.NET
Deprecation Notice: The Coralogix .NET SDK (Coralogix.SDK, CoralogixCoreSDK) is deprecated in favor of the OpenTelemetry .NET SDK and will no longer be supported after {cx.deprecations.legacySdkEol}. See the .NET OpenTelemetry instrumentation guide for setup options and the end-of-life notice for migration details.
Agent management
The agent catalog displays a concise overview of the most important details regarding your agents: version distribution, the percentage of hosts running agents and details regarding top CPU and memory utilization.
Akamai
The following tutorial demonstrates how to collect your Akamai DataStream logs and send them to Coralogix. Once ingested by our platform, query, archive, define alerts, and create dashboards with your data.
Alcide kAudit
Stream Alcide kAudit findings to Coralogix, enabling you to view, analyze and monitor your logs using cutting-edge tools.
Alibaba Cloud ActionTrail
The integration of Coralogix with ActionTrail on Alibaba Cloud offers a powerful solution for tracking and analyzing cloud-based actions.
APM using AWS EC2
Using Amazon Data Firehose, you can now send metrics to Coralogix from Amazon Elastic Compute Cloud (Amazon EC2) and view them on your Coralogix dashboard using our application performance monitoring features.
Architecture
Centrally manage the configuration of all OpenTelemetry Collectors in your environment with Fleet Manager.
AWS CloudFormation logs
Send your logs to Coralogix using AWS CloudFormation, granting you observability into your CloudFormation events. The following tutorial demonstrates how to configure an AWS CloudFormation template using a Lambda function to send your telemetry data to Coralogix.
AWS CloudFront logs
Enable logging from your Amazon CloudFront distribution to seamlessly send web access logs to Coralogix using the AWS CloudFront Logs via Firehose integration package.
AWS CloudTrail
Coralogix provides a predefined Lambda function to forward your CloudTrail logs straight to the Coralogix platform using our app in the Serverless Application Repository.
AWS CloudTrail log collection via SNS trigger
Coralogix provides a predefined Lambda function to easily forward your CloudTrail logs through SNS to the Coralogix platform. For easy setup, use our app in the AWS serverless application repository.
AWS CloudTrail Terraform module
Using Coralogix Terraform Modules, you can easily install and manage Coralogix integrations with AWS services as modules in your infrastructure code. This tutorial demonstrates how to install our CloudTrail collection Lambda.
AWS CloudWatch metric streams with Amazon Data Firehose
Utilize any of our setup options for Amazon Data Firehose and CloudWatch metric streams to seamlessly stream your CloudWatch metrics into Coralogix. Process and analyze the metrics for enhanced monitoring and deeper insights.
AWS CloudWatch metrics
The Coralogix AWS Metrics integration offers a simple and easy way to ingest AWS metrics into Coralogix. It’s a cost-efficient alternative Amazon Firehose. In addition, it accepts S3 metrics with 24-hour frequency that can’t be collected via Firehose/CloudWatch metrics streams.
AWS CloudWatch metrics processing
Amazon CloudWatch monitors your Amazon Web Services (AWS) resources and applications you run on AWS in real time. Use the Coralogix destination to easily forward metrics for your AWS resources to Coralogix using CloudWatch Metric Stream and Firehose Delivery Stream.
AWS CloudWatch: data collection options
Amazon CloudWatch collects and visualizes real-time logs, metrics, and event data in automated dashboards to streamline your infrastructure and application maintenance. Send these to Coralogix to enhance your data management, analysis, and monitoring capabilities. Coralogix provides multiple methods to collect logs and metrics from Amazon CloudWatch.
AWS EKS Fargate
Integrate Coralogix seamlessly with Amazon EKS on AWS Fargate to effortlessly collect, analyze, and visualize logs, metrics, and traces from your containerized applications, empowering you with comprehensive full-stack monitoring and insights.
AWS EKS Fargate logs
Seamleslly collect and send your EKS Fargate cluster logs straight to Coralogix.
AWS Elastic Beanstalk
This tutorial demonstrates how to instrument a Java application running on the Tomcat platform within an Elastic Beanstalk environment.
AWS EventBridge
Amazon EventBridge is a serverless event bus service that makes it easy to collect and send data from across your applications and services to any destination. Use EventBridge to seamlessly deliver real-time data from your application to Coralogix for monitoring and analysis.
AWS Infrastructure Explorer
Connect your AWS account to Coralogix to collect metadata for EC2 instances and network interfaces, and enrich logs, metrics, and traces with cloud context in Infrastructure Explorer.
AWS inspector
The following tutorial demonstrates how to successfully integrate AWS Inspector with Coralogix by using AWS Event Bridge API destinations.
AWS Kinesis with Logstash
Coralogix provides integration to connect Logstash to AWS Kinesis , so you can send your logs from anywhere into Coralogix.
AWS Lambda
This guide provides a step-by-step deployment guide for the AWS Stale Non-Human Resources Lambda.
AWS Lambda telemetry exporter
This tutorial demonstrates how to set up and install the Coralogix AWS Lambda Telemetry Exporter - an AWS Lambda extension that uses AWS Lambda Telemetry API to seamlessly collect Lambda function logs, as well as Lambda platform logs, metrics, and traces.
AWS load balancer
This tutorial demonstrates how to collect your AWS Elastic Load Balancers, Application Load Balancers, and Network Load Balancers using Elastic Load Balancing. The data, decrypted and retaining original timestamps, is sent to Coralogix. The process is installation-free and entails simply deploying a Lambda function.
AWS MSK & Kafka
Coralogix’s Kafka lambdas provide an easy way to send Kafka topics’ data to Coralogix. The preferred integration method is to use our AWS Serverless Application Repository.
AWS resource metadata collection
Deploy the Coralogix-Resource-Metadata AWS Lambda function in your AWS account. The function collects metadata of EC2 instances and AWS Lambda functions in the region of your AWS account and sends them to Coralogix.
AWS resource metadata collection Terraform module
Use Coralogix Terraform modules to install and manage AWS service integrations with Coralogix as modules in your infrastructure code. This guide shows you how to install our Resource Metadata Collection Lambda.
