# RunReveal Documentation > RunReveal is a security log management and detection platform. It collects, normalizes, and analyzes security logs from 60+ sources with built-in detections, AI-powered investigation, and alerting. ## Getting Started - [Introduction](https://docs.runreveal.com): Overview of RunReveal and core concepts - [Onboarding Guide](https://docs.runreveal.com/how-to-guides/onboarding): Step-by-step onboarding walkthrough - [Quick Start: Detections, Signals, and Alerts](https://docs.runreveal.com/how-to-guides/detections-signals-alerts-quick-start): End-to-end detection setup guide ## How-To Guides - [Collect Nginx Logs](https://docs.runreveal.com/how-to-guides/collect-nginx-logs): Ingest nginx access/error logs - [Kubernetes Logs](https://docs.runreveal.com/how-to-guides/kubernetes-logs): Collect Kubernetes audit logs - [OpenAPI Spec](https://docs.runreveal.com/how-to-guides/openapi): RunReveal API specification ## AI Chat - [Native AI Chat](https://docs.runreveal.com/ai-chat/native-ai-chat): Built-in AI assistant for log investigation - [Model Context Protocol](https://docs.runreveal.com/ai-chat/model-context-protocol): MCP integration for external AI tools - [Prompts](https://docs.runreveal.com/ai-chat/prompts): Custom prompt configuration - [Agents](https://docs.runreveal.com/ai-chat/agents): Autonomous AI agents for scheduled tasks ## Dashboards & Graphs - [Dashboards](https://docs.runreveal.com/dashboards): Creating and managing dashboards ## Log Management - [Explore Logs](https://docs.runreveal.com/logs/search): Searching and exploring log data - [Queries](https://docs.runreveal.com/logs/queries): Saved queries and SQL syntax - [Custom Views](https://docs.runreveal.com/logs/custom-views): Custom log views ### Log Processing (Pipelines) - [Pipelines Overview](https://docs.runreveal.com/logs/log-processing/getting-started): Log processing pipeline setup - [Transforms](https://docs.runreveal.com/logs/log-processing/transforms): Transform log fields - [Filtering](https://docs.runreveal.com/logs/log-processing/filtering): Filter logs in pipelines - [Enrichments](https://docs.runreveal.com/logs/log-processing/enrichments): Enrich logs with additional context - [Sampling](https://docs.runreveal.com/logs/log-processing/sampling): Sample high-volume log streams - [Dropping](https://docs.runreveal.com/logs/log-processing/dropping): Drop unwanted logs - [Destinations](https://docs.runreveal.com/logs/log-processing/destinations): Route logs to external destinations ## Sources - [Sources Overview](https://docs.runreveal.com/sources): Connecting log sources to RunReveal - [Health Checks](https://docs.runreveal.com/sources/health-checks): Monitor source health ### Object Storage Sources - [Azure Blob Storage](https://docs.runreveal.com/sources/object-storage/azure) - [External S3](https://docs.runreveal.com/sources/object-storage/external-s3) - [Google Cloud Storage](https://docs.runreveal.com/sources/object-storage/gcs) - [Cloudflare R2](https://docs.runreveal.com/sources/object-storage/r2) ### Forwarders - [Datadog Forwarder](https://docs.runreveal.com/sources/forwarders/datadog-forwarder) - [Fluent Bit](https://docs.runreveal.com/sources/forwarders/fluent-bit) - [Logstash](https://docs.runreveal.com/sources/forwarders/logstash) - [OTLP JSON](https://docs.runreveal.com/sources/forwarders/otlp-json) - [Reveald](https://docs.runreveal.com/sources/forwarders/reveald) - [Vector](https://docs.runreveal.com/sources/forwarders/vector) ### Source Types - [1Password](https://docs.runreveal.com/sources/source-types/1password) - [Abnormal AI](https://docs.runreveal.com/sources/source-types/abnormal) - [Atlassian](https://docs.runreveal.com/sources/source-types/atlassian) - [Auth0](https://docs.runreveal.com/sources/source-types/auth0) - [Authentik](https://docs.runreveal.com/sources/source-types/authentik) - [AWS ALB](https://docs.runreveal.com/sources/source-types/aws/alb) - [AWS CloudTrail](https://docs.runreveal.com/sources/source-types/aws/cloudtrail) - [AWS DNS](https://docs.runreveal.com/sources/source-types/aws/dns) - [AWS Flow Logs](https://docs.runreveal.com/sources/source-types/aws/flow) - [AWS GuardDuty](https://docs.runreveal.com/sources/source-types/aws/guardduty) - [AWS Hosted Zone](https://docs.runreveal.com/sources/source-types/aws/hosted-zone) - [AWS Network