How AI is changing the SOC operating model. Listen now →

close

How AI is changing the SOC operating model. Listen now →

close

Integrate your stack

All your security data and workflows, connected.

Featured Integrations

All Integrations

Log Sources

Cloud

Network

Host

Application

On-Prem

Alert Destinations

Enrichment

Data Lake

Cloud Resources

MCP Servers

Panther Log Forwarder

Get on-premises logs into Panther without the infrastructure overhead.

On-Prem

Google Threat Intelligence

Enrich detections with real-time IoCs from Google Threat Intelligence.

Enrichment

Hex Log Monitoring

Monitor user activity and data access across your Hex workspace.

Application

Anthropic Compliance Log Monitoring

Monitor administrative and security activity across your Anthropic organization.

Application

Slack MCP Server

Send messages and search your Slack workspace directly from Panther AI.

MCP Servers

PagerDuty MCP Server

Manage incidents and on-call schedules directly from Panther AI.

MCP Servers

Notion MCP Server

Search and update your Notion workspace directly from Panther AI.

MCP Servers

GitHub MCP Server

Interact with your repositories and code security tools directly from Panther AI.

MCP Servers

Atlassian MCP Server

Take action in Jira and Confluence directly from Panther AI.

MCP Servers

Island Enterprise Browser Log Monitoring

Monitor browser activity, DLP events, and administrative actions across your enterprise.

Application

SOCRadar Log Monitoring

Bring external threat intelligence into your security operations workflow.

Application

Upwind Log Monitoring

Detect runtime threats across your cloud environment.

Cloud

Iru Log Monitoring

Monitor endpoint management activity across your device fleet.

Host

AWS Network Load Balancer Log Monitoring

Monitor TLS connection activity across your AWS network infrastructure.

Cloud

Amazon Bedrock Model Invocation Log Monitoring

Monitor AI model usage and invocation activity across your AWS environment.

Cloud

Microsoft Entra ID Audit Log Monitoring

Monitor identity activity and authentication events across your Azure environment.

Application

OpenAI Log Monitoring

Monitor administrative and security activity across your OpenAI organization.

Application

Open Threat Exchange (OTX)

Enrich detections with community-driven threat intelligence.

Enrichment

Databricks

Detect and investigate threats in your Databricks data lake

Data Lake

Docusign Log Monitoring

Detect fraud and monitor activity across your eSignature workflows.

Application

Microsoft Intune Log Monitoring

Monitor device compliance and endpoint management activity across your organization.

Application

Axonius Log Monitoring

Gain security visibility across your asset inventory.

Application

Snowflake Audit Log Monitoring

Monitor user activity and queries across your Snowflake instance.

Application

Snowflake Enrichment

Add Snowflake identity and access context to your detections.

Enrichment

Microsoft Defender XDR Log Monitoring

Correlate Defender XDR events with your full security data set.

Application

Orca Security Log Monitoring

Cloud

Mindflow

Automate incident response from your alerts

Alert Destinations

Rapid7 Log Monitoring

Centralize Rapid7 audit activity alongside your full security data set.

Application

Tracebit Log Monitoring

Monitor activity on Tracebit security canaries across your organization

Application

Amazon Security Lake & OSCF Log Monitoring

Inspect your OSCF data for signs of unusual behavior.

Cloud

Proofpoint Log Monitoring

Detect email attacks.

Application

AWS CloudFront Log Monitoring

Analyze CDN traffic for signs of unusual behavior.

Cloud

Thinkst Canary Log Monitoring

Detect lateral movement in your environment.

Application

Wiz Log Monitoring

Protect your cloud security controls.

Cloud

Zscaler Log Monitoring

Monitor application, network, and device access.

Application

Material Security SIEM Integration

Monitor threats in Google Workspace and M365.

Application

Custom Lookup Tables

Enrich log data from custom sources.

Enrichment

Anomali ThreatStream API SIEM Integration

Correlate log data with threat intelligence.

Enrichment

Torq

Trigger automated workflows from your alerts

Alert Destinations

Sublime Security SIEM Integration

Monitor email threats.

Application

Push Security SIEM Integration

Defend against identity attacks.

Host

Blink Ops

Deliver Panther alerts to your automation platform

Alert Destinations

AppOmni SIEM Integration

Monitor your Software as a Service security posture.

Application

Incident.io

Forward Panther alerts to your incident management platform

Alert Destinations

Discord

Route Panther alerts to a Discord channel

Alert Destinations

IPInfo

Enrich detections and reduce false-positive alerts

Enrichment

Splunk

Send Panther alerts to Splunk

Alert Destinations

AWS Security Hub Monitoring

Correlate AWS Security Hub findings.

Cloud

Notion Log Monitoring

Continuously monitor your Notion workspace.

Application

Tenable Vulnerability Scan Monitoring

Gain complete visibility into your network assets.

Application

Envoy Access Log Monitoring

Monitor network activity for suspicious behavior.

Network

Carbon Black Log Monitoring

Monitor endpoint activity for suspicious behavior.

Host

Azure Log Monitoring

Continuously monitor your Azure account.

Cloud

Docker Event Log Monitoring

Gain complete visibility into your Docker system events.

Application

Netskope Log Monitoring

Identify any suspicious cloud-based app or service activity.

Application

Auditd Log Monitoring

Monitor system-level activities in your Linux environment.

Host

Heroku Log Monitoring

Monitor your Heroku applications, infrastructure, and admin actions.

Cloud

Windows Event Log Monitoring

Monitor application, system, and security notifications from Windows machines.

Host

Tailscale Log Monitoring

Monitor your team’s Tailscale network.

Network

Auth0 Log Monitoring

Monitor user authentication and authorization activities in Auth0.

Application

AWS ALB Log Monitoring

Monitor requests sent to your load balancer for suspicious activity.

Cloud

AWS Aurora Log Monitoring

Monitor and detect any suspicious database events.

Cloud

AWS CloudTrail Log Monitoring

Identify any suspicious activity within your AWS infrastructure.

Cloud

AWS CloudWatch Log Monitoring

Monitor any resource changes within your AWS environment.

Cloud

AWS Config Log Monitoring

Monitor the configuration of your AWS resources.

Cloud

AWS EKS Log Monitoring

Monitor your Kubernetes environment for suspicious activity.

Cloud

AWS GuardDuty Log Monitoring

Monitor your AWS environment for malicious activity and unauthorized behavior.

Cloud

AWS S3 Log Monitoring

Monitor all requests made to AWS S3 buckets.

Cloud

AWS Transit Gateway Flow Log Monitoring

Monitor the IP traffic flowing through your transit gateway.

Cloud

AWS VPC Log Monitoring

Monitor the IP traffic going to and from network interfaces in your VPC.

Cloud

AWS WAF Log Monitoring

Investigate traffic that is analyzed by your web Access Control Lists (ACLs).

Cloud

Tines Log Monitoring

Monitor any changes within your Tines tenant.

