About the OpenSearch SIEM Integration
OpenSearch SIEM delivers security information and event management capabilities built on the open-source OpenSearch platform, enabling security teams to implement threat detection, log analytics, and security investigation workflows on a flexible, scalable, and vendor-neutral foundation. Part of Synqly’s SIEM Unified API, the OpenSearch SIEM integration enables security teams to route normalized security event data from Synqly-connected tools into OpenSearch’s analytics and detection engine. Integrate with OpenSearch SIEM to centralize security telemetry from across your stack into an open-source security analytics platform, powering threat detection and investigation without vendor lock-in.
Integration Use Cases
Post Events
Writes a batch of `Event` objects to the SIEM configured with the token used for authentication.
Query Events
Queries events from the SIEM configured with the token used for authentication.
Query Log Providers
Queries available log providers in the source SIEM
Integration Resources
About OpenSearch
OpenSearch is an open-source search and analytics suite backed by a broad community and widely adopted by security operations teams to power log analytics, threat hunting, and SIEM capabilities at scale. Built on proven open-source technology and governed by a transparent, community-driven development model, OpenSearch provides a flexible, vendor-neutral foundation for security data analysis and operational intelligence. Teams looking to integrate with OpenSearch or build an OpenSearch integration can use Synqly to route normalized security event and log data into OpenSearch's analytics engine through standardized data pipelines.