Available

SIEM integration that doesn't need a custom parser

Every detection and every decision your endpoints make arrives as one JSON object per line, so your SIEM receives structured events instead of prose. What you configure is where they go.

The kernel drivers behind these detections are attested by Microsoft, and we’re accredited by Portugal’s National Cybersecurity Centre.

Microsoft Entra ID
+
Security Dashboard
Siem And Qs-Wan

Yes, QS-WAN works with the SIEM you already run

Yes. QNova Client writes every detection and every decision as one JSON object per line, so what you configure is where the events go, not a parser somebody has to write and then keep working. When the VPN comes up, the client repoints the collector address to its tunnelled address, so endpoint telemetry reaches your SIEM inside the tunnel, and events written while a device is offline are queued and drained on reconnect.

What it can do

From "supports SIEM" to the line your collector actually reads

Three answers, in the order a network administrator usually asks for them.

Client Pc Scan
A detection on the device. What leaves it is one JSON line.

Ingest our events without anyone writing a decoder

One line, one event. Every detection and every decision is a JSON object on its own line, not prose with a timestamp glued to the front, and the files rotate on their own at 50 MB so nothing has to be tidied by hand. What your SIEM needs is the path and the address: no field order to guess, and nothing to re-test the next time either side updates.

Send the telemetry down the tunnel, not across the open internet

The client repoints the manager address to its tunnelled address every time the VPN comes up, so your endpoint events travel the same protected path as the rest of your traffic. That handshake uses post-quantum cryptography, which matters more for logs than people expect, because a security log is exactly the recording an attacker would like to keep. It also means one fewer collector sitting on the public internet for you to expose, authenticate and defend. The client repoints the manager address to its tunnelled address every time the VPN comes up, so your endpoint events travel the same protected path as the rest of your traffic. That handshake uses post-quantum cryptography, which matters more for logs than people expect, because a security log is exactly the recording an attacker would like to keep. It also means one fewer collector sitting on the public internet for you to expose, authenticate and defend.

Client Tunnel Logs
Tunnel logs on the device. The manager address follows the tunnel.
Endpoint Monitoring
Endpoint monitoring in the console, fed by the same agent telemetry.

Tell a quiet week apart from a broken pipe

A laptop in an airport writes to a queue, and the queue drains when the device reconnects, so the record ends up complete rather than merely calm. Host Endpoint Monitoring in the console is fed by the same telemetry from the agent on each machine, and when a screen has nothing to show it says which kind of nothing it is: no data, or the data couldn’t be fetched. A screen that renders both of those as a zero is telling you something untrue.

Data and security

What leaves the device, and where it stops

The log is written on the device by the system service and sent to the collector you run. We don’t run it for you, we don’t operate a SOC, and no analyst of ours reads your events. The licence runs on your own infrastructure, physical or in the cloud, and the software gateway runs on your infrastructure too. One thing we haven’t published is the full field list of the event schema, and we’d rather say that than describe fields we haven’t written down.

Why QS-WAN
Learn more
Ask us

Tell us what you're trying to connect

Which SIEM is it, do you already have a collector running or would you be standing one up, and how many of your devices spend most of the week off the network?

Scroll to Top