# Which SIEM solutions integrate with the security tools an organisation already runs?

<p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">Nobody replaces the whole stack to buy a SIEM. The endpoint agent, the firewall, the identity provider and the cloud accounts are already chosen, and the SIEM has to read all of them.</p><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">Question for the<a class="a a--md" elv="true" href="https://www.g2.com/categories/security-information-and-event-management-siem"> </a><a class="a a--md" elv="true" href="https://www.g2.com/categories/security-information-and-event-management-siem">Security Information and Event Management (SIEM)</a> G2 reviewers here: which ones genuinely integrate with what is already running? What to check during evaluation:</p><ul>
<li>Whether connectors exist for your specific firewall and identity provider, not just the vendor's own products</li>
<li>How custom or unusual log formats are handled</li>
<li>Whether each log type needs its own collection rule and table</li>
<li>What ingesting more sources does to the bill</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/microsoft-sentinel/reviews"><strong>Microsoft Sentinel</strong></a> ingests logs of any format without touching the VMs and connects to Defender XDR, Entra ID and other clouds including AWS. Reviewers note that different log types each need their own data collection rule and table.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/splunk-enterprise/reviews"><strong>Splunk Enterprise</strong></a> remains the broadest ingestion engine, with reviewers valuing having search, reporting and security in one place rather than separate consoles.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/google-security-operations/reviews"><strong>Google Security Operations</strong></a> is the newer entrant here, well rated by teams already running Google Cloud.</li>
</ul><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">Which integration turned out to be the awkward one in your environment?</p><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true"></p><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true"></p>

##### Post Metadata
- Posted at: 3 days ago
- Author title: Tech Consultant
- Net upvotes: 1


## Comments
### Comment 1

&lt;p&gt;I’d be especially interested in the integrations that require custom parsing or normalization. Native connectors are easy to compare, but the real maintenance burden usually shows up with legacy appliances, unusual log formats, and one-off internal systems.&lt;/p&gt;

##### Comment Metadata
- Posted at: about 16 hours ago
- Author title: Marketer





## Related discussions
- [How well does Trello scale into a larger team?](https://www.g2.com/discussions/1-how-well-does-trello-scale-into-a-larger-team)
  - Posted at: over 13 years ago
  - Comments: 6
- [Can we please add a new section](https://www.g2.com/discussions/2-can-we-please-add-a-new-section)
  - Posted at: over 13 years ago
  - Comments: 0
- [Quantifiable benefits from implementing your CRM](https://www.g2.com/discussions/quantifiable-benefits-from-implementing-your-crm)
  - Posted at: over 13 years ago
  - Comments: 4