Application

Bitwarden Log Monitoring

Identify any abnormal user activity in your organization's Bitwarden account.

Application

Sysdig Log Monitoring

Gain complete visibility into Sysdig platform activity.

Application

SentinelOne Log Monitoring

Monitor your endpoint data, network activity, and DNS requests.

Host

MongoDB Atlas Log Monitoring

Monitor events within your MongoDB Atlas organization or project.

Application

Microsoft Graph Log Monitoring

Monitor security alerts across Microsoft products, services, and partners.

Application

Jamf Pro Log Monitoring

Monitor Jamf Pro login events for suspicious activity.

Application

Dropbox Log Monitoring

Identify any suspicious file-sharing activity within your organization.

Application

Snyk Log Monitoring

Monitor for any changes within your Snyk Organization.

Application

Zendesk Log Monitoring

Monitor unusual activity within your Zendesk account.

Application

Asana Log Monitoring

Monitor Asana audit logs to identify suspicious activity in real-time.

Application

Atlassian Log Monitoring

Monitor Atlassian audit logs to identify suspicious activity in real-time.

Application

1Password Log Monitoring

Monitor your password management platform for suspicious activity.

Application

Zoom Log Monitoring

Monitor abnormal user activity within your Zoom account.

Application

Salesforce Log Monitoring

Monitor your sales operations data for suspicious activity.

Application

GitHub Log Monitoring

Identify any vulnerabilities within your GitHub repositories.

Application

Microsoft 365 Log Monitoring

Monitor your team’s communication and collaboration tools for suspicious activity.

Application

Slack Log Monitoring

Monitor your team’s communication platform for suspicious activity.

Application

Tines

Send Panther alerts to Tines and initiate a workflow

Alert Destinations

Duo Security Log Monitoring

Monitor your access management tools for suspicious activity.

Application

Sophos Log Monitoring

Monitor endpoint policy violations and data loss prevention events.

Host

Custom Webhooks

Send alert data to third-party applications

Alert Destinations

Fastly Log Monitoring

Monitor network traffic for signs of suspicious behavior.

Network

Cloudflare Log Monitoring

Inspect network traffic for signs of suspicious behavior.

Network

CrowdStrike Log Monitoring

Gain complete visibility into your managed endpoints.

Host

EC2 Instance

Track real-time changes to your EC2 Instance

Cloud Resources

EC2 AMI

Monitor which AWS accounts can use AMI to launch instances

Cloud Resources

EC2 Volume

Continuously audit your EC2 Volume configurations

Cloud Resources

EC2 Network ACL

Audit changes to AWS Network ACL

Cloud Resources

EC2 Security Group

Audit changes to the security group in your EC2 instances.

Cloud Resources

PagerDuty

Send Panther alerts to PagerDuty and begin an investigation

Alert Destinations

SNS

Send programmatic alerts to emails with Panther via SNS

Alert Destinations

GCP Log Monitoring

Gain complete visibility into activity across your cloud service.

Cloud

Syslog Log Monitoring

Monitor machine and network activity for suspicious behavior.

Host

Fluentd Log Monitoring

Inspect application activity for any signs of suspicious behavior.

Host

Zeek Log Monitoring

Inspect network traffic and DNS protocols for suspicious activity.

Network

Cisco Umbrella Log Monitoring

Identify any suspicious or malicious domain addresses or DNS requests.

Network

Juniper Log Monitoring

Monitor network traffic for attack attempts or probes.

Network

Suricata Log Monitoring

Identify any suspicious traffic or domain activity.

Network

Lacework Log Monitoring

Gain complete visibility into your cloud and container environments.

Application

Teleport Log Monitoring

Inspect all SSH access activity for signs of suspicious behavior.

Application

Apache Log Monitoring

Inspect all web activity for signs of suspicious behavior.

Network

GitLab Log Monitoring

Identify any suspicious behavior within your GitLab environment.

Application

Okta Log Monitoring

Monitor Okta logs to gain complete visibility into your IdP activity.

Application

OneLogin Log Monitoring

Monitor your IdP for suspicious activity.

Application

Google Workspace (G Suite) Log Monitoring

Identify any suspicious activity within your Google Workspace applications.

Application

Box Log Monitoring

Gain complete visibility into your organization’s content management and file sharing.

Application

Snowflake

Build a robust security data lake in Snowflake.

Data Lake

AWS CloudTrail Log Analyzer

Track account changes in real-time and detect suspicious activity

Cloud Resources

S3 Buckets

Detect and alert on unauthorized access to your S3 buckets.

Cloud Resources

EC2 VPC

Capture traffic activity and monitor actual network traffic flows.

Cloud Resources

GuardDuty

Track real-time changes to your AWS GuardDuty

Cloud Resources

Lambda

Track real-time changes to your AWS Lambda

Cloud Resources

WAF Web ACL

Track real-time changes to your WAF ACLs

Cloud Resources

ALB

Audit changes to AWS Application Load Balancer

Cloud Resources

ACM Certificate

Audit changes to AWS Certificate manager

Cloud Resources

Redshift Cluster

Audit changes to AWS Redshift Clusters

Cloud Resources

DynamoDB Table

Continuously monitor AWS DynamoDB tables for compliance

Cloud Resources

Config Recorder

Audit changes to AWS Config Recorder

Cloud Resources

CloudWatch Log group

Track real-time changes to AWS CloudWatch Log group

Cloud Resources

CloudFormation Stack

Track real-time changes to AWS CloudFormation stacks

Cloud Resources

RDS Instance

Get alerted in real-time when a RDS change occurs.

Cloud Resources

Password Policy

Monitor password policies for your AWS account

Cloud Resources

IAM

Track real-time changes to IAM User, Group, Role, and Policy

Cloud Resources

KMS Key

Follow the highest standards of cryptographic practices.

Cloud Resources

ECS Cluster

Gain visibility into specific ECS environments in real-time.

Cloud Resources

OSSEC Log Monitoring

Monitor OSSEC logs to gain complete security visibility into host activity.

Host

Asana

Send Panther alerts to Asana and analyze the issue.

Alert Destinations

OpsGenie

Send Panther alerts to OpsGenie and begin an investigation.

Alert Destinations

Jira

Send Panther alerts to Jira and analyze the issue

Alert Destinations

Slack

Send Panther alerts to a designated Slack channel.

Alert Destinations

GitHub

Send Panther alerts to GitHub and analyze the issue

Alert Destinations

SQS

Send programmatic notifications to emails with Panther via SQS

Alert Destinations

Microsoft Teams

Send Panther alerts to a designated Microsoft Teams channel

Alert Destinations

Nginx Access Log Monitoring

Monitor Nginx access logs and gain complete visibility into web server activity.

Network

Osquery Log Monitoring

Gain complete visibility into your operating system activity.