Firewall](https://docs.runreveal.com/sources/source-types/aws/network-firewall) - [AWS Redshift Audit](https://docs.runreveal.com/sources/source-types/aws/redshift-audit) - [AWS S3 Access](https://docs.runreveal.com/sources/source-types/aws/s3-access) - [AWS WAF](https://docs.runreveal.com/sources/source-types/aws/aws-waf) - [Azure Activity Logs](https://docs.runreveal.com/sources/source-types/azure/activity-logs) - [Azure Flow Logs](https://docs.runreveal.com/sources/source-types/azure/azure-flow) - [Azure Entra](https://docs.runreveal.com/sources/source-types/azure/entra) - [Backfill](https://docs.runreveal.com/sources/source-types/backfill) - [Bitwarden](https://docs.runreveal.com/sources/source-types/bitwarden) - [BOX](https://docs.runreveal.com/sources/source-types/box) - [CircleCI](https://docs.runreveal.com/sources/source-types/circleci) - [Cloudentity](https://docs.runreveal.com/sources/source-types/cloudentity) - [Cloudflare Audit](https://docs.runreveal.com/sources/source-types/cloudflare/audit) - [Cloudflare Firewall](https://docs.runreveal.com/sources/source-types/cloudflare/firewall) - [Cloudflare Gateway DNS](https://docs.runreveal.com/sources/source-types/cloudflare/gateway-dns) - [Cloudflare Gateway HTTP](https://docs.runreveal.com/sources/source-types/cloudflare/gateway-http) - [Cloudflare Gateway Network](https://docs.runreveal.com/sources/source-types/cloudflare/gateway-network) - [Cloudflare HTTP](https://docs.runreveal.com/sources/source-types/cloudflare/http) - [Cloudflare Zero Trust Access](https://docs.runreveal.com/sources/source-types/cloudflare/zt-access) - [ConductorOne](https://docs.runreveal.com/sources/source-types/conductor-one) - [CrowdStrike Event Stream](https://docs.runreveal.com/sources/source-types/crowdstrike/event-stream) - [CrowdStrike FDR](https://docs.runreveal.com/sources/source-types/crowdstrike/fdr) - [Cursor Audit Logs](https://docs.runreveal.com/sources/source-types/cursor-audit-logs) - [Cyberhaven](https://docs.runreveal.com/sources/source-types/cyberhaven) - [DNSFilter](https://docs.runreveal.com/sources/source-types/dnsfilter) - [Dope Security](https://docs.runreveal.com/sources/source-types/dope-security) - [Dropbox](https://docs.runreveal.com/sources/source-types/dropbox) - [Duo Security](https://docs.runreveal.com/sources/source-types/duo) - [Fastly WAF](https://docs.runreveal.com/sources/source-types/fastly-waf) - [Fireblocks](https://docs.runreveal.com/sources/source-types/fireblocks) - [FireHydrant](https://docs.runreveal.com/sources/source-types/firehydrant) - [Fluent Bit](https://docs.runreveal.com/sources/source-types/fluent-bit) - [Formal Security](https://docs.runreveal.com/sources/source-types/formal-security) - [GCP](https://docs.runreveal.com/sources/source-types/gcp) - [Generic Sources](https://docs.runreveal.com/sources/source-types/generic) - [GitHub Audit](https://docs.runreveal.com/sources/source-types/github/audit) - [GitHub Rulesets](https://docs.runreveal.com/sources/source-types/github/rulesets) - [GitHub Webhook](https://docs.runreveal.com/sources/source-types/github/webhook) - [GitLab](https://docs.runreveal.com/sources/source-types/gitlab) - [Google Workspace](https://docs.runreveal.com/sources/source-types/google-workspace-logs) - [HashiCorp Vault](https://docs.runreveal.com/sources/source-types/hashicorp-vault) - [Heroku](https://docs.runreveal.com/sources/source-types/heroku) - [JAMF](https://docs.runreveal.com/sources/source-types/jamf) - [JAMF Protect](https://docs.runreveal.com/sources/source-types/jamfprotect) - [JumpCloud](https://docs.runreveal.com/sources/source-types/jumpcloud) - [Keeper Security](https://docs.runreveal.com/sources/source-types/keeper) - [Kubernetes Audit Logs](https://docs.runreveal.com/sources/source-types/kubernetes) - [Linear](https://docs.runreveal.com/sources/source-types/linear) - [Lumos](https://docs.runreveal.com/sources/source-types/lumos) - [Microsoft 365](https://docs.runreveal.com/sources/source-types/microsoft-365) - [MongoDB](https://docs.runreveal.com/sources/source-types/mongodb) - [n8n](https://docs.runreveal.com/sources/source-types/n8n) - [Notion](https://docs.runreveal.com/sources/source-types/notion) - [Obsidian