Ingest
Alerts arrive from a native connector or over a REST endpoint. Splunk, Microsoft Sentinel, Defender for Endpoint, Intune and Acronis EDR have purpose-built integrations; anything that can POST JSON works through the generic path.
- Webhook or polling, depending on what the source supports
- Per-tenant credentials, encrypted at rest and never cached
- Original payload retained verbatim beside the normalized copy
