Toggle navigation
Dochub
Home
Admin Portal
Menu
Admin Documentation
ThreatSTOP Overview
Home Page
The ThreatSTOP platform
Supported Devices
Community Accounts
Targets
Legal information
Admin Portal
Introduction
Accounts and settings
Users and Roles
OKTA Integration
Guided Setup
Dashboard
Devices
Policy Editor
RPZ Behaviors
User-Defined Lists
Falcon X Integration
Log files
Customer networks
IPFW Reports
DNSFW Reports
Roaming Reports
IP/DNS Email reports
IP/DNS Email Alerts
Check IOC
SIEM Integration
API Keys
IP Defense Devices
A10 ADC/TPS (TSCM Web Automation)
A10 ADC/TPS (TSCM CLI)
A10 (Pre-TSCM)
Bandura platform
Check Point (TSCM CLI)
Check Point (TSCM Web Automation)
Cisco ASA via SSH (TSCM Web Automation)
Cisco ASA via SSH (TSCM CLI)
Cisco ASA via REST API (TSCM Web Automation)
Cisco ASA via REST API (TSCM CLI)
Cisco ISR (TSCM Web Automation)
Cisco ISR (TSCM CLI)
Cisco Firepower (TSCM Web Automation)
Cisco Firepower (TSCM CLI)
Fortigate (TSCM Web Automation)
Fortigate (TSCM CLI)
IPTables (Ubuntu)
IPTables (Ubuntu Web Automation)
IPTables (Red Hat)
IPTables (Red Hat Web Automation)
Juniper SRX/EX/MX
Juniper SRX/EX/MX (Web Automation)
Juniper Security Zones
Packet Capture (PCAP)
Palo Alto Networks (Web Automation)
Palo Alto Networks (TSCM CLI)
Palo Alto Networks (HTTP)
PF (FreeBSD)
PF (OpenBSD)
pfSense (CLI)
pfSense (Web Automation)
Ubiquiti (CLI)
Ubiquiti (Web Automation)
Vyatta (CLI)
Vyatta (Web Automation)
VyOS (CLI)
VyOS (Web Automation)
DNS Defense Devices
BIND 9 (pfSense)
BIND 9 (Red Hat CentOS/RHEL)
BIND 9 (Ubuntu)
BIND 9 (TSCM)
BIND 9 (TSCM Web Automation)
Docker Container
F5® Big IP/IQ® (BIND RPZ)
F5® Big IP/IQ® (DNS Cache)
Infoblox NIOS
Microsoft Windows DNS Server
Nokia VitalQIP
PowerDNS (Ubuntu)
RPZ devices
DNS Defense Cloud
DNS Defense Cloud settings
Enabling DNS Defense Cloud on Windows Server
Enabling DNS Defense Cloud on Unix
DNS Defense Roaming
DNS Defense Roaming for Linux
PAAS integrations
Amazon AWS Route 53
AWS WAFv2 (Cloud)
AWS WAF Managed Rules
Azure DNS Defense
Azure IP Defense
Roaming Defense
Quick Start Guide
Configuration
Roaming Reports
TSCM Reference
Requirements
Installation
Backup & Restore
Command Line
ThreatSTOP Live ISO
REST API
REST Reference
Installation
UDL Utility
Integrations
ThreatList
STIX/TAXII
ThreatConnect
Resources
How-to and Tips
Advanced Bundle configuration
DNS Notifications
Wannacry Ransomware
Glossary
Print Page
SIEM Integration
The ThreatSTOP platforms implements two methods to integrate with a SIEM:
ThreatList
(CSV export of policy data).
ThreatList
(STIX/TAXII integration).