AWS secrets manager Lambda layer
Deploy the AWS Secrets Manager Lambda layer to be used in any of our AWS integrations. Doing so ensures the security of your ApiKey, which is presented in the Lambda as a secret rather than an environment variable.
AWS SNS data ingestion
Collect your AWS SNS messages in the Coralogix platform using our automatic Contextual Data Integration Package. The package automatically generates a URL to be use when creating an SNS subscription.
AWS status logs
Routing your AWS status logs to Coralogix streamlines log aggregation, augments monitoring efficiency, and expedites problem resolution. By funneling your AWS status logs into Coralogix's log management platform, you attain a consolidated view of your AWS infrastructure's condition, enabling rapid anomaly detection, proactive troubleshooting, and informed decision-making. This integration empowers teams to fine-tune resource allocation, fortify system reliability, and sustain operational effectiveness, leveraging Coralogix's analytics, alerts, and visualization tools to extract valuable insights from AWS status logs and ensure a robust and resilient cloud environment.
AWS Terraform module
Terraform simplifies the way we deploy our infrastructure and allows us to maintain it as code.Using our Terraform Modules, you can easily install and manage Coralogix integrations with AWS services as modules in your infrastructure code.Our modules are open source and available on our Github and in the Terraform Registry.
AWS VPC flow logs
The legacy Coralogix-VPC-Flog-Logs-S3 SAR app is deprecated. For new deployments, use the unified Coralogix AWS Shipper, which supports VPC flow logs via S3 with the IntegrationType parameter. The parameter set differs from the legacy app described below; see the coralogix-aws-shipper repository for the current reference. These instructions will be migrated in a follow-up.
AWS VPC flow logs Terraform module
Using Coralogix Terraform Modules, you can easily install and manage Coralogix integrations with AWS services as modules in your infrastructure code. This tutorial demonstrates how to install the VPC Flow Logs collection Lambda.
Azure activity logs
Collect Azure Activity logs and submit them to Coralogix for seamless integration.
Azure Blob Storage to OTel Terraform module
Using our Terraform modules, you can easily install and manage Coralogix integrations with Azure services as modules in your infrastructure code. This tutorial demonstrates how to install the Coralogix function app, allowing you to connect your Blob Storage container and send logs to OTel Endpoint.
Azure Blob Storage via Event Grid Terraform module
Using our Terraform modules, you can easily install and manage Coralogix integrations with Azure services as modules in your infrastructure code. This tutorial demonstrates how to install the Coralogix function app, allowing you to connect your Blob Storage container and send logs to Coralogix.
Azure diagnostic data Terraform module
Using our Terraform modules, you can easily install and manage Coralogix integrations with Azure services as modules in your infrastructure code. This tutorial demonstrates how to install our function app, which processes logs and metrics that are forwarded through diagnostic settings to an Event Hub and are then transmitted to Coralogix.
Azure Event Hub Terraform module
Using our Terraform modules, you can easily install and manage Coralogix integrations with Azure services as modules in your infrastructure code. This tutorial demonstrates how to install our function app that connects to your Event Hub and sends logs to Coralogix.
Azure Infrastructure Explorer
Connect your Azure tenant to Coralogix to collect metadata for Azure Virtual Machines and Virtual Machine Scale Set instances, and enrich logs and traces with resource context.
Azure metrics
Collect metrics from your Azure subscriptions using the Azure Monitor REST API and route them to Coralogix for dashboards, alerts, and Infrastructure Explorer correlation.
Azure platform monitoring
Microsoft Azure platform monitoring focuses on capturing platform logs - Microsoft Entra ID, Activity, and Resource logs - from various components within your environment.
Azure Queue Storage Terraform module
Using our Terraform modules, you can easily install and manage Coralogix integrations with Azure services as modules in your infrastructure code. This tutorial demonstrates how to install our function app that connects to your storage queue and sends logs to Coralogix.
Azure resource logs
Collect Azure Resource logs and send them to Coralogix for seamless integration.
Azure Resource Manager (ARM) integration packages
Access our Azure Resources Integration Packages to automatically deploy our various Microsoft Azure integrations. Extend your platform capabilities with packages and sources, without expending unnecessary time and resources. Gain insights into role, user, group and directory management, successful and failed sign-in events, and application management data that helps you understand your users’ experience and immediately troubleshoot any errors.
Beats: Auditbeat
Coralogix provides seamless integration with Auditbeat so you can send your audit data from anywhere into Coralogix.
Beats: Metricbeat
Coralogix provides a seamless integration with Metricbeat so help you send your metric data from anywhere and create metric dashboards.
Beats: Packetbeat
Coralogix provides a seamless integration with Packetbeat so you can send your network usage logs from anywhere and parse them according to your needs.
Bitbucket data ingestion
Send your Bitbucket logs to Coralogix to enhance log consolidation, strengthen monitoring capabilities, and streamline issue resolution. By directing Bitbucket logs into Coralogix, you can achieve a comprehensive view of your code repository activities, enabling swift anomaly detection, proactive debugging, and informed decision-making. This integration empowers teams to optimize development workflows, fortify system reliability, and maintain operational effectiveness, leveraging Coralogix's analytics, alerts, and visualization tools to extract valuable insights from Bitbucket logs and ensure a productive and resilient software development environment.
Bitdefender
Iitdefender is a leading cybersecurity company that offers a comprehensive suite of security products and services. Integrate Coralogix with Bitdefenders’ GravityZone service for comprehensive event streaming functionality.
Blob Storage to OTel: Microsoft Azure Resource Manager (ARM)
Coralogix provides a seamless integration with Azure cloud, allowing you to send your logs from anywhere and parse them according to your needs. The Azure Blob Storage To OTel integration allows parsing of Azure Blobs, triggered by an EventHub subscription, and sending the data to OTel endpoint.
Blob Storage via Event Grid: Microsoft Azure Resource Manager (ARM)
Coralogix provides a seamless integration with Azure cloud, allowing you to send your logs from anywhere and parse them according to your needs. The Azure Blob Storage via EventGrid integration allows parsing of Azure Blobs, triggered by an EventGrid subscription notification.
CircleCI
Integrate your CircleCI workflows and jobs pipeline with Coralogix to automatically receive reports and analyze version upgrades for their impact on the overall quality of your production system.
