Cato Data: Third-Party Supported Integrations

The Cato service generates rich and granular events, providing comprehensive visibility across network and security features. You can directly consume these events in the following ways:

For more information about license requirements for third-party integrations, see License and Apps for Cato Third-Party Integrations.

Turnkey SIEM Integrations

Forward events directly to the following SIEM solutions using a native connector in the CMA.

Vendor Cato Knowledge Base Documentation
crowdstrike_logo.png Crowdstrike Integrating Cato Events with CrowdStrike
sentinel_logo.png Microsoft Sentinel Integrating Cato Events with Microsoft Sentinel
Splunk_logo.png Splunk Integrating Cato Events with Splunk

Open-Source Data Integrations

In addition to the native turnkey integration described in this article, you can also integrate Cato events with these SIEM vendors using the tools in the Cato GitHub repositories. Cato also offers native turnkey solutions for these vendors.

The reference implementation for these solutions is provided as-is and is not supported by the Cato Support team.

Vendor Cato Github Reference
sentinel_logo.png Microsoft Sentinel cato-sentinel-connect
Splunk_logo.png Splunk cato-splunk-integration

Was this article helpful?

4 out of 7 found this helpful

52 comments

  • Comment author
    Yaakov Simon

    Added Secureworks Taegis XDR as a third-party SIEM vendor

  • Comment author
    Yaakov Simon

    Praveen Singh (Admin) , Yoann Moizan , Golan Shai  Cato events are available in JSON format via API or direct integration with cloud storage. Syslog is not supported.

    For details on Cato events integration, please refer to the following articles:

  • Comment author
    Vongsovann Heng
    • Edited

    Any update for Microsoft Sentinel integration?

  • Comment author
    David Gorman

    A direct Sentinel Integration would be great.

     

    It's a pity there's no Qradar integration. It's probably going to stop us considring Cato for a full replacement firewall solution in the medium term. 

  • Comment author
    Brian bcrossen

    Hello all,

    I've been looking at sending security logs into Crowdstrike Logscale/NG-SIEM.  Wondering if there was a direct integration on the roadmap/progress?  Saw some comments from a few months back. 

    Thanks!

  • Comment author
    tom.treat

    As some other previously commented, I would love to see a connector for the CrowdStrike NG-SIEM and to hear of any ETA on if/when it might come. We have to decide if it is worth sending out syslogs or pulling data from API or if we should just wait for a new connector. Thanks! 

  • Comment author
    wwebsterSA

    Seconding the request for an ETA on the Crowdstrike NG-SIEM Connector

  • Comment author
    Pessoa Gonçalo

    Hello, do you have any roadmap or ETA on Splunk integration? If not, how can we integrate via APIs?

  • Comment author
    Jeremy Rea

    I would also like to see native support for Crowdstrike NG-SIEM.

  • Comment author
    Derek Wolcott

    Is it preferred to send directly to Azure Blob Storage or is the eventsFeed.py script with the streaming option sufficient to send to a SIEM? 

    eventsFeed.py seems pretty straightforward but have some concerns after watching the AMA video on the Cato API of it not being able to keeping up with events generated and events retrieved. 

    An earlier response Peter Lee  you mentioned that you are working on an Azure Function to help process these logs. This was related to Azure Sentinel but assume it could be reworked to send to an on-prem SIEM. I've seen this approach for other SIEMs such as SumoLogic. Is there any update on the Azure Function (assuming it's an ARM template) to help with this?

  • Comment author
    Christopher Sinclair
    • Edited

    We would also like to see native support for Crowdstrike NG-SIEM.

    Crowdstrike themselves recently told me that a dedicated connector is in the works but no hard release date has been set yet. 

    Do you have any updates on this and is there anything we can do to speed up the process?

  • Comment author
    wwebsterSA

    Christopher Sinclair We set up ingest via the AWS S3 connector relatively easy, the cato log parser is available to choose from already there just isnt a dedicated connector yet.

  • Comment author
    craig.mccaddon

    We'd like ingest logs and metrics into Grafana, has anyone tried?

  • Comment author
    Brian Ciarimboli
    • Edited

    We would also like to see official support/integration for Microsoft Sentinel.  I know this was mentioned approximately a year ago that it was being worked on, is there any update to this?

  • Comment author
    Jeremy Nielson

    For those looking for Azure Sentinel connectors, look here:  catonetworks/cato-sentinel-connect

  • Comment author
    adm_ozanoz

    Hi

    Can you please share documentation regarding configuration of syslog forwarding feature?

    do you have a Manage Engine Event Log Analyzer Tool syslog integration or any syslog tool ?

    Regards,

  • Comment author
    Yaakov Simon

    Added Microsoft Sentinel and Splunk as open-source data integrations

  • Comment author
    Sean Daniels

    Is SentinelOne Data Lake on the roadmap?

  • Comment author
    Yaakov Simon

    Sean Daniels  Yes, SentinelOne is working on an integration for Data Lake with Cato

  • Comment author
    Tom Drought

    CrowdStrike NG-SIEM please. I'll be pinging CrowdStrike also.

  • Comment author
    Yaakov Simon

    Added turnkey integration support for Microsoft Sentinel and Splunk

  • Comment author
    Daniel Balogh

    Nice to see Wazuh and Elastic integration and also with their opensource counterparts.

    Any ETA for this?