Host

All Integrations

Log Sources

Cloud

Network

Host

Application

On-Prem

Alert Destinations

Enrichment

Data Lake

Cloud Resources

MCP Servers

Panther Log Forwarder

Get on-premises logs into Panther without the infrastructure overhead.

On-Prem

Google Threat Intelligence

Enrich detections with real-time IoCs from Google Threat Intelligence.

Enrichment

Hex Log Monitoring

Monitor user activity and data access across your Hex workspace.

Application

Anthropic Compliance Log Monitoring

Monitor administrative and security activity across your Anthropic organization.

Application

Slack MCP Server

Send messages and search your Slack workspace directly from Panther AI.

MCP Servers

PagerDuty MCP Server

Manage incidents and on-call schedules directly from Panther AI.

MCP Servers

Notion MCP Server

Search and update your Notion workspace directly from Panther AI.

MCP Servers

GitHub MCP Server

Interact with your repositories and code security tools directly from Panther AI.

MCP Servers

Atlassian MCP Server

Take action in Jira and Confluence directly from Panther AI.

MCP Servers

Island Enterprise Browser Log Monitoring

Monitor browser activity, DLP events, and administrative actions across your enterprise.

Application

SOCRadar Log Monitoring

Bring external threat intelligence into your security operations workflow.

Application

Upwind Log Monitoring

Detect runtime threats across your cloud environment.

Cloud

Iru Log Monitoring

Monitor endpoint management activity across your device fleet.

Host

AWS Network Load Balancer Log Monitoring

Monitor TLS connection activity across your AWS network infrastructure.

Cloud

Amazon Bedrock Model Invocation Log Monitoring

Monitor AI model usage and invocation activity across your AWS environment.

Cloud

Microsoft Entra ID Audit Log Monitoring

Monitor identity activity and authentication events across your Azure environment.

Application

OpenAI Log Monitoring

Monitor administrative and security activity across your OpenAI organization.

Application

Open Threat Exchange (OTX)

Enrich detections with community-driven threat intelligence.

Enrichment

Databricks

Detect and investigate threats in your Databricks data lake

Data Lake

Docusign Log Monitoring

Detect fraud and monitor activity across your eSignature workflows.

Application

Microsoft Intune Log Monitoring

Monitor device compliance and endpoint management activity across your organization.

Application

Axonius Log Monitoring

Gain security visibility across your asset inventory.

Application

Snowflake Audit Log Monitoring

Monitor user activity and queries across your Snowflake instance.

Application

Snowflake Enrichment

Add Snowflake identity and access context to your detections.

Enrichment

Microsoft Defender XDR Log Monitoring

Correlate Defender XDR events with your full security data set.

Application

Orca Security Log Monitoring

Cloud

Mindflow

Automate incident response from your alerts

Alert Destinations

Rapid7 Log Monitoring

Centralize Rapid7 audit activity alongside your full security data set.

Application

Tracebit Log Monitoring

Monitor activity on Tracebit security canaries across your organization

Application

Amazon Security Lake & OSCF Log Monitoring

Inspect your OSCF data for signs of unusual behavior.

Cloud

Proofpoint Log Monitoring

Detect email attacks.

Application

AWS CloudFront Log Monitoring

Analyze CDN traffic for signs of unusual behavior.

Cloud

Thinkst Canary Log Monitoring

Detect lateral movement in your environment.

Application

Wiz Log Monitoring

Protect your cloud security controls.

Cloud

Zscaler Log Monitoring

Monitor application, network, and device access.

Application

Material Security SIEM Integration

Monitor threats in Google Workspace and M365.

Application

Custom Lookup Tables

Enrich log data from custom sources.

Enrichment

Anomali ThreatStream API SIEM Integration

Correlate log data with threat intelligence.

Enrichment

Torq

Trigger automated workflows from your alerts

Alert Destinations

Sublime Security SIEM Integration

Monitor email threats.

Application

Push Security SIEM Integration

Defend against identity attacks.

Host

Blink Ops

Deliver Panther alerts to your automation platform

Alert Destinations

AppOmni SIEM Integration

Monitor your Software as a Service security posture.

Application

Incident.io

Forward Panther alerts to your incident management platform

Alert Destinations

Discord

Route Panther alerts to a Discord channel

Alert Destinations

IPInfo

Enrich detections and reduce false-positive alerts

Enrichment

Splunk

Send Panther alerts to Splunk

Alert Destinations

AWS Security Hub Monitoring

Correlate AWS Security Hub findings.

Cloud

Notion Log Monitoring

Continuously monitor your Notion workspace.

Application

Tenable Vulnerability Scan Monitoring

Gain complete visibility into your network assets.

Application

Envoy Access Log Monitoring

Monitor network activity for suspicious behavior.

Network

Carbon Black Log Monitoring

Monitor endpoint activity for suspicious behavior.

Host

Azure Log Monitoring

Continuously monitor your Azure account.

Cloud

Docker Event Log Monitoring

Gain complete visibility into your Docker system events.

Application

Netskope Log Monitoring

Identify any suspicious cloud-based app or service activity.

Application

Auditd Log Monitoring

Monitor system-level activities in your Linux environment.

Host

Heroku Log Monitoring

Monitor your Heroku applications, infrastructure, and admin actions.

Cloud

Windows Event Log Monitoring

Monitor application, system, and security notifications from Windows machines.

Host

Tailscale Log Monitoring

Monitor your team’s Tailscale network.

Network

Auth0 Log Monitoring

Monitor user authentication and authorization activities in Auth0.

Application

AWS ALB Log Monitoring

Monitor requests sent to your load balancer for suspicious activity.

Cloud

AWS Aurora Log Monitoring

Monitor and detect any suspicious database events.

Cloud

AWS CloudTrail Log Monitoring

Identify any suspicious activity within your AWS infrastructure.

Cloud

AWS CloudWatch Log Monitoring

Monitor any resource changes within your AWS environment.

Cloud

AWS Config Log Monitoring

Monitor the configuration of your AWS resources.

Cloud

AWS EKS Log Monitoring

Monitor your Kubernetes environment for suspicious activity.

Cloud

AWS GuardDuty Log Monitoring

Monitor your AWS environment for malicious activity and unauthorized behavior.

Cloud

AWS S3 Log Monitoring

Monitor all requests made to AWS S3 buckets.

Cloud

AWS Transit Gateway Flow Log Monitoring

Monitor the IP traffic flowing through your transit gateway.

Cloud

AWS VPC Log Monitoring

Monitor the IP traffic going to and from network interfaces in your VPC.

Cloud

AWS WAF Log Monitoring

Investigate traffic that is analyzed by your web Access Control Lists (ACLs).

Cloud

Tines Log Monitoring

Monitor any changes within your Tines tenant.

Application

Bitwarden Log Monitoring

Identify any abnormal user activity in your organization's Bitwarden account.

Application

Sysdig Log Monitoring

Gain complete visibility into Sysdig platform activity.