Claude
Connect Claude Code, Claude Cowork, and the Claude Usage & Compliance APIs to Coralogix for unified observability across Claude.
Claude Code client-side
Connect Claude Code to Coralogix to stream token usage, costs, tool calls, code changes, and session activity using built-in OpenTelemetry support.
Claude Cowork client-side
Connect Claude Cowork to Coralogix to stream session activity, token usage, cost estimates, and tool calls as OpenTelemetry telemetry — set up entirely from the Claude admin panel.
Claude Usage & Compliance APIs
Pull Claude usage, cost, Claude Code, per-user, seat, and governance telemetry from your Anthropic organization into Coralogix as metrics and logs.
Cloud Accounts
Connect a cloud provider account to Coralogix with Cloud Accounts, discover its resources, and deploy metrics monitoring per service and region.
Cloudflare
Cloudflare Enterprise customers have access to Logpush service which allows you to forward logs to cloud service providers like AWS. In this tutorial, you will find all steps to send logs to Coralogix via your S3 bucket.
Cloudflare Logpush Terraform module
Terraform simplifies the way we deploy our infrastructure and allows us to maintain it as code.
CockroachDB
This guide demonstrates the process of integrating Coralogix with a self-managed CockroachDB instance from Cockroach Labs. Initially, we will set up a CockroachDB instance on an EC2 instance, following the outlined steps below.
Codex CLI and Desktop
Connect Codex CLI and the ChatGPT desktop app to Coralogix to stream logs, metrics, and traces using built-in OpenTelemetry support.
Collect CloudWatch metrics with Telegraf
Amazon CloudWatch monitors your Amazon Web Services (AWS) resources and applications you run on AWS in real time. Use the Coralogix destination to easily forward metrics for your AWS resources to Coralogix using Telegraf.
Config Navigator
Config Navigator provides a real-time, interactive visualization of your OpenTelemetry (OTel) Collector configurations. This feature transforms complex YAML definitions into a transparent architectural map, allowing you to validate data flow, verify processing logic, and understand the precise relationship between pipeline components.
Configuration deep dive
Configurations in Fleet Management lets you centrally manage Collector configurations across your entire fleet, regardless of how they are deployed. It provides a single, consistent control point for updates and reduces the chance of configuration drift.
Configuration fallback
Set up S3-based configuration fallback for Fleet Management so agents always have a working configuration, even when Fleet Manager is unreachable.
Configuration management
The Configurations tab in Fleet Management displays all configuration groups, where each group represents a configuration and its complete version history.
Configuration templates
Generate production-ready OpenTelemetry Collector configurations from environment-specific templates in Fleet Management, without writing YAML from scratch.
Configuring TLS on rsyslog
This document explains how to configure TLS on rsyslog, which is necessary for sending logs to Coralogix syslog endpoints.
Coralogix endpoint updates and deprecations
Coralogix offers a regional endpoint for sending data into the Coralogix platform from all observability sources. This document provides updates regarding endpoint changes and deprecations.
Coralogix endpoints
Coralogix offers a regional endpoint for sending data into the Coralogix platform from all observability sources. This document provides generally available endpoints.
Coralogix icons
coralogix-actions
Coralogix icons 2.0
cx-actions
Cross-region configuration
This tutorial provides step-by-step guidance on configuring AWS PrivateLink cross-region connectivity.
CrowdStrike Falcon
Forward CrowdStrike events into Coralogix to centralize your security data for advanced correlation and analysis across multiple data sources. This holistic security view allows you to become more efficient in detecting and investigating sophisticated threats and reduce time to respond to security incidents.
CrowdStrike Falcon SIEM connector
Coralogix provides seamless integration with CrowdStrike Falcon, allowing you to correlate security-related events with your application and infrastructure logs and detect and respond to security incidents more effectively.
Cursor
Connect Cursor to Coralogix to stream agent session traces, tool usage, code changes, and session activity.
Custom metrics
Coralogix provides a scalable Prometheus-compatible managed service for time-series data. This tutorial presents a series of use cases employing our custom metric endpoint, including serverless computing and quick cURL-like calls to send counters and gauges to Coralogix.
Custom syslog
Seamlessly send Coralogix your logs using a syslog template with a custom format.
Diagnostic data: Microsoft Azure Resource Manager (ARM)
Coralogix provides a seamless integration with Azure cloud, allowing you to send your logs from anywhere and parse them according to your needs.The Azure Diagnostic Data integration allows processing of logs and metrics submitted to an Event Hub using the resource diagnostic settings configuration.
Duo Security
The following tutorial demonstrates how to successfully integrate Duo Security with Coralogix and send us your logs using FluentD.
ECS enhanced monitoring for CloudWatch metrics
Coralogix offers ECS enhanced monitoring, an extension to AWS metrics from CloudWatch using the Amazon ECS API to collect tags and additional metrics.
ElastiCache enhanced monitoring for CloudWatch metrics
Coralogix offers ElastiCache enhanced monitoring, an extension to AWS metrics from CloudWatch using the Amazon ElastiCache API to collect tags and additional metrics.
Endpoints and deployment
Use this page as a reference when configuring or validating Coralogix PrivateLink connectivity. Configuration instructions are covered in the PrivateLink guides.
Event Hub: Microsoft Azure Resource Manager (ARM)
Coralogix provides seamless integration with Azure cloud, allowing you to send your logs from anywhere and parse them according to your needs.
Extensions
Coralogix offers a variety of out-of-the-box data extensions to complement the CloudWatch Metrics via Firehose integration package.
External labels
New! Send Coralogix your metrics using external labels, maximizing query performance and adding an extra layer of granularity in your data indexing.
Fastly logs via HTTPS streaming
Fastly's real-time log streaming feature provides the ability to send Fastly logs to any HTTPS endpoint.
Filebeat
This integration is maintained for legacy support and is not recommended for new use cases. We recommend using OpenTelemetry (OTel) for a more modern, flexible, and industry-standard observability solution.
Fluent Bit
Coralogix provides seamless integration with Fluent Bit, allowing you to send your logs from anywhere and parse them according to your needs.
Fluent Bit Helm chart for Kubernetes
Use our multi-arch Helm chart to streamline your Kubernetes monitoring by creating a DaemonSet on your Kubernetes cluster using the Helm package manager.
