Integrations
Lagebild reads what your systems already see and hands each case to the people and tools that act on it. On the plant side it only reads, at agreed low rates, and never touches controllers.
Available: works in Lagebild today. Planned: on our roadmap; if you need it first, tell us. Today via e-mail: works now through the tool’s e-mail-to-ticket channel; the native connector is planned. With setup: works with a configuration we provide, connected together with you.
OT systems and process data
SCADA, historians and OT monitoring you already run. Read-only, through Telegraf, with a documented maximum read rate.
…and 300+ more sources through Telegraf: their metrics are stored as they come, and we map the ones that matter to cases. If your system is not listed, we can almost always connect it.
- With setup
OPC UA (official site)
Read-only from SCADA servers and historians, by subscription or at least 10 s apart. Never polls PLCs or field devices.
- Available
MQTT (official site)
Process values and process alarms from the broker you already run. Subscribes only; tested end to end, a value out of range opens a case.
- Planned
AVEVA PI System (official site)
Process values and their normal ranges from the historian.
- Planned
Siemens WinCC
Alarms and process values from the SCADA system.
- With setup
Historian export (CSV, SQL)
A read-only query on the historian or MES database, at most once a minute, when there is no live access.
- With setup
Modbus TCP (read from a gateway) (official site)
Process values from a Modbus gateway or the SCADA server, read function codes only, at least 10 s apart. Never writes.
- With setup
Apache Kafka (official site)
Process values from a topic your historian or MES already publishes. Consumes only, in its own consumer group.
- With setup
HTTP (POST from any system)
Any system that can send an HTTP POST, such as a script or a gateway, delivers process values.
- Planned
Claroty (official site)
Alerts and assets from your OT monitoring.
- Planned
Nozomi Networks (official site)
Alerts and assets from your OT monitoring.
Industrial protocols and passive network sensing
Where there is no source to read, a passive sensor on a mirror (SPAN) port sees the traffic. It sends nothing into the plant network.
- Planned
Zeek (official site)
Logs every connection on a mirror port and decodes IT and OT protocols.
- Planned
CISA ICSNPP (official site)
Zeek parsers for industrial protocols, published by CISA.
- Planned
Modbus (official site)
Reads and writes to controllers, decoded passively.
- Planned
Siemens S7 (S7comm)
Siemens S7 traffic, including program downloads and writes, decoded passively.
- Planned
DNP3 (official site)
Telecontrol traffic in energy and water, decoded passively.
- Planned
BACnet (official site)
Building automation traffic, decoded passively.
- Planned
Suricata (official site)
Flags known attacks on the same mirror port.
- With setup
NetFlow, IPFIX, sFlow
Flow records from switches, routers and firewalls (NetFlow v5/v9, IPFIX, sFlow v5).
- With setup
SNMP (polling) (official site)
Interface counters and status from switches, firewalls and UPS, with a read-only SNMPv3 user.
- With setup
SNMP traps
Link down, power supply and other traps that network devices send.
Firewalls, endpoints and directories
The IT side of the picture: who signed in, when and from where, and what the firewall and endpoint protection saw.
- Available
Syslog (RFC 5424) (official site)
Firewall decisions and VPN logins become events the rules use; tested end to end. Switches and servers too.
- With setup
Fortinet FortiGate (official site)
Firewall and VPN logs over syslog, mapped to network events and VPN logins.
- With setup
Palo Alto Networks (official site)
Firewall and VPN logs over syslog, mapped to network events and VPN logins.
- With setup
Sophos Firewall (official site)
Firewall and VPN logs over syslog, mapped to network events and VPN logins.
- With setup
pfSense (official site)
Firewall logs over syslog, mapped to network events.
- With setup
OPNsense (official site)
Firewall logs over syslog, mapped to network events.
- Planned
Microsoft Defender for Endpoint (official site)
Endpoint alerts through the Defender API, with least-privilege access.
- Planned
Windows event logs and Active Directory (official site)
Sign-ins and account changes, through the OpenTelemetry Collector or Windows Event Forwarding.
SIEM and logging
Lagebild sits on top of your SIEM instead of replacing it: it reads from it and sends its cases back.
- Planned
OpenTelemetry (official site)
One vendor-neutral collector for logs from syslog and APIs.
- Planned
Microsoft Sentinel (official site)
Reads its alerts, or sends the cases from Lagebild into it.
- Planned
Splunk (official site)
Reads its alerts, or sends the cases from Lagebild into it.
- Planned
Any SIEM (syslog, CEF)
Every case forwarded to your SIEM over syslog or CEF.
Ticketing and ITSM
A case becomes a ticket in the queue your team already works from, and closes with it.
- Today via e-mail
Jira Service Management (official site)
Today: each case opens a ticket through the tool’s e-mail channel, routed like any notification. Planned: a native connector that closes the ticket with the case.
- Today via e-mail
ServiceNow (official site)
Today: each case opens a ticket through the tool’s e-mail channel, routed like any notification. Planned: a native connector that closes the ticket with the case.
- Today via e-mail
TOPdesk (official site)
Today: each case opens a ticket through the tool’s e-mail channel, routed like any notification. Planned: a native connector that closes the ticket with the case.
Messaging and notifications
Each case reaches the right person: routed by severity, rule, zone or NIS2 relevance.
- Available
E-mail (SMTP) (official site)
Routed cases, requests for a step and notices, to a team or one person.
- Available
Webhooks
Every case event as signed JSON (HMAC) to an endpoint of yours: SOC, SOAR or your own scripts.
- Available
Power Automate, n8n
Through the signed webhook: start your own flows on any case event, such as posting to a channel or updating a register.
- Available
Node-RED (official site)
Open source (Apache 2.0) and common in plants: receive the signed webhook and run your own flows.
- Available
Kestra (official site)
Open source (Apache 2.0) workflow engine that runs on premises: receive the signed webhook and orchestrate the follow-up.
- Available
Microsoft Teams (official site)
Cases posted to a channel as cards, through a channel webhook.
- Planned
Microsoft Teams app (official site)
An app you install in a few clicks: cases and requests in Teams.
- Planned
Slack app (official site)
An app you install in a few clicks: cases and requests in Slack.
- Planned
SMS
Short notices for urgent cases, to the people the routes name.
Identity and sign-in
Sign in with the accounts you already have, with multi-factor authentication.
- Planned
Keycloak (official site)
Single sign-on with multi-factor authentication, a separate realm per customer, works air-gapped.
- Planned
Microsoft Entra ID (official site)
Sign in with your company accounts through Keycloak; sign-in logs as a source.
- Planned
OpenID Connect (official site)
Connect the identity provider you already use.