Application

SentinelOne Log Monitoring

Monitor your endpoint data, network activity, and DNS requests.

Host

MongoDB Atlas Log Monitoring

Monitor events within your MongoDB Atlas organization or project.

Application

Microsoft Graph Log Monitoring

Monitor security alerts across Microsoft products, services, and partners.

Application

Jamf Pro Log Monitoring

Monitor Jamf Pro login events for suspicious activity.

Application

Dropbox Log Monitoring

Identify any suspicious file-sharing activity within your organization.

Application

Snyk Log Monitoring

Monitor for any changes within your Snyk Organization.

Application

Zendesk Log Monitoring

Monitor unusual activity within your Zendesk account.

Application

Asana Log Monitoring

Monitor Asana audit logs to identify suspicious activity in real-time.

Application

Atlassian Log Monitoring

Monitor Atlassian audit logs to identify suspicious activity in real-time.

Application

1Password Log Monitoring

Monitor your password management platform for suspicious activity.

Application

Zoom Log Monitoring

Monitor abnormal user activity within your Zoom account.

Application

Salesforce Log Monitoring

Monitor your sales operations data for suspicious activity.

Application

GitHub Log Monitoring

Identify any vulnerabilities within your GitHub repositories.

Application

Microsoft 365 Log Monitoring

Monitor your team’s communication and collaboration tools for suspicious activity.

Application

Slack Log Monitoring

Monitor your team’s communication platform for suspicious activity.

Application

Tines

Send Panther alerts to Tines and initiate a workflow

Alert Destinations

Duo Security Log Monitoring

Monitor your access management tools for suspicious activity.

Application

Sophos Log Monitoring

Monitor endpoint policy violations and data loss prevention events.

Host

Custom Webhooks

Send alert data to third-party applications

Alert Destinations

Fastly Log Monitoring

Monitor network traffic for signs of suspicious behavior.

Network

Cloudflare Log Monitoring

Inspect network traffic for signs of suspicious behavior.

Network

CrowdStrike Log Monitoring

Gain complete visibility into your managed endpoints.

Host

EC2 Instance

Track real-time changes to your EC2 Instance

Cloud Resources

EC2 AMI

Monitor which AWS accounts can use AMI to launch instances

Cloud Resources

EC2 Volume

Continuously audit your EC2 Volume configurations

Cloud Resources

EC2 Network ACL

Audit changes to AWS Network ACL

Cloud Resources

EC2 Security Group

Audit changes to the security group in your EC2 instances.

Cloud Resources

PagerDuty

Send Panther alerts to PagerDuty and begin an investigation

Alert Destinations

SNS

Send programmatic alerts to emails with Panther via SNS

Alert Destinations

GCP Log Monitoring

Gain complete visibility into activity across your cloud service.

Cloud

Syslog Log Monitoring

Monitor machine and network activity for suspicious behavior.

Host

Fluentd Log Monitoring

Inspect application activity for any signs of suspicious behavior.

Host

Zeek Log Monitoring

Inspect network traffic and DNS protocols for suspicious activity.

Network

Cisco Umbrella Log Monitoring

Identify any suspicious or malicious domain addresses or DNS requests.

Network

Juniper Log Monitoring

Monitor network traffic for attack attempts or probes.

Network

Suricata Log Monitoring

Identify any suspicious traffic or domain activity.

Network

Lacework Log Monitoring

Gain complete visibility into your cloud and container environments.

Application

Teleport Log Monitoring

Inspect all SSH access activity for signs of suspicious behavior.

Application

Apache Log Monitoring

Inspect all web activity for signs of suspicious behavior.

Network

GitLab Log Monitoring

Identify any suspicious behavior within your GitLab environment.

Application

Okta Log Monitoring

Monitor Okta logs to gain complete visibility into your IdP activity.

Application

OneLogin Log Monitoring

Monitor your IdP for suspicious activity.

Application

Google Workspace (G Suite) Log Monitoring

Identify any suspicious activity within your Google Workspace applications.

Application

Box Log Monitoring

Gain complete visibility into your organization’s content management and file sharing.

Application

Snowflake

Build a robust security data lake in Snowflake.

Data Lake

AWS CloudTrail Log Analyzer

Track account changes in real-time and detect suspicious activity

Cloud Resources

S3 Buckets

Detect and alert on unauthorized access to your S3 buckets.

Cloud Resources

EC2 VPC

Capture traffic activity and monitor actual network traffic flows.

Cloud Resources

GuardDuty

Track real-time changes to your AWS GuardDuty

Cloud Resources

Lambda

Track real-time changes to your AWS Lambda

Cloud Resources

WAF Web ACL

Track real-time changes to your WAF ACLs

Cloud Resources

ALB

Audit changes to AWS Application Load Balancer

Cloud Resources

ACM Certificate

Audit changes to AWS Certificate manager

Cloud Resources

Redshift Cluster

Audit changes to AWS Redshift Clusters

Cloud Resources

DynamoDB Table

Continuously monitor AWS DynamoDB tables for compliance

Cloud Resources

Config Recorder

Audit changes to AWS Config Recorder

Cloud Resources

CloudWatch Log group

Track real-time changes to AWS CloudWatch Log group

Cloud Resources

CloudFormation Stack

Track real-time changes to AWS CloudFormation stacks

Cloud Resources

RDS Instance

Get alerted in real-time when a RDS change occurs.

Cloud Resources

Password Policy

Monitor password policies for your AWS account

Cloud Resources

IAM

Track real-time changes to IAM User, Group, Role, and Policy

Cloud Resources

KMS Key

Follow the highest standards of cryptographic practices.

Cloud Resources

ECS Cluster

Gain visibility into specific ECS environments in real-time.

Cloud Resources

OSSEC Log Monitoring

Monitor OSSEC logs to gain complete security visibility into host activity.

Host

Asana

Send Panther alerts to Asana and analyze the issue.

Alert Destinations

OpsGenie

Send Panther alerts to OpsGenie and begin an investigation.

Alert Destinations

Jira

Send Panther alerts to Jira and analyze the issue

Alert Destinations

Slack

Send Panther alerts to a designated Slack channel.

Alert Destinations

GitHub

Send Panther alerts to GitHub and analyze the issue

Alert Destinations

SQS

Send programmatic notifications to emails with Panther via SQS

Alert Destinations

Microsoft Teams

Send Panther alerts to a designated Microsoft Teams channel

Alert Destinations

Nginx Access Log Monitoring

Monitor Nginx access logs and gain complete visibility into web server activity.

Network

Osquery Log Monitoring

Gain complete visibility into your operating system activity.

Host

All Integrations

Log Sources

Cloud

Network

Host

Application

On-Prem

Alert Destinations

Enrichment

Data Lake

Cloud Resources

MCP Servers

Panther Log Forwarder

Get on-premises logs into Panther without the infrastructure overhead.

On-Prem

Google Threat Intelligence

Enrich detections with real-time IoCs from Google Threat Intelligence.