Fluent Bit official Helm chart migration
This guide explains how to migrate from the Coralogix Fluent Bit Helm chart to the official Fluent Bit Helm chart.
Fluentd
Coralogix provides seamless integration with Fluentd so you can send your logs from anywhere and parse them according to your needs.
Fluentd Helm chart for Kubernetes
Here at Coralogix, we love Kubernetes and we love making things simple. To help streamline your Kubernetes monitoring, we created this chart to bootstrap our optimized Fluentd image to create a DaemonSet on your Kubernetes cluster using the Helm Package Manager.
GCP - getting started
Coralogix offers a number of basic integrations with Google Cloud Platform.
GCP Infrastructure Explorer
Connect a GCP project to Coralogix to collect metadata for Compute Engine, Google Kubernetes Engine (GKE), and Cloud Storage resources for Infrastructure Explorer context.
GCP log explorer
Coralogix offers a number of different approaches for collecting logs from your Google Cloud environments including using GCP Log Explorer and Google Cloud Storage.The tutorial describes how to configure a Logs router to send logs to a Pub/Sub topic and deliver them to Coralogix using a push subscription on the topic.
GCP logs
Google Cloud Platform (GCP) offers integrated monitoring and observability tools that enable users to gather and analyze logs from their GCP resources. Send these GCP logs to Coralogix to search, analyze, and visualize your data. Gain insights into application behavior, identify errors, and troubleshoot problems effectively.
GCP metrics
Google Cloud Platform provides built-in monitoring and observability tools that allow users to collect and analyze metrics and traces from their GCP resources. Send Google Cloud metrics seamlessly to Coralogix. Search, analyze, and visualize your data, gaining insights into application behavior, identifying errors, and troubleshooting problems.
GCP Private Service Connect Terraform module
Provision consumer-side Google Cloud Private Service Connect resources for private connectivity from GCP to Coralogix using Terraform.
GCP pub/sub Terraform module
This module will be installing our function app that gets messages from your Pub/Sub topic and sends logs to Coralogix.
GCP status logs
Sending Google Cloud Platform (GCP) status logs to Coralogix facilitates streamlined log aggregation, real-time monitoring, and efficient troubleshooting. By channeling GCP status logs into Coralogix's log management platform, organizations gain a comprehensive view of their cloud infrastructure's health, enabling rapid detection of anomalies, proactive issue resolution, and data-driven decision-making. This integration empowers teams to optimize resource utilization, enhance system reliability, and maintain operational excellence by leveraging Coralogix's analytics and visualization tools to extract valuable insights from GCP status logs.
GCP storage
Coralogix deprecated this integration. The GCP Cloud Storage push-based function — including both the gcloud CLI and Terraform deployment paths — is no longer supported for new deployments. Use the pull-based GCP Logs integration instead.
GCP traces
Google Cloud Platform provides built-in monitoring and observability tools that allow users to collect and analyze metrics and traces from their GCP resources. Send Google Cloud traces seamlessly to Coralogix. Search, analyze, and visualize your data, gaining insights into application behavior, identifying errors, and troubleshooting problems.
GELF
Coralogix will permanently disable native GELF ingestion on August 20, 2026. Migrate to a Logstash-based forwarder before the cutoff to avoid data loss. See the GELF and UDP rsyslog deprecation notice for full migration steps.
Generic incoming webhooks
Coralogix offers customers the option of automating the creation of your incoming webhooks to connect your applications to Coralogix.
Getting started
Overview
GitHub Actions
Monitoring GitHub Actions is critical for understanding what causes delays and failures in your CI/CD pipelines. Coralogix supports sending logs, traces, and metrics from completed actions to the platform by providing its own GitHub Action workflow.
GitHub app for AI discovery
Connect the Coralogix GitHub app for AI discovery to scan your repositories for AI-related projects, the models they use, and the applications Coralogix monitors.
GitHub Copilot
Observe GitHub Copilot in Coralogix: managed daily usage and billing metrics from the GitHub App, plus live per-session telemetry from the built-in OpenTelemetry in Copilot CLI.
GitHub data ingestion
Sending your GitHub logs to Coralogix streamlines log management, augments development monitoring, and enhances issue resolution. By routing GitHub logs into Coralogix, you gain a consolidated view of your code repository activities, enabling rapid anomaly detection, proactive debugging, and data-driven decision-making. This integration empowers development teams to optimize workflows, strengthen system reliability, and sustain operational effectiveness, utilizing Coralogix's analytics, alerts, and visualization tools to extract valuable insights from GitHub logs and ensure a seamless and resilient software development lifecycle.
GitHub Enterprise
This document explains how to configure the integration, allowing you to read logs from GitHub Enterprise into Coralogix.
GitLab data ingestion
Sending your GitLab logs to Coralogix streamlines log aggregation, strengthens monitoring capabilities, and enhances issue resolution for efficient software development. By directing GitLab logs into Coralogix, you gain a comprehensive view of your version control activities, enabling rapid anomaly detection, proactive debugging, and informed decision-making. This integration empowers development teams to optimize workflows, bolster system reliability, and maintain operational efficiency, leveraging Coralogix's analytics, alerts, and visualization tools to extract valuable insights from GitLab logs and ensure a collaborative and resilient software development environment.
Go
Deprecation Notice: The Coralogix Go SDK (go-coralogix-sdk) is deprecated in favor of the OpenTelemetry SDK and will no longer be supported after {cx.deprecations.legacySdkEol}. See the Go OpenTelemetry instrumentation guide for setup options and the end-of-life notice for migration details.
Google Workspace
Google Workspace audit logs provide detailed records of user activities, such as logins, file sharing, and administrative actions. These logs help you understand how Google Workspace applications are being used, track changes, and monitor for suspicious behavior, enabling you to maintain a secure and efficient workspace.
Google Workspace alert center
Google Workspace Alert Center offers real-time security alerts and insights that help you protect your organization from the latest threats, including phishing, malware, and other suspicious activity. The following tutorial will show you how to integrate Google Workspace Alert Center with Coralogix directly.
Google Workspace users
This integration will let you collect all user details from your Google Workspace Admin Console along with their metadata. This provides your Coralogix features with additional user details to get better context.