Security](https://docs.runreveal.com/sources/source-types/obsidian-security) - [Okta](https://docs.runreveal.com/sources/source-types/okta) - [OpenAI](https://docs.runreveal.com/sources/source-types/openai) - [Opal](https://docs.runreveal.com/sources/source-types/opal) - [OpenTelemetry (OTLP)](https://docs.runreveal.com/sources/source-types/otlp-json) - [PagerDuty](https://docs.runreveal.com/sources/source-types/pagerduty) - [Palo Alto Panorama Traffic](https://docs.runreveal.com/sources/source-types/palo-pano-traffic) - [PlanetScale](https://docs.runreveal.com/sources/source-types/planetscale) - [Reveald](https://docs.runreveal.com/sources/source-types/reveald) - [Salesforce Audit Trail](https://docs.runreveal.com/sources/source-types/salesforce/audittrail) - [SentinelOne](https://docs.runreveal.com/sources/source-types/sentinelone) - [ServiceNow](https://docs.runreveal.com/sources/source-types/servicenow) - [Snowflake](https://docs.runreveal.com/sources/source-types/snowflake) - [Sophos](https://docs.runreveal.com/sources/source-types/sophos) - [Structured Webhooks](https://docs.runreveal.com/sources/source-types/structured-webhooks) - [Tailscale Audit](https://docs.runreveal.com/sources/source-types/tailscale/audit) - [Tailscale Flow](https://docs.runreveal.com/sources/source-types/tailscale/flow) - [Teleport Cloud Audit Logs](https://docs.runreveal.com/sources/source-types/teleport) - [Twingate](https://docs.runreveal.com/sources/source-types/twingate) - [Webflow](https://docs.runreveal.com/sources/source-types/webflow-audit) - [Wiz Threats](https://docs.runreveal.com/sources/source-types/wiz-threats) - [Workday](https://docs.runreveal.com/sources/source-types/workday) - [Zendesk](https://docs.runreveal.com/sources/source-types/zendesk) ## Detections - [Detections Overview](https://docs.runreveal.com/detections): Writing and managing detection rules - [Writing Detections](https://docs.runreveal.com/detections/writing-detections): SQL-based detection authoring - [Sigma Streaming](https://docs.runreveal.com/detections/sigma-streaming): Real-time Sigma rule evaluation - [Detection as Code](https://docs.runreveal.com/detections/detection-as-code/deployment): CI/CD deployment of detections - [Export Detections](https://docs.runreveal.com/detections/detection-as-code/export-detections): Exporting detection rules ## Investigations - [Investigations](https://docs.runreveal.com/investigations): Security investigation workflows ## Notifications - [Getting Started](https://docs.runreveal.com/notifications/getting-started): Notification setup overview - [Email](https://docs.runreveal.com/notifications/email) - [Slack](https://docs.runreveal.com/notifications/slack) - [PagerDuty](https://docs.runreveal.com/notifications/pagerduty) - [Jira](https://docs.runreveal.com/notifications/jira) - [Google Chat](https://docs.runreveal.com/notifications/gchat) - [Linear](https://docs.runreveal.com/notifications/linear) - [Tines](https://docs.runreveal.com/notifications/tines) - [Incident.io](https://docs.runreveal.com/notifications/incidentio) - [Notification Templates](https://docs.runreveal.com/notifications/templates) - [History API](https://docs.runreveal.com/notifications/history-api) ## Integrations - [Grafana](https://docs.runreveal.com/integrations/grafana): ClickHouse data source for Grafana - [Jupyter Notebooks](https://docs.runreveal.com/integrations/jupyter): Query RunReveal from Jupyter ## Reference - [Logs API](https://docs.runreveal.com/reference/logs-api): Programmatic log access - [Audit Logs](https://docs.runreveal.com/reference/audit-logs): RunReveal platform audit logs - [Managing Users](https://docs.runreveal.com/reference/managing-users): User management - [Role-Based Access Control](https://docs.runreveal.com/reference/role-based-access-control): RBAC configuration - [Glossary](https://docs.runreveal.com/glossary): Terminology and definitions ## Bring Your Own Cloud - [Overview](https://docs.runreveal.com/bring-your-own-cloud): Self-hosted deployment guide - [Deployment](https://docs.runreveal.com/bring-your-own-cloud/deployment) - [Authentication](https://docs.runreveal.com/bring-your-own-cloud/authentication) - [SPIFFE/mTLS](https://docs.runreveal.com/bring-your-own-cloud/spiffe-mtls) - [Data Model](https://docs.runreveal.com/bring-your-own-cloud/data-model) - [RunReveal Query](https://docs.runreveal.com/bring-your-own-cloud/rrq) - [RunReveal Scheduler](https://docs.runreveal.com/bring-your-own-cloud/rrsch)