Enrichment

Hex Log Monitoring

Monitor user activity and data access across your Hex workspace.

Application

Anthropic Compliance Log Monitoring

Monitor administrative and security activity across your Anthropic organization.

Application

Slack MCP Server

Send messages and search your Slack workspace directly from Panther AI.

MCP Servers

PagerDuty MCP Server

Manage incidents and on-call schedules directly from Panther AI.

MCP Servers

Notion MCP Server

Search and update your Notion workspace directly from Panther AI.

MCP Servers

GitHub MCP Server

Interact with your repositories and code security tools directly from Panther AI.

MCP Servers

Atlassian MCP Server

Take action in Jira and Confluence directly from Panther AI.

MCP Servers

Island Enterprise Browser Log Monitoring

Monitor browser activity, DLP events, and administrative actions across your enterprise.

Application

SOCRadar Log Monitoring

Bring external threat intelligence into your security operations workflow.

Application

Upwind Log Monitoring

Detect runtime threats across your cloud environment.

Cloud

Iru Log Monitoring

Monitor endpoint management activity across your device fleet.

Host

AWS Network Load Balancer Log Monitoring

Monitor TLS connection activity across your AWS network infrastructure.

Cloud

Amazon Bedrock Model Invocation Log Monitoring

Monitor AI model usage and invocation activity across your AWS environment.

Cloud

Microsoft Entra ID Audit Log Monitoring

Monitor identity activity and authentication events across your Azure environment.

Application

OpenAI Log Monitoring

Monitor administrative and security activity across your OpenAI organization.

Application

Open Threat Exchange (OTX)

Enrich detections with community-driven threat intelligence.

Enrichment

Databricks

Detect and investigate threats in your Databricks data lake

Data Lake

Docusign Log Monitoring

Detect fraud and monitor activity across your eSignature workflows.

Application

Microsoft Intune Log Monitoring

Monitor device compliance and endpoint management activity across your organization.

Application

Axonius Log Monitoring

Gain security visibility across your asset inventory.

Application

Snowflake Audit Log Monitoring

Monitor user activity and queries across your Snowflake instance.

Application

Snowflake Enrichment

Add Snowflake identity and access context to your detections.

Enrichment

Microsoft Defender XDR Log Monitoring

Correlate Defender XDR events with your full security data set.

Application

Orca Security Log Monitoring

Cloud

Mindflow

Automate incident response from your alerts

Alert Destinations

Rapid7 Log Monitoring

Centralize Rapid7 audit activity alongside your full security data set.

Application

Tracebit Log Monitoring

Monitor activity on Tracebit security canaries across your organization

Application

Amazon Security Lake & OSCF Log Monitoring

Inspect your OSCF data for signs of unusual behavior.

Cloud

Proofpoint Log Monitoring

Detect email attacks.

Application

AWS CloudFront Log Monitoring

Analyze CDN traffic for signs of unusual behavior.

Cloud

Thinkst Canary Log Monitoring

Detect lateral movement in your environment.

Application

Wiz Log Monitoring

Protect your cloud security controls.

Cloud

Zscaler Log Monitoring

Monitor application, network, and device access.

Application

Material Security SIEM Integration

Monitor threats in Google Workspace and M365.

Application

Custom Lookup Tables

Enrich log data from custom sources.

Enrichment

Anomali ThreatStream API SIEM Integration

Correlate log data with threat intelligence.

Enrichment

Torq

Trigger automated workflows from your alerts

Alert Destinations

Sublime Security SIEM Integration

Monitor email threats.

Application

Push Security SIEM Integration

Defend against identity attacks.

Host

Blink Ops

Deliver Panther alerts to your automation platform

Alert Destinations

AppOmni SIEM Integration

Monitor your Software as a Service security posture.

Application

Incident.io

Forward Panther alerts to your incident management platform

Alert Destinations

Discord

Route Panther alerts to a Discord channel

Alert Destinations

IPInfo

Enrich detections and reduce false-positive alerts

Enrichment

Splunk

Send Panther alerts to Splunk

Alert Destinations

AWS Security Hub Monitoring

Correlate AWS Security Hub findings.

Cloud

Notion Log Monitoring

Continuously monitor your Notion workspace.

Application

Tenable Vulnerability Scan Monitoring

Gain complete visibility into your network assets.

Application

Envoy Access Log Monitoring

Monitor network activity for suspicious behavior.

Network

Carbon Black Log Monitoring

Monitor endpoint activity for suspicious behavior.

Host

Azure Log Monitoring

Continuously monitor your Azure account.

Cloud

Docker Event Log Monitoring

Gain complete visibility into your Docker system events.

Application

Netskope Log Monitoring

Identify any suspicious cloud-based app or service activity.

Application

Auditd Log Monitoring

Monitor system-level activities in your Linux environment.

Host

Heroku Log Monitoring

Monitor your Heroku applications, infrastructure, and admin actions.

Cloud

Windows Event Log Monitoring

Monitor application, system, and security notifications from Windows machines.

Host

Tailscale Log Monitoring

Monitor your team’s Tailscale network.

Network

Auth0 Log Monitoring

Monitor user authentication and authorization activities in Auth0.

Application

AWS ALB Log Monitoring

Monitor requests sent to your load balancer for suspicious activity.

Cloud

AWS Aurora Log Monitoring

Monitor and detect any suspicious database events.

Cloud

AWS CloudTrail Log Monitoring

Identify any suspicious activity within your AWS infrastructure.

Cloud

AWS CloudWatch Log Monitoring

Monitor any resource changes within your AWS environment.

Cloud

AWS Config Log Monitoring

Monitor the configuration of your AWS resources.

Cloud

AWS EKS Log Monitoring

Monitor your Kubernetes environment for suspicious activity.

Cloud

AWS GuardDuty Log Monitoring

Monitor your AWS environment for malicious activity and unauthorized behavior.

Cloud

AWS S3 Log Monitoring

Monitor all requests made to AWS S3 buckets.

Cloud

AWS Transit Gateway Flow Log Monitoring

Monitor the IP traffic flowing through your transit gateway.

Cloud

AWS VPC Log Monitoring

Monitor the IP traffic going to and from network interfaces in your VPC.

Cloud

AWS WAF Log Monitoring

Investigate traffic that is analyzed by your web Access Control Lists (ACLs).

Cloud

Tines Log Monitoring

Monitor any changes within your Tines tenant.

Application

Bitwarden Log Monitoring

Identify any abnormal user activity in your organization's Bitwarden account.

Application

Sysdig Log Monitoring

Gain complete visibility into Sysdig platform activity.

Application

SentinelOne Log Monitoring

Monitor your endpoint data, network activity, and DNS requests.

Host

MongoDB Atlas Log Monitoring

Monitor events within your MongoDB Atlas organization or project.

Application

Microsoft Graph Log Monitoring

Monitor security alerts across Microsoft products, services, and partners.