Heroku logs
Use our logging add-on to seamlessly forward all Heroku logging output to Coralogix.
Heroku metric logs
Our Heroku integration is configured to automatically detect inbound platform and custom metric logs, and parse them into JSON. To avoid confusion, we'll show some before and after examples, as well as explaining how to parse and generate metrics from these values, once they appear in your account.
Heroku telemetry drains
This guide provides step-by-step instructions for setting up Heroku telemetry drains to collect logs, metrics, and traces from your Heroku Private Space applications into Coralogix.
Integration overview
Coralogix offers multiple integration methods for collecting observability data from Heroku applications. Choose the appropriate method based on your Heroku environment generation and hosting type.
Integrations
Explore Coralogix integrations and quick-start tools to get up and running fast with customizable parsing rules, dashboards, alerts, and more.
Intercom data ingestion
Companies that use Intercom for customer relations can ingest Intercom events in their logs, in order to correlate them with other events in their systems, and then seamlessly send them to Coralogix and take advantage of Coralogix log analytic capabilities, alerts, and top-notch visualization features.
Introduction to Microsoft Azure
The Coralogix Azure integrations enable the collection of logs and metrics from your Azure environment. Gain insights into role, user, group and directory management, successful and failed sign-in events, and application management data that helps you understand your users' experience and immediately troubleshoot any errors.
Java
Deprecation Notice: The Coralogix Java SDK (coralogix-sdk) is deprecated in favor of the OpenTelemetry SDK and will no longer be supported after {cx.deprecations.legacySdkEol}. See the Java OpenTelemetry instrumentation guide for setup options and the end-of-life notice for migration details.
Jenkins plugin
The Coralogix Jenkins plugin facilitates the transmission of audit, security, and pipeline console logs to Coralogix, while pushing tags to the Coralogix platform.
Jenkins telemetry
Monitoring Jenkins telemetry is critical to understanding what is causing delays and failures in your CI/CD pipelines. Coralogix leverages the OpenTelemetry plugin for Jenkins to monitor metrics and traces. Logs and tagging are supported using our Coralogix plugin for Jenkins.
Jira
Monitor and track your Jira activities in real-time by integrating Jira with Coralogix using webhooks.
JumpCloud
JumpCloud’s open directory platform allows the user to unify technology stack across identity, access, and device management, in a manner that doesn’t sacrifice security or functionality.
JumpCloud
JumpCloud is a cloud-based Directory-as-a-Service (DaaS) platform that centralizes the management and security of user identities, devices, and applications within an organization's IT environment. Stream JumpCloud Directory Insights logs to Coralogix to improve observability and strengthen security analytics. This integration centralizes log management and unlocks advanced analysis features.
JumpCloud SCIM identity management
Send your logs to Coralogix using the JumpCloud SCIM Identity Management Integration.
Kandji
Integrate Kandji into Coralogix via OpenTelemetry (OTel) Collector to send Threat-Details logs. These logs track and record security-related events, including potential threats and vulnerabilities, within an organization's Apple devices managed through Kandji.
Kubernetes with Filebeat
kubernetes versions
Kubernetes with Fluent Bit (without Helm)
kubernetes versions
Kubernetes with Fluentd (without Helm)
Fluentd is a versatile data shipper with numerous available plugins and functionalities, playing a pivotal role as a logs shipper to our platform. Below are instructions on how to set up the Fluentd shipper along with the http output plugin to transmit logs to the Coralogix platform.
Lambda configuration
This tutorial provides step-by-step guidance on configuring AWS PrivateLink Lambda connectivity.
Log4j
Deprecation Notice: The SDK is deprecated in favor of the OpenTelemetry SDK and will no longer be supported after {cx.deprecations.legacySdkEol}. See the Java OpenTelemetry instrumentation guide for setup options and the end-of-life notice for migration details.
Log4net
Deprecation Notice: The SDK is deprecated in favor of the OpenTelemetry SDK and will no longer be supported after {cx.deprecations.legacySdkEol}. See the .NET OpenTelemetry instrumentation guide for setup options and the end-of-life notice for migration details.
Logback
Deprecation Notice: The SDK is deprecated in favor of the OpenTelemetry SDK and will no longer be supported after {cx.deprecations.legacySdkEol}. See the Java OpenTelemetry instrumentation guide for setup options and the end-of-life notice for migration details.
Logstash
Coralogix provides a seamless integration with Logstash, so you can send your logs from anywhere and parse them according to your needs.
Mastra
Export OpenTelemetry GenAI spans from Mastra to Coralogix for full visibility into agent runs, model generations, and tool calls.
Microsoft 365
Microsoft 365 provides detailed audit logs of user activities, such as file downloads, data access grants, configuration changes, and DLP event logs. You can monitor the logs in the Coralogix platform.
Microsoft Azure activity and Audit logs with Filebeat
For us to be able to get audit logs from Azure, we are going to use the FileBeat Module.
Microsoft Azure API rate limits
Monitor Azure ARM API rate limits to track remaining request quota and avoid throttling. The integration collects remaining read and write request counts at subscription, global, and tenant scopes.
Microsoft Azure compute scale and quotas
Azure Virtual Network is the fundamental building block for your Azure-based private network. The service enables many types of Azure VMs to securely communicate with each other, the internet, and on-site networks. You can use the Virtual Network statistics to create metrics and send them to Coralogix.
Microsoft Azure Functions
Coralogix provides a seamless integration with Microsoft Azure Cloud, so you can send your logs from anywhere and parse them according to your needs. We provide several trigger strategies with any of the following automatic integrations using Azure custom template deployments: Event Hub, Blob Storage, and Queue Storage.
Microsoft Azure Service Bus
Microsoft Azure Service Bus is a cloud-based messaging service that connects any applications, devices, and services running in the cloud to any other applications or services. You can use the Service Bus statistics to create metrics and send them to Coralogix.
Microsoft Azure SQL Server metrics
Azure SQL Database provides geo-replication for disaster recovery and high availability. You can use the SQL Server metrics to monitor replication link states and send them to Coralogix.
