Log Sources
Log Sources
Every source Hal monitors is connected read-only, ingested every few minutes, and retained for 365 days — searchable across all of a client’s sources at once. Cloud sources connect by API with nothing installed; Windows endpoints use a lightweight log shipper; network gear sends syslog.
Mailbox, SharePoint, and admin activity from the Management Activity API.
Sign-in logs, risk detections, and directory audits via Microsoft Graph.
Login, admin, and security events from the Reports API and Alert Center.
Windows event logs via a userspace log shipper — not an EDR.
Routers, firewalls, and switches over syslog.
Setup walkthroughs for cloud tenants live under Getting Started.