About Illumio Integrations
The following topics provide an overview of the available Illumio integrations with third-party providers.
Ansible
Use Ansible modules for VEN and C-VEN pairing and to create, update, and remove labels.
See User Guide.
Links | Validated Compatibility |
|---|---|
Ansible 21.2+ PCE 22.2, 22.5, SaaS |
Armis Connector for Illumio
The Illumio - Armis integration allows you to view iOT inventories and their metadata. This integration extends Illumio's zero-trust model for IoT devices to provide IoT/OT segmentation.
Check Point Connector for Illumio
The Illumio integration with Check Point allows you to collect and analyze firewall logs using Check Point's native log-export capability and view this data within the Illumio Platform. With this integration, your organization can make data-driven security-policy decisions to improve its security posture.
Fortinet
The Illumio and Fortinet integration allows you to ingest flow logs from both on-premise and cloud Fortinet FortiGate firewalls into Illumio Insights. This integration delivers unified visibility across the network and enables you to rapidly detect security gaps and identify potential breaches before they occur.
Illumio App for ServiceNow CMDB
The Illumio App for ServiceNow provides enriched workload collection on the Illumio Policy Compute Engine (PCE) instance using the database of workloads discovered by ServiceNow. You can use the ServiceNow tables as a customized source for workloads and synchronize the data to the PCE both automatically and manually.
See ServiceNow CMDB.
Illumio App for Splunk and Illumio Technology Add-On for Splunk
The Illumio App for Splunk integrates with the Illumio Policy Compute Engine (PCE) to provide security and operational insights into your Illumio-secured data center.
The Illumio Technology Add-On for Splunk enriches Illumio PCE data with the Common Information Model (CIM) field names, event types and tags.
See Illumio App for Splunk 3.2.x and Illumio App and Technology Add-On for Splunk 4.x.
Links | Validated Compatibility |
|---|---|
User Guide | Splunk 9.1, 9.0, 8.2, 8.1 + PCE 21.2, 21.5, 22.2, 22.5, and SaaS |
Integration Guide 4.x | Splunk 9.3, 9.2, 9.1, 9.0, 8.2, 8.1 + PCE 21.5, 22.2, 22.5, 23.2, 23.5 and SaaS |
Illumio Application for QRadar (SIEM)
The Illumio App for QRadar integrates with the Illumio Policy Compute Engine (PCE) to provide insights into your Illumio-secured data center. It provides the following dashboards that are integrated into the QRadar user interface:
The Security Operations dashboard displays east-west traffic, so you can see potential attacks and identify compromised workloads.
The PCE Operations dashboard allows you to monitor the health of all deployed and managed PCEs.
See QRadar.
Links | Validated Compatibility |
|---|---|
Integration Guide | QRadar 7.4.3+PCE 24.1 (SaaS), 23.5, 23.2, 22.5, |
QRadar 7.4.1+PCE SaaS |
IBM QRadar (SOAR)
The Illumio integration with the IBM SOAR platform allows you to automate actions in Illumio Core through the use of SOAR functions and workflows.
Illumio Plugin for Netskope Cloud Exchange
The Illumio Plugin for Netskope Cloud Exchange extends Illumio Zero Trust Segmentation (ZTS) principles to remote access architectures. Using Illumio's ZTS combined with Netskope's Security Service Edge provides dynamic access controls and security across hybrid and multi-cloud environments.
See Netskope.
Illumio Sentinel Solution
The Illumio Sentinel Solution provides an integration between Microsoft Sentinel and Illumio's Zero Trust Segmentation platform. This integration enhances SecOps and provides greater visibility into workloads, faster response to incidents, and strengthened compliance.
See Sentinel 3.4.0.
Illumio Terraform Provider
The Illumio Terraform source allows you to manage resources and policy objects on the Illumio Policy Compute Engine (PCE). With Terraform, you can represent your infrastructure and policy as code and also manage the PCE state.
See Terraform.
Links | Validated Compatibility |
|---|---|
v1.1.4 | Terraform 1.4+ PCE 21.2, 21.5, 22.2, 22.5, SaaS |
Palo Alto Cortext (SOAR)
This integration connects to Illumio Core APIs to perform investigative and restorative actions. It retrieves the traffic analysis of a port or protocol, creates segmentation rule-sets for workloads, and creates enforcement boundaries for microsegmentation.
Links | Validated Compatibility |
|---|---|
Cortex 6.0 (6.2, 6.5, 6.8, and master) PCE 22.2, 21.5, 21.2, SaaS |
Palo Alto Networks Next-Generation Firewall (NGFW)
The Illumio integration with Palo Alto Networks Next-Generation Firewall allows organizations to collect and analyze firewall logs to enhance visibility, drive segmentation decisions, and enhance their security posture.
See About the Illumio and Palo Alto Networks Next-Generation Firewall (NGFW) Integration.
ServiceNow ITSM
The Illumio and ServiceNow ITSM integration allows you to create a ServiceNow IT ticket from within Illumio Console.
Wiz Connector for Illumio
The Wiz Connector for Illumio integration uses security events from the Wiz application to augment flow data in Illumio Console to help you understand how resources outside your organization are interacting with your data center and cloud assets.
See Wiz Connector for Illumio Integration Guide.
Links | Validated Compatibility |
|---|---|
N/A |