Application

Jamf Pro Log Monitoring

Monitor Jamf Pro login events for suspicious activity.

Application

Dropbox Log Monitoring

Identify any suspicious file-sharing activity within your organization.

Application

Snyk Log Monitoring

Monitor for any changes within your Snyk Organization.

Application

Zendesk Log Monitoring

Monitor unusual activity within your Zendesk account.

Application

Asana Log Monitoring

Monitor Asana audit logs to identify suspicious activity in real-time.

Application

Atlassian Log Monitoring

Monitor Atlassian audit logs to identify suspicious activity in real-time.

Application

1Password Log Monitoring

Monitor your password management platform for suspicious activity.

Application

Zoom Log Monitoring

Monitor abnormal user activity within your Zoom account.

Application

Salesforce Log Monitoring

Monitor your sales operations data for suspicious activity.

Application

GitHub Log Monitoring

Identify any vulnerabilities within your GitHub repositories.

Application

Microsoft 365 Log Monitoring

Monitor your team’s communication and collaboration tools for suspicious activity.

Application

Slack Log Monitoring

Monitor your team’s communication platform for suspicious activity.

Application

Tines

Send Panther alerts to Tines and initiate a workflow

Alert Destinations

Duo Security Log Monitoring

Monitor your access management tools for suspicious activity.

Application

Sophos Log Monitoring

Monitor endpoint policy violations and data loss prevention events.

Host

Custom Webhooks

Send alert data to third-party applications

Alert Destinations

Fastly Log Monitoring

Monitor network traffic for signs of suspicious behavior.

Network

Cloudflare Log Monitoring

Inspect network traffic for signs of suspicious behavior.

Network

CrowdStrike Log Monitoring

Gain complete visibility into your managed endpoints.

Host

EC2 Instance

Track real-time changes to your EC2 Instance

Cloud Resources

EC2 AMI

Monitor which AWS accounts can use AMI to launch instances

Cloud Resources

EC2 Volume

Continuously audit your EC2 Volume configurations

Cloud Resources

EC2 Network ACL

Audit changes to AWS Network ACL

Cloud Resources

EC2 Security Group

Audit changes to the security group in your EC2 instances.

Cloud Resources

PagerDuty

Send Panther alerts to PagerDuty and begin an investigation

Alert Destinations

SNS

Send programmatic alerts to emails with Panther via SNS

Alert Destinations

GCP Log Monitoring

Gain complete visibility into activity across your cloud service.

Cloud

Syslog Log Monitoring

Monitor machine and network activity for suspicious behavior.

Host

Fluentd Log Monitoring

Inspect application activity for any signs of suspicious behavior.

Host

Zeek Log Monitoring

Inspect network traffic and DNS protocols for suspicious activity.

Network

Cisco Umbrella Log Monitoring

Identify any suspicious or malicious domain addresses or DNS requests.

Network

Juniper Log Monitoring

Monitor network traffic for attack attempts or probes.

Network

Suricata Log Monitoring

Identify any suspicious traffic or domain activity.

Network

Lacework Log Monitoring

Gain complete visibility into your cloud and container environments.

Application

Teleport Log Monitoring

Inspect all SSH access activity for signs of suspicious behavior.

Application

Apache Log Monitoring

Inspect all web activity for signs of suspicious behavior.

Network

GitLab Log Monitoring

Identify any suspicious behavior within your GitLab environment.

Application

Okta Log Monitoring

Monitor Okta logs to gain complete visibility into your IdP activity.

Application

OneLogin Log Monitoring

Monitor your IdP for suspicious activity.

Application

Google Workspace (G Suite) Log Monitoring

Identify any suspicious activity within your Google Workspace applications.

Application

Box Log Monitoring

Gain complete visibility into your organization’s content management and file sharing.

Application

Snowflake

Build a robust security data lake in Snowflake.

Data Lake

AWS CloudTrail Log Analyzer

Track account changes in real-time and detect suspicious activity

Cloud Resources

S3 Buckets

Detect and alert on unauthorized access to your S3 buckets.

Cloud Resources

EC2 VPC

Capture traffic activity and monitor actual network traffic flows.

Cloud Resources

GuardDuty

Track real-time changes to your AWS GuardDuty

Cloud Resources

Lambda

Track real-time changes to your AWS Lambda

Cloud Resources

WAF Web ACL

Track real-time changes to your WAF ACLs

Cloud Resources

ALB

Audit changes to AWS Application Load Balancer

Cloud Resources

ACM Certificate

Audit changes to AWS Certificate manager

Cloud Resources

Redshift Cluster

Audit changes to AWS Redshift Clusters

Cloud Resources

DynamoDB Table

Continuously monitor AWS DynamoDB tables for compliance

Cloud Resources

Config Recorder

Audit changes to AWS Config Recorder

Cloud Resources

CloudWatch Log group

Track real-time changes to AWS CloudWatch Log group

Cloud Resources

CloudFormation Stack

Track real-time changes to AWS CloudFormation stacks

Cloud Resources

RDS Instance

Get alerted in real-time when a RDS change occurs.

Cloud Resources

Password Policy

Monitor password policies for your AWS account

Cloud Resources

IAM

Track real-time changes to IAM User, Group, Role, and Policy

Cloud Resources

KMS Key

Follow the highest standards of cryptographic practices.

Cloud Resources

ECS Cluster

Gain visibility into specific ECS environments in real-time.

Cloud Resources

OSSEC Log Monitoring

Monitor OSSEC logs to gain complete security visibility into host activity.

Host

Asana

Send Panther alerts to Asana and analyze the issue.

Alert Destinations

OpsGenie

Send Panther alerts to OpsGenie and begin an investigation.

Alert Destinations

Jira

Send Panther alerts to Jira and analyze the issue

Alert Destinations

Slack

Send Panther alerts to a designated Slack channel.

Alert Destinations

GitHub

Send Panther alerts to GitHub and analyze the issue

Alert Destinations

SQS

Send programmatic notifications to emails with Panther via SQS

Alert Destinations

Microsoft Teams

Send Panther alerts to a designated Microsoft Teams channel

Alert Destinations

Nginx Access Log Monitoring

Monitor Nginx access logs and gain complete visibility into web server activity.

Network

Osquery Log Monitoring

Gain complete visibility into your operating system activity.

Host

All Integrations

Log Sources

Cloud

Network

Host

Application

On-Prem

Alert Destinations

Enrichment

Data Lake

Cloud Resources

MCP Servers

Panther Log Forwarder

Get on-premises logs into Panther without the infrastructure overhead.

On-Prem

Google Threat Intelligence

Enrich detections with real-time IoCs from Google Threat Intelligence.

Enrichment

Hex Log Monitoring

Monitor user activity and data access across your Hex workspace.

Application

Anthropic Compliance Log Monitoring

Monitor administrative and security activity across your Anthropic organization.

