Skip to content

Integrations Overview

Seliq is designed to sit on top of the tools you already use. Every integration pulls data into Seliq; your existing tools keep working exactly as they do today.

IntegrationCategoryStatusNotes
Microsoft SentinelSIEM✅ AvailablePull (API) + Push (webhook)
Splunk Cloud / EnterpriseSIEM✅ AvailablePull (REST API)
Elastic SIEMSIEM✅ AvailablePull (Elasticsearch API)
Google ChronicleSIEM🔜 Coming soon
CrowdStrike FalconEDR✅ AvailablePush (webhook)
SentinelOneEDR✅ AvailablePush (webhook)
Microsoft Defender XDREDR🔜 Coming soon
AWS GuardDutyCloud✅ AvailablePush (EventBridge)
Azure DefenderCloud🔜 Coming soon
GCP Security Command CenterCloud🔜 Coming soon
ServiceNowTicketing✅ AvailableBidirectional
JiraTicketing✅ AvailableBidirectional
PagerDutyNotifications✅ AvailableOutbound
SlackNotifications✅ AvailableOutbound
EmailNotifications✅ AvailableOutbound via SMTP or Seliq domain

Seliq supports the following authentication patterns:

  • API key / token — Most SIEM and EDR platforms
  • OAuth 2.0 — Google Chronicle, some cloud platforms
  • Service principal — Microsoft Sentinel, Azure
  • Webhook shared secret — CrowdStrike, SentinelOne push delivery

All credentials are encrypted at rest using AES-256. Secret values are never returned in API responses or shown in the UI after initial save.