Secure60 offers several ways to collect and process your security data. Every method normalises events into one data model, so you can correlate activity across systems no matter how it arrived. Choose the integration that best fits your environment:
Integrations feed the data foundation every other capability builds on. For the wider picture, see Log Management and the Platform overview.
Our comprehensive solution for data collection and transformation. The Secure60 Collector:
A high-performance TCP load balancer designed for syslog ingestion. Perfect for:
A customer-deployed container that collects Microsoft 365 and Microsoft Entra ID (Azure AD) telemetry and forwards it to Secure60. It:
A customer-deployed container that collects Google Workspace audit and authentication logs and forwards them to Secure60. It:
auth_application field) for app governanceDirect integrations with hundreds of applications and services including:
Secure60 platform by design is schemaless, you can send any field names and they will be ingested and securely stored and searchable via the portal UI.
To enable the more advanced security features in the platform (such as Rules and Entity Analysis) we require that data is stored in the Secure60 Common Information Model (CIM). This is a simple schema that stores fields in a common naming strategy so that you can correlate activity across multiple systems and log types.
An example of this would be that if you are sending us an IP address instead of having one system send ip_source:54.7.36.12 and another send source_ip:54.7.36.12 we would parse and transform both of those fields into ip_src_dst:54.7.36.12 which then provides a standard format for referenceing Source IP information.
We offer rich parsing and transformation features within the Secure60 Collector, This includes automated field analysis for common field names which will automatically be converted into Secure60 schema.
We support hundreds of device and log formats including: Syslog, auditd, Windows Events, Cisco Schema, Juniper, AWS, Azure, GCP, Rackcorp, Zeek.
For details on parsing and transformation using the Secure60 Collector see: Secure60 Collector Installation and Configuration
We can also normalise from other standards such as Elastic Common Schema (ECS) and Open Cybersecurity Schema Framework (OCSF) into the Secure60 Schema, Touch base with our team for details on how to do this.
Every method below normalises to the same data model. The Secure60 Collector is the recommended starting point for most sources.
Every method feeds Log Management — the data foundation the rest of the platform runs on.