Direct query
A published query names this technology's own tables or API — Azure KQL reads IdentityInfo, AWS Athena reads iam_credential_report. Nothing to export or forward. This applies to Microsoft Azure, Amazon Web Services, Splunk Enterprise Security, Microsoft Entra ID, Active Directory, AWS IAM, Azure Backup, AWS Backup, and the Azure and AWS configuration sources.
Via Splunk
The published Splunk searches read vendor-neutral sourcetypes, not any vendor's own tables: directory:users, privileged:assignments, credential:inventory, backup:jobs, config:snapshot, and network:rules.
Forward a product into Splunk with the right sourcetype and fields and the existing query covers it, with no new query written. Emit one event per backup job to index=ops sourcetype=backup:jobs carrying resource_id and status, and the published CP-9 search covers Veeam, Rubrik, Commvault, Google Cloud Backup and DR, or a tool written in-house. The same holds for Okta and Google Cloud IAM on the identity controls.
Azure and AWS read vendor-specific tables, so they cannot absorb a third-party product this way and stay strict about the source you select.
Via CSV export
Export into one of the five open CSV contracts the published queries join to. For a CMDB or a ticketing system this is not a workaround — supplying evidence the cloud cannot produce is exactly what those systems are for in this method. A CMDB feeds asset_inventory.csv; a ticketing system or Git history feeds change_approvals.csv.