- logs are ingesting
- dashboards populate (after provisioning)
- alerting can be enabled (built-in or custom)
The mental model
Almost every integration follows this pattern:- Ingest events (API integration or syslog)
- Store events in your SIEM datastore (Wazuh Indexer / OpenSearch-backed)
- (Often) build alerts in Graylog → alerts land in
gl-events* - CoPilot shows alerts in Incident Management → Alerts → operators open Cases
First-wave integrations
Network connectors (syslog)
- Network connectors overview
- Fortinet: FortiGate
- Palo Alto Networks: PAN-OS
- Cisco: ASA
