AQUILA - Varonis (DLP) Integration
Purpose
This document outlines the procedure to integrate Varonis DatAlert or DatAdvantage with a SIEM platform using Syslog (CEF). The integration provides visibility into sensitive data access, permissions changes, and threat alerts.
Prerequisites
-
Admin access to Varonis DatAlert Console
-
IP address and port of your SIEM/syslog collector
-
Network/firewall access from Varonis to SIEM (UDP or TCP port open)
-
(Optional) CEF parsing support in your SIEM
Step 1: Configure Varonis DatAlert for Syslog forwarding
-
Log in to the Varonis DatAlert Console.
- Navigate to:
Tools → DatAlert → Configuration → Syslog -
Click Add Syslog Server.
-
Input the following:
-
Server Name: Descriptive name (e.g., AquilaSyslog)
-
IP Address: AQUILA log collector IP
-
Port: Common options: 514 or 10514
-
Protocol: Choose UDP or TCP (enable encryption if needed)
-
Message Format: Choose CEF
-
-
Click Apply.
Step 2: Create Alert Template in Varonis DatAlert
-
Go to:
Tools → DatAlert → Templates -
Click New Template.
-
Enter:
-
Template Name: e.g., “AQUILA Syslog CEF Export”
-
Description: Template for sending alerts to AQUILA
-
-
In the Alert Outputs section:
-
Check Syslog Message
-
Choose the syslog server created in Step 1
-
-
Set the Message Format to External system default template (CEF)
-
Click OK.
Step 3: Enable Alerts to Send via Syslog
Please provide the following information to CyTech Support:
-
IP Address
-
Port Address
-
Protocol (TCP or UDP)
If you need further assistance, kindly contact our support at support@cytechint.com for prompt assistance and guidance.