SIEM integration that doesn't need a custom parser
Every detection and every decision your endpoints make arrives as one JSON object per line, so your SIEM receives structured events instead of prose. What you configure is where they go.
The kernel drivers behind these detections are attested by Microsoft, and we’re accredited by Portugal’s National Cybersecurity Centre.
Yes, QS-WAN works with the SIEM you already run
Yes. QNova Client writes every detection and every decision as one JSON object per line, so what you configure is where the events go, not a parser somebody has to write and then keep working. When the VPN comes up, the client repoints the collector address to its tunnelled address, so endpoint telemetry reaches your SIEM inside the tunnel, and events written while a device is offline are queued and drained on reconnect.
From "supports SIEM" to the line your collector actually reads
Three answers, in the order a network administrator usually asks for them.
Ingest our events without anyone writing a decoder
One line, one event. Every detection and every decision is a JSON object on its own line, not prose with a timestamp glued to the front, and the files rotate on their own at 50 MB so nothing has to be tidied by hand. What your SIEM needs is the path and the address: no field order to guess, and nothing to re-test the next time either side updates.
Send the telemetry down the tunnel, not across the open internet
The client repoints the manager address to its tunnelled address every time the VPN comes up, so your endpoint events travel the same protected path as the rest of your traffic. That handshake uses post-quantum cryptography, which matters more for logs than people expect, because a security log is exactly the recording an attacker would like to keep. It also means one fewer collector sitting on the public internet for you to expose, authenticate and defend. The client repoints the manager address to its tunnelled address every time the VPN comes up, so your endpoint events travel the same protected path as the rest of your traffic. That handshake uses post-quantum cryptography, which matters more for logs than people expect, because a security log is exactly the recording an attacker would like to keep. It also means one fewer collector sitting on the public internet for you to expose, authenticate and defend.
Tell a quiet week apart from a broken pipe
A laptop in an airport writes to a queue, and the queue drains when the device reconnects, so the record ends up complete rather than merely calm. Host Endpoint Monitoring in the console is fed by the same telemetry from the agent on each machine, and when a screen has nothing to show it says which kind of nothing it is: no data, or the data couldn’t be fetched. A screen that renders both of those as a zero is telling you something untrue.
What leaves the device, and where it stops
The log is written on the device by the system service and sent to the collector you run. We don’t run it for you, we don’t operate a SOC, and no analyst of ours reads your events. The licence runs on your own infrastructure, physical or in the cloud, and the software gateway runs on your infrastructure too. One thing we haven’t published is the full field list of the event schema, and we’d rather say that than describe fields we haven’t written down.
- One JSON object per line, written locally by the system service, rotating at 50 MB.
- What's in the record is what the protection engines did: a detection, and the decision that followed it.
- No listening socket on the machine. The client uses framed JSON over local channels, not an HTTP port on localhost.
- Windows devices run eleven detection engines. On Linux the client ships a host monitoring agent, and that's the endpoint side there. macOS and iOS are planned.
- All communications are encrypted with post-quantum cryptography, including the tunnel handshake.
- Not documented publicly: the full field list of the event schema. Ask, and an engineer answers.
Tell us what you're trying to connect
Which SIEM is it, do you already have a collector running or would you be standing one up, and how many of your devices spend most of the week off the network?