---
slug: /send-data/hosted-collectors/cloud-to-cloud-integration-framework
title: Cloud-to-Cloud Integration Framework Sources
canonical: https://www.sumologic.com/help/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/
---
import useBaseUrl from '@docusaurus/useBaseUrl';
The Cloud-to-Cloud Integration Framework is a fully-managed collection system that collects logs and events directly from SaaS and Cloud platforms. This data often includes custom events and user data critical for operations monitoring, security, and compliance use cases. As a fully managed collection system, integrations running within the Cloud-to-Cloud Integration Framework provide a secure endpoint to receive event data in your account. Integration authentication, scheduling, and state tracking are all managed by the framework.
## Limitations
* Each account is limited to 50 Cloud-to-Cloud Sources.
* A warning is issued when you reach 80% of the limit (40 Sources).
* You are notified when the maximum limit is reached.
* In the [Fed deployment](/docs/api/about-apis/troubleshooting#deployments-and-sumo-logic-endpoints), supported Cloud-to-Cloud Sources are limited.
## Static IP addresses
The following table provides the static IP addresses used for Cloud-to-Cloud Integration Sources by deployment. These are provided in case you want to explicitly allow the IP addresses on your third-party target SaaS or Cloud platform.
| Deployment | Static IP addresses |
|:------------|:----------|
| AU | 13.210.38.180, 54.253.14.8, 52.63.30.49 |
| CA | 3.96.85.212, 3.97.51.58, 3.96.95.249 |
| CH | 16.62.108.141, 16.63.37.253, 16.63.8.54 |
| DE | 52.28.151.126, 18.193.176.46, 18.192.147.254 |
| ESC | 51.224.239.250, 51.225.127.189 |
| EU | 54.74.133.34, 18.200.219.230, 54.216.109.182 |
| JP | 52.69.8.121, 54.248.157.127, 18.182.95.102 |
| KR | 13.209.100.246, 3.37.181.174, 3.38.126.107 |
| US1 | 54.209.19.175, 23.22.90.93, 23.22.11.54, 34.228.131.3, 34.237.107.105, 3.88.82.220 |
| US2 | 54.149.79.97, 54.218.43.134, 44.239.32.230, 35.161.2.93 |
For the Federal environments, a different set of Static IPs is available for each C2C deployment.
| Deployment | Static IP addresses |
|:------------|:---------------------|
| Fed C2C 1A | 50.19.6.130 |
| Fed C2C 1B | 174.129.156.86 |
| Fed C2C 1C | 52.202.74.197 |
| Fed C2C 1D | 100.25.65.170 |
| Fed C2C 1E | 3.226.78.211 |
| Fed C2C 1F | 23.22.209.147 |
## Integrations
The topics below are the available integrations. In Sumo Logic these are called Sources. Check out the Sources we have available in beta.
import TerraformLink from '../../../reuse/terraform-link.md';
:::tip
You can use Terraform to provide a cloud-to-cloud source with the [`sumologic_cloud_to_cloud_source`](https://registry.terraform.io/providers/SumoLogic/sumologic/latest/docs/resources/cloud_to_cloud_source) resource.
})
Learn the basics of setting up Cloud-to-Cloud Integration Framework sources.
})
Provides a secure endpoint to receive Sign-in Attempts and Item Usage from the 1Password Event API.
})
Abnormal Security Source helps to collect abnormal threat log from the Abnormal Security platform.
Airtable Source helps to retrieve Airtable audit logs into the Sumo Logic environment.
Learn to fetch CPC-Configs, CPC-Alerts, and CPC-Alert Details from the Akamai platform.
Provides a secure endpoint to receive security events generated on the Akamai platform.
Armis Source helps to fetch device and alert logs from the Armis platform and send it to Sumo Logic.
Learn to retrieve Asana audit logs into the Sumo Logic environment.
Learn how to retrieve Atlassian audit logs into the Sumo Logic environment.
Learn how to retrieve all events objects, audit trail events, and device inventory details into the Sumo Logic environment.
Learn to collect cost and usage reports from AWS Cost Explorer Source.
})
Learn to collect the IAM User Inventory logs from the AWS SDK and send them to Sumo Logic for analysis.
Provides a secure endpoint to receive data from Azure Event Hubs.
})
Learn how to collect event logs from the Bitwarden API.
The Box API integration ingests events from the GetEvents API.
})
Provides a secure endpoint to receive data from the Carbon Black Cloud, Enriched Event Search, and Alerts APIs.
})
Provides a secure endpoint to receive data from the CB Devices API.
})
Cato Networks Source helps to retrieve Cato audit and security logs into the Sumo Logic environment.
})
Securely collect and analyze ChatGPT Compliance platform conversation logs.
})
Provides a secure endpoint to receive data from the Cisco Amp System Log API.
})
Provides a secure endpoint to receive data from the Cisco Meraki API.
})
Provides a secure endpoint to receive assets data from Asset API and vulnerabilities data from Vulnerability API.
Provides a secure endpoint to receive System Log data from the Citrix Cloud System Log API.
Provides a secure endpoint to receive event data from the EC2 describe instances API.
Sources in the Cloud-to-Cloud Integration Framework need updates over time to maintain data collection.
})
Learn how to collect alerts, file events, and audit logs from Code42 Incydr.
})
Learn how to collect metrics from the Confluent Metrics platform and send them to Sumo Logic.
})
Provides a secure endpoint to receive event data from the CrowdStrike Streams API.
})
Provides a secure endpoint to ingest Falcon Data Replicator events using the S3 ingestion.
