Skip to main content

Integrations

About Illumio Integrations

This topic describes the available Illumio integrations with third-party providers.

For information about integrations not described in this topic and for links to the software, see Table 1, “Apps and Integration Tools.

Armis Connector for Illumio

The Illumio - Armis integration allows you to view iOT inventories and their metadata. This integration extends Illumio's zero-trust model to IoT devices to provide IoT/OT segmentation.

See About the Illumio - Armis Integration.

Check Point Connector for Illumio

The Illumio integration with Check Point allows you to collect and analyze firewall logs using Check Point's native log-export capability and view this data within the Illumio Platform. With this integration, your organization can make data-driven security-policy decisions to improve its security posture.

See About the Illumio - Check Point Integration.

Illumio App for ServiceNow CMDB

The Illumio app for ServiceNow provides enriched workload collection on the Illumio Policy Compute Engine (PCE) instance using the database of workloads discovered by ServiceNow. You can use the ServiceNow tables as a customized source for workloads and synchronize the data to the PCE both automatically and manually.

See ServiceNow CMDB.

Illumio App for Splunk and Illumio Technology Add-On for Splunk

The Illumio App for Splunk integrates with the Illumio Policy Compute Engine (PCE) to provide security and operational insights into your Illumio-secured data center.

The Illumio Technology Add-On for Splunk enriches Illumio Policy Compute Engine (PCE) data with Common Information Model (CIM) field names, event types, and tags.

See Illumio App for Splunk Version 3.2.x and Illumio App for Splunk Version 4.0.x.

Illumio Application for QRadar

Illumio Application for QRadar integrates with the Illumio Policy Compute Engine (PCE) to provide insights into your Illumio-secured data center. It provides the following dashboards that are integrated into the QRadar user interface:

  • The Security Operations dashboard displays east-west traffic, so you can see potential attacks and identify compromised workloads.

  • The PCE Operations dashboard allows you to monitor the health of all deployed and managed PCEs.

See Illumio Application for QRadar 1.4.0.

Illumio Plugin for Netskope Cloud Exchange

The Illumio Plugin for Netskope Cloud Exchange extends Illumio Zero Trust Segmentation (ZTS) principles to remote access architectures. Using Illumio's ZTS combined with Netskope's Security Service Edge (SSE) provides dynamic access controls and security across hybrid and multi-cloud environments.

See Illumio® Plugin for Netskope Cloud Exchange.

Illumio Sentinel Solution

The Illumio Sentinel Solution provides an integration between Microsoft Sentinel and Illumio's Zero Trust Segmentation platform. This integration enhances SecOps and provides greater visibility into workloads, faster response to incidents, and strengthened compliance.

See Illumio Sentinel Solution 3.4.0

Illumio Terraform Provider

The Illumio Terraform source allows you to manage resources and policy objects on the Illumio Policy Compute Engine (PCE). With Terraform, you can represent your infrastructure and policy as code and also manage the PCE state.

See Terraform.

Wiz Connector for Illumio

The Wiz Connector for Illumio integration uses security events from the Wiz application to augment flow data in Illumio Console to help you understand how resources outside your organization are interacting with your data center and cloud assets.

See Wiz Connector for Illumio Integration Guide.

Table 1. Apps and Integration Tools

Integration

Description

Links

Validated Compatibility

Ansible

Ansible modules for

  • VEN and C-VEN pairing

  • Label creation/update/removal

User Guide

Version 0.2.6

  • Ansible 2.12+

  • PCE 22.5, 22.2, 21.5, 21.2, SaaS

Armis

Allows you to view flow data from IoT devices and between IoT devices and enforce policies without needing to install a physical device

Integration Guide

SaaS

Check Point

Use Check Point's native log export capabilities to collect and analyze firewall logs and use their data to make data-driven policy decisions

Integration Guide

SaaS

IBM QRadar (SIEM)

Connector and Dashboards to view Illumio flow and event data

v1.4

Integration Guide

(HTML)

(PDF)

v1.3

Integration Guide (PDF)

  • QRadar 7.4.3+

  • PCE 24.1 (SaaS), 23.5, 23.2, 22.5, and 21.5

  • QRadar 7.4.1+

  • PCE 21.2, 19.3, SaaS

IBM QRadar (SOAR)

Provides a selective port-blocking playbook

v1.0

User Guide (PDF)

  • PCE 21.2+, SaaS

Netskope Cloud Exchange

Ensures dynamic access controls and security across hybrid and multi-cloud environments

v1.0.0 Integration Guide

(HTML)

(PDF)

Palo Alto Cortex (SOAR)

Provides a selective port-blocking playbook

v1.0.1

Configuration Guide

Port Blocking Playbook Guide

  • Cortex 6.0 (6.2, 6.5, 6.8, and master) PCE 22.2, 21.5, 21.2, SaaS

Python (SDK)

Python REST client for Illumio PCE APIs

v1.1.3

User Guide

  • PCE 21.2+, SaaS

Sentinel

Azure Function Apps for data ingestion

v3.4.0

Integration Guide

(HTML)

(PDF)

  • PCE SaaS

ServiceNow (CMDB)

Uses ServiceNow CMDB as the source of truth for labeling PCE workloads with R/A/E/L labels

v2.1.0

Installation and Configuration Guide (PDF)

  • Vancouver, Washington DC, Xanadu

  • PCE 22.5, 23.2.30, 23.5.20, 24.2.10, or SaaS

Splunk (SIEM)

Connector and Dashboards to view Illumio flow and event data

TA-Illumio v3.2.4

Illumio App for Splunk v3.2.1

User Guide v3.2.4 (HTML)

User Guide v3.2.4 (PDF)

EULA (PDF)

TA-Illumio v4.0.3

Illumio App for Splunk v4.0.1

Integration Guide v4.0.x

(HTML)

(PDF)

For v3.2.4:

  • Splunk 9.1, 9.0, 8.2, 8.1 + PCE 21.2, 21.5, 22.2, 22.5, and SaaS

For v4.0.3:

  • Splunk 9.3, 9.2, 9.1, 9.0, 8.2, 8.1 + PCE 21.5, 22.2, 22.5, 23.2, 23.5 and SaaS

Terraform

Terraform HCL scripts to manage PCE policy and policy objects

v1.1.4

User Guide

  • Terraform 1.4+

  • PCE 22.5, 22.2, 21.5, 21.2, SaaS

Wiz

The Wiz Connector for Illumio uses security events from Wiz cloud to augment cloud resources and flow data in Illumio to help you understand potential vulnerabilities and exposures to security breaches in your cloud environment.

Wiz Connector for Illumio

(HTML)

(PDF)

N/A



Note

Integration with Third-Party Applications. Illumio’s products (the “Products”) may contain features designed to integrate and/or interoperate with Third-Party Applications (as defined below). Illumio cannot guarantee the continued availability of such Product features, and may cease providing them without entitling an Illumio customer (‘Customer”) to any refund, credit, or other compensation, if for example and without limitation, the provider of a Third-Party Application ceases to make the Third-Party Application available for interoperation with the corresponding Product features in a manner acceptable to Illumio.

If Customer chooses to use a Third-Party Application with a Product, Customer grants Illumio permission to allow the Third-Party Application and its provider to access Customer Data and information about Customer’s usage of the Third-Party Application as appropriate for the interoperation of that Third-Party Application with a Product.