Microsoft Azure status logs
Forwarding your Azure status logs to Coralogix simplifies log consolidation, enhances monitoring capabilities, and streamlines issue resolution. By directing Azure status logs to Coralogix, you gain a unified perspective on your Azure infrastructure's status, enabling swift identification of irregularities, proactive problem-solving, and informed decision-making. This integration empowers teams to optimize resource allocation, bolster system dependability, and uphold operational efficiency, utilizing Coralogix's analytical, alerts, and visualization features to extract actionable insights from Azure status logs and ensure a resilient cloud environment.
Microsoft Azure Virtual Network
Azure Virtual Network is the fundamental building block for your Azure-based private network. The service enables many types of Azure VMs to securely communicate with each other, the internet, and on-site networks. You can use the Virtual Network statistics to create metrics and send them to Coralogix.
Microsoft Defender
Microsoft Defender → Coralogix Via Azure Event Hubs
Microsoft Entra ID logs
Collect Microsoft Entra ID (previously Azure Active Directory) audit, sign-in, and provisioning logs, and submit them to Coralogix for seamless integration.
MongoDB Atlas
MongoDB Atlas is is a fully-managed cloud database that handles the complexity of deploying, managing, and healing your deployments on the cloud service provider of your choice.Deploy this integration to send your MongoDB Atlas metrics to you Coralogix account using the OpenTelemetry Collector.
NLog
Deprecation Notice: The SDK is deprecated in favor of the OpenTelemetry SDK and will no longer be supported after {cx.deprecations.legacySdkEol}. See the .NET OpenTelemetry instrumentation guide for setup options and the end-of-life notice for migration details.
Node.js
Deprecation Notice: The Coralogix Node.js SDK (coralogix-logger) is deprecated in favor of the OpenTelemetry SDK and will no longer be supported after {cx.deprecations.legacySdkEol}. See the Node.js OpenTelemetry instrumentation guide for setup options and the end-of-life notice for migration details.
Node.js Bunyan
Deprecation Notice: The Coralogix Bunyan logger package (coralogix-logger-bunyan) is deprecated in favor of the OpenTelemetry SDK and will no longer be supported after {cx.deprecations.legacySdkEol}. See the Node.js OpenTelemetry instrumentation guide for setup options and the end-of-life notice for migration details.
Node.js Winston
Deprecation Notice: The legacy Coralogix Node.js Winston integration is deprecated in favor of the OpenTelemetry SDK and will no longer be supported after {cx.deprecations.legacySdkEol}. See the Node.js OpenTelemetry instrumentation guide for setup options and the end-of-life notice for migration details.
NXLog
The following tutorial demonstrates how to configure NXLog to seamlessly send your logs to Coralogix.
OCI Audit logs
This integration guide focuses on connecting your Oracle Cloud Infrastructure (OCI) environment to Coralogix using OCI Notification Service.
OneLogin
OneLogin, a cloud-based identity and access management solution, streamlines user authentication and authorization processes for organizations. It features single sign-on (SSO) functionality, allowing users to access multiple applications using a single set of login credentials. OneLogin also offers multi-factor authentication options, such as SMS, email, and biometric verification, for enhanced security. Integration between OneLogin and Coralogix is facilitated via Webhook.
Open commerce API
Coralogix provides an easy way to collect your Open Commerce OrderSearch API logs. The preferred and easiest integration method will be to use our app in the AWS Serverless Application Repository.
OpenClaw
Connect OpenClaw to Coralogix to stream gateway sessions, token usage, costs, model runs, message flow, and webhook activity using built-in OpenTelemetry support.
OpenTelemetry custom logs
Send your custom logs to Coralogix using our OpenTelemetry-compatible endpoint.
OpenTelemetry custom metrics
Coralogix provides a scalable Prometheus-compatible managed service for time-series data. Employ our custom metric endpoint, including serverless computing and quick cURL-like calls, to send counters, gauges, and histograms to Coralogix.
OpenTelemetry custom traces
Send your custom traces to Coralogix using our OpenTelemetry-compatible endpoint.
OpenTelemetry ECS Fargate
Seamlessly stream logs, metrics, and traces generated by AWS ECS Fargate containers to Coralogix for optimal monitoring, analysis, and visualization.
Opsgenie data ingestion
Sending your Opsgenie alerts to Coralogix streamlines alert management, enhances monitoring capabilities, and facilitates comprehensive incident analysis. By directing your Opsgenie alerts into Coralogix, you gain a centralized view of your alerting activities, enabling rapid incident detection, proactive troubleshooting, and data-driven decision-making. This integration empowers teams to optimize response workflows, strengthen system reliability, and ensure operational efficiency, leveraging Coralogix's analytics, alerts, and visualization tools to extract valuable insights from Opsgenie alerts and ensure a streamlined and resilient incident response process.
Optional configurations: Microsoft Azure
Coralogix offers optional configurations for particular use-cases utilizing our Azure deployments.
Overview
AWS PrivateLink provides private connectivity between virtual private clouds (VPCs), supported AWS services, and your on-premises networks without exposing your traffic to the public internet. Interface VPC endpoints, powered by PrivateLink, connect you to services hosted by Coralogix. This tutorial provides AWS Coralogix PrivateLink endpoints, as well as instructions for local and cross-region setup.
Overview
Fleet Management uses the OTel OpAMP protocol to enable visualization and management of your OpenTelemetry agents
PagerDuty Bi-directional integration
Connect Coralogix Cases to PagerDuty with two-way sync. Acknowledge, resolve, comment on, and add resolution notes to a PagerDuty incident and the linked Coralogix Case updates automatically, and the reverse.
PagerDuty data ingestion
Forwarding your PagerDuty alerts to Coralogix streamlines alert consolidation, augments monitoring capabilities, and expedites incident resolution. By routing your PagerDuty alerts into Coralogix, you achieve a unified view of your alerting and incident management activities, enabling swift anomaly detection, proactive troubleshooting, and informed decision-making. This integration empowers teams to optimize incident response workflows, enhance system reliability, and sustain operational effectiveness, utilizing Coralogix's analytics, alerts, and visualization tools to extract valuable insights from PagerDuty alerts and ensure an efficient and resilient incident management process.
Palo Alto Networks Cortex XDR
Forward Cortex XDR alerts, agent audit, and management audit logs to Coralogix over CEF/syslog through an OpenTelemetry Collector relay.