})
Provides a secure endpoint to receive device data from the CrowdStrike Host and Host Group Management APIs.
})
Learn how to collect file integrity monitoring logs from the CrowdStrike FileVantage platform.
})
Learn how to collect combined endpoint vulnerabilities data from the CrowdStrike Spotlight platform.
})
Learn how to collect combined endpoint indicators data from the CrowdStrike Threat Intel platform.
})
Before configuring an AWS Source give Sumo Logic access to your AWS product
})
Learn to collect audits using the CyberArk SIEM integrations API.
})
Provides a secure endpoint to receive authentication logs from the Cybereason Malops API.
Track user and system activities to support governance and compliance using Databricks Audit logs.
Learn how to collect export data from the Digital Guardian ARC and send it to Sumo Logic.
Learn how to collect customer event data from the DocuSign and send it to Sumo Logic.
})
Learn how to collect address, asset, vulnerability, notification, and zone details from the Dragos API and send them to Sumo Logic.
Provides a secure endpoint to receive team events from the Get Events API.
Learn how to configure the Druva C2C source setup in your Sumo Logic environment.
Learn how to configure the Druva Cyber Resilience C2C source setup in your Sumo Logic environment.
Provides a secure endpoint to receive authentication logs from the Duo Authentication Logs API.
Pulls Gmail log data using BigQuery Library APIs.
})
Learn to collect the organization metrics and team metrics from GitHub Copilot platform.
Learn how to collect data using the BigQuery API.
})
Learn how to collect data using the Google Threat Intel API.
Configure Google Workspace AlertCenter Cloud-to-Cloud connector.
Collects a list of users from the Google Workspace Users API.
})
Learn to collect threat indicators from the Intel 471 platform.
})
Collect inventory data from the Jamf platform.
})
Collect violation events from JFrog Xray.
})
Collect events data from the JumpCloud Directory Insight.
})
Learn how to collect Audit Trail and Base Entry events from Kaltura platform.
})
Learn how to collect threat details, devices list, device activities, and device details from the Kandji platform.
})
Collects user events data into Sumo Logic for storage, analysis, and alerting.
})
Collects audit reporting events from the LastPass platform.
Collects user and device data from the Microsoft Graph API Security endpoint.
})
Learn to collect threat indicators from the Mandiant platform.
Collects email trace logs from the Office 365 reporting web service.
Collects Directory Audit, Sign-in, and Provisioning data from MS Graph API Azure AD activity reports.
Collects Risk Detection and Risky User data from the Microsoft Graph Identity Protection API.
Provides a secure endpoint to receive alerts from the Microsoft Graph Security API endpoint.
Supports collecting SIEM, DLP, Audit, and Hold Message List data from the Mimecast API.
})
Ingests audit logs obtained from the Audit log API.
})
Provides a secure endpoint to receive event data from the Netskope API.
})
The Netskope WebTx API integration ingests Web Transaction logs from Netskope Event Stream.
})
Provides a secure endpoint to receive event data from the Okta System Log API and Users API.
})
Provides a secure and centralized access to user lists from the OneLogin API.
})
Allows you to ingest incidents from your Cortex XDR application.
})
Collects data and uses the secure WebSocket protocol to stream logs.
})
Provides a secure endpoint to receive data from the Proofpoint TAP SIEM API.
})
Learn to ingest message logs via the API to deliver enhanced email threat visibility and actionable insights for faster detection and response to attacks.
The Qualys VMDR Source tracks errors, reports its health, and start-up progress.
})
Collects asset and vulnerabilities data from Rapid7 InsightVM.
Provides a secure endpoint to receive Events and User Inventory data from the IdentityNow V3 API.
Provides a secure endpoint to receive event data from the Salesforce through its Rest API.
Collects data from the SentinelOne Management Console.
})
Learn about the Slack Source, part of Sumo Logic's Cloud-to-Cloud Integration Framework.
})
Learn how to collect events from Smartsheet platform.
})
Learn how to collect logs from Snowflake platform.
})
Learn to receive authentication logs from the Sophos Central APIs.
})
Learn how to set up a STIX/TAXII 1.x client to collect threat intelligence indicators into the Sumo Logic environment.
})
Learn how to set up a STIX/TAXII 2.x client to collect threat intelligence indicators into the Sumo Logic environment.
})
Learn how to collect the list of collectors and their sources using the Sumo Logic Collector API and Sources API.
})
Learn how to collect audit reporting events using Sumo Logic sample data.
Learn to collect incidents and incident events from the Symantec Endpoint Security platform.
Learn to receive WSS Access logs from the Symantec WSS API.
})
Collect the scan results from the scanner using the Sysdig API.
})
Learn to ingest audit-log events, vulnerability, and asset data from the Tenable.io APIs.
})
Learn how to collect event logs using the Trellix.
})
Learn how to collect alert details from Trend Micro platform.
Learn how to collect report logs from Trust Login platform.
})
Learn how to set up a Universal Connector to collect data into the Sumo Logic environment.
})
Learn to collect alerts from the Varonis platform and send them to Sumo Logic.
})
Learn to collect the list of threats detected in the Vectra platform.
})
Learn how to collect the device details and corresponding list of applications for the devices from the VMware Workspace One platform.
})
Learn to collect admin audit events using Webex API.
})
Learn to create a Workday Source.
Learn to collect audit logs from the Zendesk platform.
})
Learn to collect threat indicators using the ZeroFox API and send them to Sumo Logic for analysis.
Learn to collect audit logs and network activity data from Zero Networks Segment.
Learn to collect the device logs from the Zimperium API and send it to Sumo Logic.