The Cato service generates rich and granular events, providing comprehensive visibility across network and security features. You can directly consume these events in the following ways:
- Directly in the Cato Management Application (see Analyzing Events in Your Network)
- A high-scale feed to Cloud Storage, such as AWS S3 and Azure Blob Storage
- Using the Cato API
For more information about license requirements for third-party integrations, see License and Apps for Cato Third-Party Integrations.
Forward events directly to the following SIEM solutions using a native connector in the CMA.
| Vendor | Cato Knowledge Base Documentation |
|---|---|
|
|
Integrating Cato Events with CrowdStrike |
|
|
Integrating Cato Events with Microsoft Sentinel |
|
|
Integrating Cato Events with Splunk |
These vendors officially support integrations with Cato data.
In addition to the native turnkey integration described in this article, you can also integrate Cato events with these SIEM vendors using the tools in the Cato GitHub repositories. Cato also offers native turnkey solutions for these vendors.
The reference implementation for these solutions is provided as-is and is not supported by the Cato Support team.
| Vendor | Cato Github Reference |
|---|---|
|
|
cato-sentinel-connect |
|
|
cato-splunk-integration |
52 comments
Added Secureworks Taegis XDR as a third-party SIEM vendor
Praveen Singh (Admin) , Yoann Moizan , Golan Shai Cato events are available in JSON format via API or direct integration with cloud storage. Syslog is not supported.
For details on Cato events integration, please refer to the following articles:
Any update for Microsoft Sentinel integration?
A direct Sentinel Integration would be great.
It's a pity there's no Qradar integration. It's probably going to stop us considring Cato for a full replacement firewall solution in the medium term.
Hello all,
I've been looking at sending security logs into Crowdstrike Logscale/NG-SIEM. Wondering if there was a direct integration on the roadmap/progress? Saw some comments from a few months back.
Thanks!
As some other previously commented, I would love to see a connector for the CrowdStrike NG-SIEM and to hear of any ETA on if/when it might come. We have to decide if it is worth sending out syslogs or pulling data from API or if we should just wait for a new connector. Thanks!
Seconding the request for an ETA on the Crowdstrike NG-SIEM Connector
Hello, do you have any roadmap or ETA on Splunk integration? If not, how can we integrate via APIs?
I would also like to see native support for Crowdstrike NG-SIEM.
Is it preferred to send directly to Azure Blob Storage or is the eventsFeed.py script with the streaming option sufficient to send to a SIEM?
eventsFeed.py seems pretty straightforward but have some concerns after watching the AMA video on the Cato API of it not being able to keeping up with events generated and events retrieved.
An earlier response Peter Lee you mentioned that you are working on an Azure Function to help process these logs. This was related to Azure Sentinel but assume it could be reworked to send to an on-prem SIEM. I've seen this approach for other SIEMs such as SumoLogic. Is there any update on the Azure Function (assuming it's an ARM template) to help with this?
We would also like to see native support for Crowdstrike NG-SIEM.
Crowdstrike themselves recently told me that a dedicated connector is in the works but no hard release date has been set yet.
Do you have any updates on this and is there anything we can do to speed up the process?
Christopher Sinclair We set up ingest via the AWS S3 connector relatively easy, the cato log parser is available to choose from already there just isnt a dedicated connector yet.
We'd like ingest logs and metrics into Grafana, has anyone tried?
We would also like to see official support/integration for Microsoft Sentinel. I know this was mentioned approximately a year ago that it was being worked on, is there any update to this?
For those looking for Azure Sentinel connectors, look here: catonetworks/cato-sentinel-connect
Hi
Can you please share documentation regarding configuration of syslog forwarding feature?
do you have a Manage Engine Event Log Analyzer Tool syslog integration or any syslog tool ?
Regards,
Added Microsoft Sentinel and Splunk as open-source data integrations
Is SentinelOne Data Lake on the roadmap?
Sean Daniels Yes, SentinelOne is working on an integration for Data Lake with Cato
CrowdStrike NG-SIEM please. I'll be pinging CrowdStrike also.
Added turnkey integration support for Microsoft Sentinel and Splunk
Nice to see Wazuh and Elastic integration and also with their opensource counterparts.
Any ETA for this?
Please sign in to leave a comment.