Overview

Cloud SIEM integrations stream audit, security, and activity logs from third-party services into Atatus. Once connected, events appear in Security → Cloud SIEM → Audit Logs → Events and can be searched, alerted on, and correlated alongside your other telemetry.

Each integration is configured from Security → Cloud SIEM → Integrations and follows the same two-step flow:

  1. In the source platform, create the credentials and grant the read permissions Atatus needs.
  2. In the Atatus UI, click Connect on the integration card and paste those credentials into the form.

Available integrations

Identity

DevOps

Cloud — AWS

Cloud — Azure

Cloud — GCP

Productivity

Security and Network


Common form fields

Most integration forms share a few standard fields:

Field Description
Integration Type The internal connector identifier. Pre-filled and read-only.
Poll Interval (minutes) How often Atatus fetches new events from the source. Range: 11440. Default: 5.
Enabled Toggle log collection on or off without deleting the credentials.

Credential and configuration fields are documented per integration.


Verifying an integration

After saving:

  1. The integration card on the Integrations tab shows a Configured badge and the count next to configured at the top of the page increases.
  2. Within one or two poll cycles, events from that source appear under Security → Cloud SIEM → Audit Logs → Events. Filter by the integration type to confirm.
  3. If the card shows an Error state, hover over it to see the connection error returned by the source API.