Palo Alto Networks Cortex XSOAR
If you ever need to handle security incidents you know how difficult it can be. More often than not, the system that detected the incident lacks the contextual information needed to figure out whether it's a false positive or something that needs to be investigated further. Other systems typically don't contain the full information either about the discovered incident. Also, automation would be of great help to tell the system: "Hey, if you see this particular incident from a similar IP address go to my firewall and block it and then inform me when you're done". This is where Cortex XSOAR comes in.
Perimeter 81
The following tutorial demonstrates how to integrate Perimeter 81 by sending to an S3 bucket in AWS and sending the logs to Coralogix.
Permissions
Use the following permissions to manage Fleet Management.
Private Service Connect
Connect your GCP workloads to Coralogix privately using Google Cloud's Private Service Connect.
Prometheus
Automatically ship your Prometheus metrics into your Coralogix account and store them without making complex changes to your architecture.
Prometheus agent
You can send your data to Coralogix using Prometheus Agent, a new operational mode of running Prometheus, built directly into the Prometheus binary. The agent mode optimizes the remote write use case configuring the Prometheus instance while disabling some of Prometheus' usual features - querying and alerting.
Prometheus alertmanager data ingestion
Sending your Prometheus alerts to Coralogix streamlines alert aggregation, enhances monitoring capabilities, and facilitates comprehensive incident analysis. By directing your Prometheus alerts into Coralogix, you gain a centralized view of your alerting activities, enabling rapid incident detection, proactive troubleshooting, and data-driven decision-making. This integration empowers teams to optimize response workflows, strengthen system reliability, and ensure operational efficiency, leveraging Coralogix's analytics, alerts, and visualization tools to extract valuable insights from Prometheus alerts and ensure a streamlined and resilient incident response process.
Prometheus operator
This guide shows you how to run Prometheus Operator in Kubernetes to export your data to Coralogix.
Prometheus server
Automatically ship your Prometheus metrics into your Coralogix account and store them without making complex changes to your architecture.
Proofpoint TAP
Stream Proofpoint Targeted Attack Protection (TAP) SIEM events into Coralogix using a native, pull-based managed integration. Get delivered and blocked messages, plus permitted and blocked URL clicks, in your Coralogix account.
Python SDK
Deprecation Notice: The Coralogix Python SDK (coralogix_logger) is deprecated in favor of the OpenTelemetry SDK and will no longer be supported after {cx.deprecations.legacySdkEol}. See the Python OpenTelemetry instrumentation guide for setup options and the end-of-life notice for migration details.
Querying Coralogix with SQL
Java Database Connectivity (JDBC) is a common standard for database drivers, and many popular querying tools support it. This tutorial explains how to use the Coralogix JDBC driver with the popular tools DataGrip, DBeaver, and Tableau.
Queue Storage: Microsoft Azure Resource Manager (ARM)
Coralogix provides seamless integration with Azure cloud, allowing you to send your logs from anywhere and parse them according to your needs.Deploy the Azure Queue Storage integration to send Coralogix your JSON-formatted queue messages using the ARM template below.
Quick start: your first time using Config Navigator
This guide shows how to move from raw YAML to a visual architectural map using Config Navigator, helping you validate your first configuration.
Quick-start extensions
Coralogix offers a variety of out-of-the-box data extensions. Each tailored extension unlocks a set of predefined items - alerts, parsing rules, dashboards, saved views, actions, and more - allowing you to jumpstart Coralogix monitoring of your external-facing resources.
RabbitMQ metrics
This is a tool to pull Metrics from RabbitMQ Admin UI and send them to Coralogix. It will deploy a lambda function to your AWS Account.
RDS enhanced monitoring for CloudWatch metrics
Coralogix offers RDS enhanced monitoring, an extension to AWS metrics from CloudWatch using the Amazon RDS API to collect tags and additional metrics.
Rsyslog
Seamlessly send Coralogix your logs with Rsyslog using TCP (recommended), UDP, or manual installation.
Ruby
Deprecation Notice: The Coralogix Ruby SDK (coralogix_logger) is deprecated in favor of the OpenTelemetry SDK and will no longer be supported after {cx.deprecations.legacySdkEol}. See the end-of-life notice for migration details.
Salesforce
Integrate Salesforce with Coralogix to gain enhanced visibility and real-time monitoring of system events and logs. Salesforce generates detailed logs encompassing system activities, user interactions, and data changes, thereby offering valuable insights into the platform's operations. By leveraging this integration, you can actively monitor your Salesforce environment, optimize its performance, and ensure adherence to security and compliance standards.Users can choose which types of logs to monitor from a comprehensive list of options, including Platform Event logs and Event Log File logs. This customization empowers organizations to tailor their monitoring strategy according to their specific requirements, ensuring that critical events are promptly detected and addressed.
Salesforce commerce cloud
Coralogix provides an easy way to collect your Salesforce logs. The preferred and easiest integration method will be to use our app in the AWS Serverless Application Repository.
Same-region configuration
This tutorial provides step-by-step guidance on configuring AWS PrivateLink same-region connectivity.
Send logs using Amazon Data Firehose
Amazon Data Firehose delivers real-time streaming data to destinations like Amazon Simple Storage Service (Amazon S3), Amazon Redshift, or Amazon OpenSearch Service (successor to Amazon Elasticsearch Service), and now supports delivering streaming data to Coralogix. There is no limit on the number of delivery streams, so it can be used for retrieving data from multiple AWS services. Coralogix is an AWS Partner Network (APN) Advanced Technology Partner with AWS Competencies in DevOps. The platform enables you to easily explore and analyze logs to gain deeper insights into the state of your applications and AWS infrastructure. Analyze all of your AWS service logs while storing only those you need. Generate metrics from aggregated logs to uncover and alert on trends in your AWS services.
SentinelOne
SentinelOne logs provide critical insights into your organization's security, including endpoint activities, detected threats, and user and admin actions. Monitor your logs in the Coralogix platform to identify patterns, investigate threats and abnormal actions, and understand the context of potential security breaches.
SentinelOne (syslog)
This tutorial demonstrates how to seamlessly send SentinelOne logs to Coralogix. The integration requires sending your logs to an interceptive server and then forwarding them from the server to Coralogix.
