior.
Network

Cloudflare Log Monitoring
Inspect network traffic for signs of suspicious behavior.
Network

CrowdStrike Log Monitoring
Gain complete visibility into your managed endpoints.
Host

EC2 Instance
Track real-time changes to your EC2 Instance
Cloud Resources

EC2 AMI
Monitor which AWS accounts can use AMI to launch instances
Cloud Resources

EC2 Volume
Continuously audit your EC2 Volume configurations
Cloud Resources

EC2 Network ACL
Audit changes to AWS Network ACL
Cloud Resources

EC2 Security Group
Audit changes to the security group in your EC2 instances.
Cloud Resources

PagerDuty
Send Panther alerts to PagerDuty and begin an investigation
Alert Destinations

SNS
Send programmatic alerts to emails with Panther via SNS
Alert Destinations

GCP Log Monitoring
Gain complete visibility into activity across your cloud service.
Cloud

Syslog Log Monitoring
Monitor machine and network activity for suspicious behavior.
Host

Fluentd Log Monitoring
Inspect application activity for any signs of suspicious behavior.
Host

Zeek Log Monitoring
Inspect network traffic and DNS protocols for suspicious activity.
Network

Cisco Umbrella Log Monitoring
Identify any suspicious or malicious domain addresses or DNS requests.
Network

Juniper Log Monitoring
Monitor network traffic for attack attempts or probes.
Network

Suricata Log Monitoring
Identify any suspicious traffic or domain activity.
Network

Lacework Log Monitoring
Gain complete visibility into your cloud and container environments.
Application

Teleport Log Monitoring
Inspect all SSH access activity for signs of suspicious behavior.
Application

Apache Log Monitoring
Inspect all web activity for signs of suspicious behavior.
Network

GitLab Log Monitoring
Identify any suspicious behavior within your GitLab environment.
Application

Okta Log Monitoring
Monitor Okta logs to gain complete visibility into your IdP activity.
Application

OneLogin Log Monitoring
Monitor your IdP for suspicious activity.
Application

Google Workspace (G Suite) Log Monitoring
Identify any suspicious activity within your Google Workspace applications.
Application

Box Log Monitoring
Gain complete visibility into your organization’s content management and file sharing.
Application

Snowflake
Build a robust security data lake in Snowflake.
Data Lake

AWS CloudTrail Log Analyzer
Track account changes in real-time and detect suspicious activity
Cloud Resources

S3 Buckets
Detect and alert on unauthorized access to your S3 buckets.
Cloud Resources

EC2 VPC
Capture traffic activity and monitor actual network traffic flows.
Cloud Resources

GuardDuty
Track real-time changes to your AWS GuardDuty
Cloud Resources

Lambda
Track real-time changes to your AWS Lambda
Cloud Resources

WAF Web ACL
Track real-time changes to your WAF ACLs
Cloud Resources

ALB
Audit changes to AWS Application Load Balancer
Cloud Resources

ACM Certificate
Audit changes to AWS Certificate manager
Cloud Resources

Redshift Cluster
Audit changes to AWS Redshift Clusters
Cloud Resources

DynamoDB Table
Continuously monitor AWS DynamoDB tables for compliance
Cloud Resources

Config Recorder
Audit changes to AWS Config Recorder
Cloud Resources

CloudWatch Log group
Track real-time changes to AWS CloudWatch Log group
Cloud Resources

CloudFormation Stack
Track real-time changes to AWS CloudFormation stacks
Cloud Resources

RDS Instance
Get alerted in real-time when a RDS change occurs.
Cloud Resources

Password Policy
Monitor password policies for your AWS account
Cloud Resources

IAM
Track real-time changes to IAM User, Group, Role, and Policy
Cloud Resources

KMS Key
Follow the highest standards of cryptographic practices.
Cloud Resources

ECS Cluster
Gain visibility into specific ECS environments in real-time.
Cloud Resources

OSSEC Log Monitoring
Monitor OSSEC logs to gain complete security visibility into host activity.
Host

Asana
Send Panther alerts to Asana and analyze the issue.
Alert Destinations

OpsGenie
Send Panther alerts to OpsGenie and begin an investigation.
Alert Destinations

Jira
Send Panther alerts to Jira and analyze the issue
Alert Destinations

Slack
Send Panther alerts to a designated Slack channel.
Alert Destinations

GitHub
Send Panther alerts to GitHub and analyze the issue
Alert Destinations

SQS
Send programmatic notifications to emails with Panther via SQS
Alert Destinations

Microsoft Teams
Send Panther alerts to a designated Microsoft Teams channel
Alert Destinations
Nginx Access Log Monitoring
Monitor Nginx access logs and gain complete visibility into web server activity.
Network

Osquery Log Monitoring
Gain complete visibility into your operating system activity.
Host
Bolt-on AI closes alerts. Panther closes the loop.
See how Panther compounds intelligence across the SOC.


Bolt-on AI closes alerts. Panther closes the loop.
See how Panther compounds intelligence across the SOC.
Bolt-on AI closes alerts. Panther closes the loop.
See how Panther compounds intelligence across the SOC.


Bolt-on AI closes alerts. Panther closes the loop.
See how Panther compounds intelligence across the SOC.


Get product updates, webinars, and news
By submitting this form, you acknowledge and agree that Panther will process your personal information in accordance with the Privacy Policy.
Platform
Solutions
All rights reserved © 2026 Panther, Inc
Get product updates, webinars, and news
By submitting this form, you acknowledge and agree that Panther will process your personal information in accordance with the Privacy Policy.
Platform
Solutions
All rights reserved © 2026 Panther, Inc
Get product updates, webinars, and news
By submitting this form, you acknowledge and agree that Panther will process your personal information in accordance with the Privacy Policy.
Platform
Solutions
All rights reserved © 2026 Panther, Inc