Application

Slack MCP Server

Send messages and search your Slack workspace directly from Panther AI.

MCP Servers

PagerDuty MCP Server

Manage incidents and on-call schedules directly from Panther AI.

MCP Servers

Notion MCP Server

Search and update your Notion workspace directly from Panther AI.

MCP Servers

GitHub MCP Server

Interact with your repositories and code security tools directly from Panther AI.

MCP Servers

Atlassian MCP Server

Take action in Jira and Confluence directly from Panther AI.

MCP Servers

Island Enterprise Browser Log Monitoring

Monitor browser activity, DLP events, and administrative actions across your enterprise.

Application

SOCRadar Log Monitoring

Bring external threat intelligence into your security operations workflow.

Application

Upwind Log Monitoring

Detect runtime threats across your cloud environment.

Cloud

Iru Log Monitoring

Monitor endpoint management activity across your device fleet.

Host

AWS Network Load Balancer Log Monitoring

Monitor TLS connection activity across your AWS network infrastructure.

Cloud

Amazon Bedrock Model Invocation Log Monitoring

Monitor AI model usage and invocation activity across your AWS environment.

Cloud

Microsoft Entra ID Audit Log Monitoring

Monitor identity activity and authentication events across your Azure environment.

Application

OpenAI Log Monitoring

Monitor administrative and security activity across your OpenAI organization.

Application

Open Threat Exchange (OTX)

Enrich detections with community-driven threat intelligence.

Enrichment

Databricks

Detect and investigate threats in your Databricks data lake

Data Lake

Docusign Log Monitoring

Detect fraud and monitor activity across your eSignature workflows.

Application

Microsoft Intune Log Monitoring

Monitor device compliance and endpoint management activity across your organization.

Application

Axonius Log Monitoring

Gain security visibility across your asset inventory.

Application

Snowflake Audit Log Monitoring

Monitor user activity and queries across your Snowflake instance.

Application

Snowflake Enrichment

Add Snowflake identity and access context to your detections.

Enrichment

Microsoft Defender XDR Log Monitoring

Correlate Defender XDR events with your full security data set.

Application

Orca Security Log Monitoring

Cloud

Mindflow

Automate incident response from your alerts

Alert Destinations

Rapid7 Log Monitoring

Centralize Rapid7 audit activity alongside your full security data set.

Application

Tracebit Log Monitoring

Monitor activity on Tracebit security canaries across your organization

Application

Amazon Security Lake & OSCF Log Monitoring

Inspect your OSCF data for signs of unusual behavior.

Cloud

Proofpoint Log Monitoring

Detect email attacks.

Application

AWS CloudFront Log Monitoring

Analyze CDN traffic for signs of unusual behavior.

Cloud

Thinkst Canary Log Monitoring

Detect lateral movement in your environment.

Application

Wiz Log Monitoring

Protect your cloud security controls.

Cloud

Zscaler Log Monitoring

Monitor application, network, and device access.

Application

Material Security SIEM Integration

Monitor threats in Google Workspace and M365.

Application

Custom Lookup Tables

Enrich log data from custom sources.

Enrichment

Anomali ThreatStream API SIEM Integration

Correlate log data with threat intelligence.

Enrichment

Torq

Trigger automated workflows from your alerts

Alert Destinations

Sublime Security SIEM Integration

Monitor email threats.

Application

Push Security SIEM Integration

Defend against identity attacks.

Host

Blink Ops

Deliver Panther alerts to your automation platform

Alert Destinations

AppOmni SIEM Integration

Monitor your Software as a Service security posture.

Application

Incident.io

Forward Panther alerts to your incident management platform

Alert Destinations

Discord

Route Panther alerts to a Discord channel

Alert Destinations

IPInfo

Enrich detections and reduce false-positive alerts

Enrichment

Splunk

Send Panther alerts to Splunk

Alert Destinations

AWS Security Hub Monitoring

Correlate AWS Security Hub findings.

Cloud

Notion Log Monitoring

Continuously monitor your Notion workspace.

Application

Tenable Vulnerability Scan Monitoring

Gain complete visibility into your network assets.

Application

Envoy Access Log Monitoring

Monitor network activity for suspicious behavior.

Network

Carbon Black Log Monitoring

Monitor endpoint activity for suspicious behavior.

Host

Azure Log Monitoring

Continuously monitor your Azure account.

Cloud

Docker Event Log Monitoring

Gain complete visibility into your Docker system events.

Application

Netskope Log Monitoring

Identify any suspicious cloud-based app or service activity.

Application

Auditd Log Monitoring

Monitor system-level activities in your Linux environment.

Host

Heroku Log Monitoring

Monitor your Heroku applications, infrastructure, and admin actions.

Cloud

Windows Event Log Monitoring

Monitor application, system, and security notifications from Windows machines.

Host

Tailscale Log Monitoring

Monitor your team’s Tailscale network.

Network

Auth0 Log Monitoring

Monitor user authentication and authorization activities in Auth0.

Application

AWS ALB Log Monitoring

Monitor requests sent to your load balancer for suspicious activity.

Cloud

AWS Aurora Log Monitoring

Monitor and detect any suspicious database events.

Cloud

AWS CloudTrail Log Monitoring

Identify any suspicious activity within your AWS infrastructure.

Cloud

AWS CloudWatch Log Monitoring

Monitor any resource changes within your AWS environment.

Cloud

AWS Config Log Monitoring

Monitor the configuration of your AWS resources.

Cloud

AWS EKS Log Monitoring

Monitor your Kubernetes environment for suspicious activity.

Cloud

AWS GuardDuty Log Monitoring

Monitor your AWS environment for malicious activity and unauthorized behavior.

Cloud

AWS S3 Log Monitoring

Monitor all requests made to AWS S3 buckets.

Cloud

AWS Transit Gateway Flow Log Monitoring

Monitor the IP traffic flowing through your transit gateway.

Cloud

AWS VPC Log Monitoring

Monitor the IP traffic going to and from network interfaces in your VPC.

Cloud

AWS WAF Log Monitoring

Investigate traffic that is analyzed by your web Access Control Lists (ACLs).

Cloud

Tines Log Monitoring

Monitor any changes within your Tines tenant.

Application

Bitwarden Log Monitoring

Identify any abnormal user activity in your organization's Bitwarden account.

Application

Sysdig Log Monitoring

Gain complete visibility into Sysdig platform activity.

Application

SentinelOne Log Monitoring

Monitor your endpoint data, network activity, and DNS requests.

Host

MongoDB Atlas Log Monitoring

Monitor events within your MongoDB Atlas organization or project.

Application

Microsoft Graph Log Monitoring

Monitor security alerts across Microsoft products, services, and partners.

Application

Jamf Pro Log Monitoring

Monitor Jamf Pro login events for suspicious activity.

Application

Dropbox Log Monitoring

Identify any suspicious file-sharing activity within your organization.