Serilog
Coralogix customers with Microsoft .NET applications using the Serilog logging library, are able to send logs to Coralogix using OpenTelemetry (OTel).
Shipping snowflake logs and Audit data to Coralogix with OpenTelemetry
This tutorial demonstrates how to centralize logging for Snowflake by sending your logs to Coralogix.
Slack access logs
Collect Slack access logs into Coralogix by enabling Collect access logs on the Coralogix Slack integration. This capability requires the Slack admin scope.
Slack Audit logs
Easily collect and analyze your Slack audit logs in Coralogix using our seamless Slack Audit Logs integration package.
Slack data ingestion
Log the activity on your Slack channels and send it to Coralogix with the Coralogix application.
Slack integration
Connect Coralogix Cases to your Slack workspace. Send Case notifications to Slack channels, sync Slack thread replies back into the Case timeline, and surface rich previews of Coralogix Case URLs in Slack.
Snyk vulnerability monitoring with Coralogix
This tutorial demonstrates how to conduct Snyk vulnerability monitoring with Coralogix by exporting Snyk's security testing data using Prometheus.
Static IPs and regional DNS endpoints
Coralogix is migrating to static Elastic IP ranges and standardized regional DNS endpoints. This page lists the new IP allowlists and DNS endpoints by region.
StatsD
StatsD is an open-source standard and, by extension, a toolkit designed for sending, collecting, and aggregating custom metrics from diverse applications. This tutorial demonstrates installing and running StatsD to send your metrics to Coralogix.
StatusPage data ingestion
Sending the Statuspage feed to Coralogix facilitates centralized incident monitoring, analysis, and streamlined communication. By directing Statuspage updates into Coralogix's log management platform, organizations can consolidate incident-related information, gain insights into the impact of service disruptions, and correlate these events with other operational data. This integration empowers teams to enhance incident response, analyze patterns, and improve communication by leveraging Coralogix's log analysis and visualization tools to extract valuable insights from Statuspage feeds, ultimately leading to improved service reliability, customer satisfaction, and operational resilience.
SURF
Seamlessly integrate your SURF logs with Coralogix.
Suricata
This guide explains how to integrate Suricata with Coralogix using the OpenTelemetry Collector. It leverages the flexibility and vendor-agnostic design of OpenTelemetry for observability pipelines.
Syslog
Whether your system generates syslog messages in rfc3164 or rfc5424 format, or lets you transform them to a custom format, seamlessly send your syslogs to Coralogix.
Syslog using OpenTelemetry
This tutorial demonstrates how to use custom syslog to send your logs to Coralogix using OpenTelemetry.
SyslogNG
Determining syslog type
Telegraf
This tutorial demonstrates how to send your metrics to Coralogix via Telegraf.
Telegraf operator
This tutorial demonstrates how to run Telegraf Operator in Kubernetes to export your telemetry data to Coralogix.
Tenable
Forward Tenable audit logs, vulnerability findings, asset inventory, plugin catalog metadata, compliance findings, and Web App Scanning data to Coralogix to gain visibility into administrative activity, configuration changes, security risk, and vulnerability management context.
Tenable Attack Surface Management
Pull external attack surface assets from Tenable Attack Surface Management (ASM) into Coralogix to monitor your internet-facing exposure alongside the rest of your telemetry and retain it long term.
Tenable Identity Exposure
Pull identity alerts, attacks, and deviances from your Tenable Identity Exposure (Tenable.ad) deployment into Coralogix for unified Active Directory security investigation and long-term retention.
Tenable OT Security
Pull OT asset inventory, vulnerability findings, and plugin metadata from your on-premise Tenable OT Security appliance into Coralogix for unified security investigation and long-term retention.
Tenable Security Center
Pull vulnerabilities, assets, and plugin metadata from your on-premise Tenable Security Center (Tenable.sc) deployment into Coralogix for unified security investigation and long-term retention.
Upcoming deprecations
Coralogix offers a regional endpoint for sending data into the Coralogix platform from all observability sources. This page provides updates regarding upcoming endpoint changes and deprecations.
Upgrade configurations
Upgrade template and OpenTelemetry Collector versions across your fleet using the one-click upgrade workflow in Fleet Management.
UpGuard
The following tutorial demonstrates how to send your telemetry data to Coralogix using UpGuard. Follow this five-step guide for each notification that you would like to send us.
Upwind
Overview
Vector
Coralogix provides seamless integration with Vector so you can send your logs from anywhere and parse them according to your needs.
Visual builder
Edit OpenTelemetry Collector pipelines for Fleet Management visually — drag components onto a graph, configure them in a structured form, and apply changes back to YAML.
VPC peering configuration
This tutorial provides step-by-step guidance on configuring AWS PrivateLink VPC peering connectivity.
Wallarm
Wallarm is an API and application security platform that protects modern web apps, microservices, and APIs from attacks by combining real-time threat detection with deep traffic analysis. It inspects HTTP and API traffic to identify vulnerabilities and malicious behavior such as OWASP Top 10 and API-specific attacks, using both signature-based and behavioral detection. Wallarm integrates with cloud-native environments (Kubernetes, service meshes, CI/CD pipelines) and provides centralized visibility, analytics, and automated response options, helping teams secure applications throughout the development and runtime lifecycle without slowing delivery.
Windows event logs with Winlogbeat
Coralogix provides a seamless integration with Winlogbeat to help you send your Windows Event Viewer logs directly to Coralogix and parse them according to your needs.
Wiz
The integration of Coralogix and Wiz empowers development teams to take complete ownership of their services, with full visibility into the performance and resource vulnerabilities, simplifying the analysis of the impact on their code and infrastructure.
Zeek
In order to ship Zeek logs to Coralogix, we need to first install Filebeat.
Zoom
Send your Zoom Sign-In/Sign-Out Activity Logs and Operation Logs to Coralogix for centralized monitoring and analysis.
Zscaler Internet Access (ZIA)
With Coralogix integration, ZIA and Zscaler's Nanolog Streaming Service (NSS) offer real-time visibility into internet traffic, user activity, and log streaming. This allows organizations to monitor and analyze network traffic for security threats and compliance purposes.
Zscaler Secure Private Access (ZPA)
Configure Zscaler Secure Private Access (ZPA) to seamlessly send logs to Coralogix.