Overview
Cloud SIEM integrations stream audit, security, and activity logs from third-party services into Atatus. Once connected, events appear in Security → Cloud SIEM → Audit Logs → Events and can be searched, alerted on, and correlated alongside your other telemetry.
Each integration is configured from Security → Cloud SIEM → Integrations and follows the same two-step flow:
- In the source platform, create the credentials and grant the read permissions Atatus needs.
- In the Atatus UI, click Connect on the integration card and paste those credentials into the form.
Available integrations
Identity
DevOps
Cloud — AWS
Cloud — Azure
Cloud — GCP
Productivity
Security and Network
Common form fields
Most integration forms share a few standard fields:
| Field | Description |
|---|---|
| Integration Type | The internal connector identifier. Pre-filled and read-only. |
| Poll Interval (minutes) | How often Atatus fetches new events from the source. Range: 1–1440. Default: 5. |
| Enabled | Toggle log collection on or off without deleting the credentials. |
Credential and configuration fields are documented per integration.
Verifying an integration
After saving:
- The integration card on the Integrations tab shows a Configured badge and the count next to configured at the top of the page increases.
- Within one or two poll cycles, events from that source appear under Security → Cloud SIEM → Audit Logs → Events. Filter by the integration type to confirm.
- If the card shows an Error state, hover over it to see the connection error returned by the source API.
+1-415-800-4104