# AQUILA - Varonis (DLP) Integration

### <span style="color: rgb(53, 152, 219);">**Purpose**</span>

<span style="color: rgb(0, 0, 0);">This document outlines the procedure to integrate **Varonis DatAlert** or **DatAdvantage** with a SIEM platform using **Syslog (CEF)**. The integration provides visibility into sensitive data access, permissions changes, and threat alerts.</span>

##### <span style="color: rgb(53, 152, 219);">**Prerequisites**</span>

- <span style="color: rgb(0, 0, 0);">Admin access to **Varonis DatAlert Console**</span>
- <span style="color: rgb(0, 0, 0);">IP address and port of your **SIEM/syslog collector**</span>
- <span style="color: rgb(0, 0, 0);">Network/firewall access from Varonis to SIEM (UDP or TCP port open)</span>
- <span style="color: rgb(0, 0, 0);">(Optional) CEF parsing support in your SIEM</span>

##### <span style="color: rgb(53, 152, 219);">**Step 1: Configure Varonis DatAlert for Syslog forwarding**</span>

1. <span style="color: rgb(0, 0, 0);">Log in to your **Varonis UI** using admin credentials.</span>
2. <span style="color: rgb(0, 0, 0);">In Data Advantage, Navigate to:</span>  
    <span style="color: rgb(0, 0, 0);">**Tools** → **DatAlert** → **Select DatAlert.**</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-10/scaled-1680-/T1GpiSEOTyEGyjPL-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-10/T1GpiSEOTyEGyjPL-image.png)

<span style="color: rgb(0, 0, 0);">3. Now, select **Configuration.**  
4\. In **Syslog Message Forwarding**,  
</span>

- <span style="color: rgb(0, 0, 0);">**Syslog Message IP Address:** AQUILA log collector IP</span>
- <span style="color: rgb(0, 0, 0);">**Port: 10514** (if the port has already been used, you can set another one)</span>
- <span style="color: rgb(0, 0, 0);">**Transport protocol:** Choose **UDP** or **TCP** (if not already an option; some Varonis versions infer it)</span>
- <span style="color: rgb(0, 0, 0);">**Facility name:** Choose a different facility.</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-06/scaled-1680-/H4qC8oP7koYwCy5S-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-06/H4qC8oP7koYwCy5S-image.png)

<span style="color: rgb(0, 0, 0);">5. Click **Apply.**</span>

##### <span style="color: rgb(53, 152, 219);">**Step 2: Create Alert Template in Varonis DatAlert**</span>

1. <span style="color: rgb(0, 0, 0);">In **DatAlert**, select **Alert Templates**.</span>
2. <span style="color: rgb(0, 0, 0);">Click on the **Green Plus** sign to add a New Alert Template.</span>
    - <span style="color: rgb(0, 0, 0);">In the Template name, select the **'External system default template (CEF)'**</span>
    - <span style="color: rgb(0, 0, 0);">In the Apply to alert methods, select the **'Syslog message'**</span>
3. <span style="color: rgb(0, 0, 0);">Click **OK.**</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-06/scaled-1680-/aEWJh6P68iLccait-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-06/aEWJh6P68iLccait-image.png)

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-06/scaled-1680-/AlBqxNaiSiN27ETg-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-06/AlBqxNaiSiN27ETg-image.png)

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-06/scaled-1680-/HPmTOp9hMqvURY5A-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-06/HPmTOp9hMqvURY5A-image.png)

##### <span style="color: rgb(53, 152, 219);">**Step 3: Configuring alerts for single or multiple rules**</span>

<span style="color: rgb(0, 0, 0);">To select the Syslog alert method for a single rule:</span>

1. <span style="color: rgb(0, 0, 0);">From the DatAlert rules table, select the **rule**, then click **Edit Rule**. The rule editing menu appears.</span>
2. <span style="color: rgb(0, 0, 0);">From the left menu, select **Alerts Method**. The “**Alert Method**” window appears.</span>
3. <span style="color: rgb(0, 0, 0);">Select **Syslog message**.</span>
4. <span style="color: rgb(0, 0, 0);">Click **OK**.</span>

<span style="color: rgb(0, 0, 0);">To select the Syslog alert method for multiple rules:</span>

1. <span style="color: rgb(0, 0, 0);">From the DatAlert rules table, select the **rules**, then click **Edit Rule**. The rule editing menu appears and just "control A" to select all rules.</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-06/scaled-1680-/PftyRnOYp0u3639o-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-06/PftyRnOYp0u3639o-image.png)

1. <span style="color: rgb(0, 0, 0);">From the left menu, select **Alerts Method**. The “**Alert Method**” window appears, and its contents are disabled for selection.</span>
2. <span style="color: rgb(0, 0, 0);">Click the **edit** icon for the Syslog message option, then click the checkbox next to **Syslog message**.</span>
3. <span style="color: rgb(0, 0, 0);">Click **OK**.</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-06/scaled-1680-/qxgzGKNqhjnofPTA-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-06/qxgzGKNqhjnofPTA-image.png)

---

<p class="callout danger">**<span class="TextRun SCXW124724174 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW124724174 BCX0">Please provide the following information to </span><span class="NormalTextRun SpellingErrorV2Themed SCXW124724174 BCX0">CyTech Support</span><span class="NormalTextRun SCXW124724174 BCX0">:</span></span><span class="EOP SCXW124724174 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335551550":0,"335551620":0,"335559738":240,"335559739":240}"> </span>**</p>

<div class="ListContainerWrapper SCXW124724174 BCX0" id="bkmrk-project-id%C2%A0---the-pr">- <span style="color: rgb(0, 0, 0);">**Port Address**</span>
- <span style="color: rgb(0, 0, 0);">**Protocol (TCP or UDP)**</span>

</div><span style="color: rgb(0, 0, 0);">*If you need further assistance, kindly contact our support at **[support@cytechint.com](mailto:info@cytechint.com)** for prompt assistance and guidance.*</span>