Supported Products Matrix
Every product this manual documents, and how its data gets into Fluency.
Ingress Methods
| Method | What it means |
|---|
| API | Fluency polls the vendor's API on a schedule using credentials you supply. |
| HEC | The vendor pushes to Fluency's Splunk-compatible HTTP Event Collector. |
| Webhook | The install produces a URL and a token; the vendor is configured to post to it. |
| Syslog | The device sends syslog to a listener, either the cloud endpoint or a local collector. |
| Cloud storage | The vendor writes objects to a bucket; Fluency consumes them via an SQS notification queue. |
| Event stream | A managed streaming service Fluency subscribes to. |
| Connector | No application template — set up as an integration on Platform → Integrations, with the data source added by hand. |
Products With an Application Template
These install from Platform → Applications → Install Application From Template. The Install Application From Template reference lists the exact parameters each one asks for.
AWS Services
| Product | Template | Ingress | Guide |
|---|
| Amazon GuardDuty | Amazon GuardDuty | API | GuardDuty |
| AWS CloudTrail | AWS CloudTrail | Cloud storage | CloudTrail |
| Amazon CloudWatch | CloudWatch LogGroup | Cloud storage | Amazon CloudWatch |
| Amazon EKS | AWS EKS Logs | Cloud storage | EKS Logs |
Cloud-based Business Softwares
| Product | Template | Ingress | Guide |
|---|
| Abnormal Security | Abnormal Security | API | — |
| Bitwarden | Bitwarden | API | Bitwarden |
| Black Kite (third-party risk findings) | BlackKite Findings | API | Black Kite |
| Cloudflare (audit log, GraphQL analytics) | Cloudflare API | API | Cloudflare |
| GitHub (organization audit) | GitHub via Org Webhook | Webhook | GitHub Audit |
| Okta | Okta Events | API | Okta |
| Salesforce | Salesforce Event Monitoring | API | Salesforce Event Monitoring |
| Varonis (SaaS — DatAlert alerts, activity events) | Varonis | API | Varonis SaaS API |
| Workday (user activity log) | Workday Events | API | Workday |
Cloud Infrastructure (IaaS)
Email Audit and Protection
Endpoint Management
Office Software (SaaS) and IAM
On-Premise IT
All syslog. The template supplies the parser.
System Components
Not third-party sources — the platform's own parts.
| Template | Purpose | Documented at |
|---|
| BehaviorSummary Notification Export | Mails behaviour summaries out | Notifications |
| Fluency Syslog Endpoint | The cloud syslog listener | Syslog Import |
| Fluency AI Assistant | The assistant's API integration | — |
| Fluency Collector | Registers an on-premises collector | Fluency Collector |
| Normalized Metaflow | Writes the platform's normalized metaflow to a lake index | — |
| Import collector | Imports an existing collector by name | Managing collectors |
| Ingext Collector import via S3 | Replays collector data from a bucket | Ingress management |
| Fluency legacy archive import via S3 | Replays a legacy archive from a bucket | Ingress management |
| Ingext Syslog import via S3 | Replays syslog from a bucket | Ingress management |
Products Without an Application Template
These are connected some other way. Do not go looking for a tile in the catalog.
| Product | Ingress | Guide |
|---|
| 1Password | Connector (REST + API pull) | — |
| Acronis Cyber Protect Cloud | Connector (API client) | — |
| Avanan | HEC | Avanan |
| AWS Kinesis | Connector | Kinesis |
| AWS Kinesis Data Firehose | Cloud storage, via S3 | Kinesis Firehose |
| AWS Security Lake | Not settled | Security Lake |
| AWS VPC flow logs | Cloud storage or CloudWatch | — |
| AWS Route 53 resolver logs | Cloud storage or CloudWatch | — |
| Cato Networks | Connector (REST + API pull) | — |
| Cisco Umbrella | Cloud storage (Cisco-managed bucket) | Cisco Umbrella |
| Cylance | Connector | Cylance |
| Darktrace | Connector (REST + API pull) | — |
| Seraphic Browser Security | Connector (API polling) | Seraphic |
| SentinelOne Cloud Funnel | Cloud storage | SentinelOne API |
| Varonis DatAdvantage (on-premise) | Syslog, parser built by hand — the SaaS API has a template, see above | Varonis |
| Zoom | Connector (OAuth app + webhook) | Zoom |
Outbound integrations — Fluency sending to a service rather than collecting from it — are covered under Notification & Ticketing and are not listed here.
Parser Cookbooks
Most templates ship a working parser, so a cookbook is only needed for customisation or for a source with no template. The parser cookbooks currently cover: Bitdefender, Cisco Meraki, FortiGate firewall, Linux server, Palo Alto firewall, Peplink device, SentinelOne, SentinelOne Cloud Funnel, SonicWall, SonicWall VPN, Sophos UTM, Windows NXLog, Zimperium, plus a passthrough recipe and a time adjustment recipe.