Application

Snyk Log Monitoring

Monitor for any changes within your Snyk Organization.

Application

Zendesk Log Monitoring

Monitor unusual activity within your Zendesk account.

Application

Asana Log Monitoring

Monitor Asana audit logs to identify suspicious activity in real-time.

Application

Atlassian Log Monitoring

Monitor Atlassian audit logs to identify suspicious activity in real-time.

Application

1Password Log Monitoring

Monitor your password management platform for suspicious activity.

Application

Zoom Log Monitoring

Monitor abnormal user activity within your Zoom account.

Application

Salesforce Log Monitoring

Monitor your sales operations data for suspicious activity.

Application

GitHub Log Monitoring

Identify any vulnerabilities within your GitHub repositories.

Application

Microsoft 365 Log Monitoring

Monitor your team’s communication and collaboration tools for suspicious activity.

Application

Slack Log Monitoring

Monitor your team’s communication platform for suspicious activity.

Application

Tines

Send Panther alerts to Tines and initiate a workflow

Alert Destinations

Duo Security Log Monitoring

Monitor your access management tools for suspicious activity.

Application

Sophos Log Monitoring

Monitor endpoint policy violations and data loss prevention events.

Host

Custom Webhooks

Send alert data to third-party applications

Alert Destinations

Fastly Log Monitoring

Monitor network traffic for signs of suspicious behavior.

Network

Cloudflare Log Monitoring

Inspect network traffic for signs of suspicious behavior.

Network

CrowdStrike Log Monitoring

Gain complete visibility into your managed endpoints.

Host

EC2 Instance

Track real-time changes to your EC2 Instance

Cloud Resources

EC2 AMI

Monitor which AWS accounts can use AMI to launch instances

Cloud Resources

EC2 Volume

Continuously audit your EC2 Volume configurations

Cloud Resources

EC2 Network ACL

Audit changes to AWS Network ACL

Cloud Resources

EC2 Security Group

Audit changes to the security group in your EC2 instances.

Cloud Resources

PagerDuty

Send Panther alerts to PagerDuty and begin an investigation

Alert Destinations

SNS

Send programmatic alerts to emails with Panther via SNS

Alert Destinations

GCP Log Monitoring

Gain complete visibility into activity across your cloud service.

Cloud

Syslog Log Monitoring

Monitor machine and network activity for suspicious behavior.

Host

Fluentd Log Monitoring

Inspect application activity for any signs of suspicious behavior.

Host

Zeek Log Monitoring

Inspect network traffic and DNS protocols for suspicious activity.

Network

Cisco Umbrella Log Monitoring

Identify any suspicious or malicious domain addresses or DNS requests.

Network

Juniper Log Monitoring

Monitor network traffic for attack attempts or probes.

Network

Suricata Log Monitoring

Identify any suspicious traffic or domain activity.

Network

Lacework Log Monitoring

Gain complete visibility into your cloud and container environments.

Application

Teleport Log Monitoring

Inspect all SSH access activity for signs of suspicious behavior.

Application

Apache Log Monitoring

Inspect all web activity for signs of suspicious behavior.

Network

GitLab Log Monitoring

Identify any suspicious behavior within your GitLab environment.

Application

Okta Log Monitoring

Monitor Okta logs to gain complete visibility into your IdP activity.

Application

OneLogin Log Monitoring

Monitor your IdP for suspicious activity.

Application

Google Workspace (G Suite) Log Monitoring

Identify any suspicious activity within your Google Workspace applications.

Application

Box Log Monitoring

Gain complete visibility into your organization’s content management and file sharing.

Application

Snowflake

Build a robust security data lake in Snowflake.

Data Lake

AWS CloudTrail Log Analyzer

Track account changes in real-time and detect suspicious activity

Cloud Resources

S3 Buckets

Detect and alert on unauthorized access to your S3 buckets.

Cloud Resources

EC2 VPC

Capture traffic activity and monitor actual network traffic flows.

Cloud Resources

GuardDuty

Track real-time changes to your AWS GuardDuty

Cloud Resources

Lambda

Track real-time changes to your AWS Lambda

Cloud Resources

WAF Web ACL

Track real-time changes to your WAF ACLs

Cloud Resources

ALB

Audit changes to AWS Application Load Balancer

Cloud Resources

ACM Certificate

Audit changes to AWS Certificate manager

Cloud Resources

Redshift Cluster

Audit changes to AWS Redshift Clusters

Cloud Resources

DynamoDB Table

Continuously monitor AWS DynamoDB tables for compliance

Cloud Resources

Config Recorder

Audit changes to AWS Config Recorder

Cloud Resources

CloudWatch Log group

Track real-time changes to AWS CloudWatch Log group

Cloud Resources

CloudFormation Stack

Track real-time changes to AWS CloudFormation stacks

Cloud Resources

RDS Instance

Get alerted in real-time when a RDS change occurs.

Cloud Resources

Password Policy

Monitor password policies for your AWS account

Cloud Resources

IAM

Track real-time changes to IAM User, Group, Role, and Policy

Cloud Resources

KMS Key

Follow the highest standards of cryptographic practices.

Cloud Resources

ECS Cluster

Gain visibility into specific ECS environments in real-time.

Cloud Resources

OSSEC Log Monitoring

Monitor OSSEC logs to gain complete security visibility into host activity.

Host

Asana

Send Panther alerts to Asana and analyze the issue.

Alert Destinations

OpsGenie

Send Panther alerts to OpsGenie and begin an investigation.

Alert Destinations

Jira

Send Panther alerts to Jira and analyze the issue

Alert Destinations

Slack

Send Panther alerts to a designated Slack channel.

Alert Destinations

GitHub

Send Panther alerts to GitHub and analyze the issue

Alert Destinations

SQS

Send programmatic notifications to emails with Panther via SQS

Alert Destinations

Microsoft Teams

Send Panther alerts to a designated Microsoft Teams channel

Alert Destinations

Nginx Access Log Monitoring

Monitor Nginx access logs and gain complete visibility into web server activity.

Network

Osquery Log Monitoring

Gain complete visibility into your operating system activity.

Host

Bolt-on AI closes alerts. Panther closes the loop.

See how Panther compounds intelligence across the SOC.

Bolt-on AI closes alerts. Panther closes the loop.

See how Panther compounds intelligence across the SOC.

Bolt-on AI closes alerts. Panther closes the loop.

See how Panther compounds intelligence across the SOC.

Bolt-on AI closes alerts. Panther closes the loop.

See how Panther compounds intelligence across the SOC.

Get product updates, webinars, and news

By submitting this form, you acknowledge and agree that Panther will process your personal information in accordance with the Privacy Policy.

Get product updates, webinars, and news

By submitting this form, you acknowledge and agree that Panther will process your personal information in accordance with the Privacy Policy.

Get product updates, webinars, and news

By submitting this form, you acknowledge and agree that Panther will process your personal information in accordance with the Privacy Policy.