IntegrationsSIEM
Supported Integrations
Connect to all major siem platforms through a single unified API.
Splunk
Sumologic




IBM QRadar

Google Chronicle
Microsoft Sentinel

Fortinet
Elastic
Data Normalization at a Glance
Different vendors, different schemas. Unizo normalizes them all into one unified output.
Splunk
_timesourcesourcetype_rawMicrosoft Sentinel
TimeGeneratedSourceSystemTypeRawDataGoogle Chronicle
metadata.event_timestampmetadata.product_namemetadata.event_typeudmElastic
@timestampagent.nameevent.categorymessageU
U
Unified Schema
Consistent across all vendors
timestampsourceeventTyperawEventseveritycategoryhostDetailed Field Mapping
Splunk
_timetimestampsourcesourcesourcetypeeventType_rawrawEventMicrosoft Sentinel
TimeGeneratedtimestampSourceSystemsourceTypeeventTypeRawDatarawEventGoogle Chronicle
metadata.event_timestamptimestampmetadata.product_namesourcemetadata.event_typeeventTypeudmrawEventElastic
@timestamptimestampagent.namesourceevent.categoryeventTypemessagerawEventWhat You Can Build
Use Unizo's unified API to power these capabilities and more.
Log Aggregation
Collect and normalize logs from all SIEM platforms.
Alert Correlation
Correlate alerts across multiple SIEM sources.
Threat Detection
Enable unified threat detection rules across platforms.
Incident Response
Trigger automated response workflows from SIEM alerts.
Unified Data Models
Consistent data structures that work the same way across all siem platforms.
Event
Security events with normalized fields
Alert
Triggered alerts with severity and context
Rule
Detection rules and correlation logic
Investigation
Investigation cases and timelines