AQUILA - Varonis (DLP) Integration
Purpose
This document outlines the procedure to integrate Varonis DatAlert or DatAdvantage with a SIEM platform using Syslog (CEF). The integration provides visibility into sensitive data access, permissions changes, and threat alerts.
Prerequisites
-
Admin access to Varonis DatAlert Console
-
IP address and port of your SIEM/syslog collector
-
Network/firewall access from Varonis to SIEM (UDP or TCP port open)
-
(Optional) CEF parsing support in your SIEM
Step 1: Configure Varonis DatAlert for Syslog Server in Varonisforwarding
-
Log in to the Varonis DatAlert Console.
- Navigate to:
Tools → DatAlert → Configuration → Syslog -
Click Add Syslog Server.
-
Input the following:
-
Server Name: Descriptive name (e.g.,
CinchSyslog)AquilaSyslog) -
IP Address:
YourSIEMAQUILAor Cinchlog collector IP -
Port: Common options:
514,9035,or1051411656 -
Protocol: Choose
UDPorTCP(enable encryption if needed) -
Message Format: Choose CEF
-
-
Click
SaveApply.
Step 2: Set Up anCreate Alert Template in Varonis DatAlert
-
Go to:
Tools → DatAlert → Templates -
Click New Template
or edit an existing one.. -
Enter:
-
Template Name: e.g., “AQUILA Syslog CEF
Export”Export” -
Description: Template for sending alerts to
SIEMAQUILA
-
-
In the Alert Outputs section:
-
Check Syslog Message
-
Choose the syslog server created in Step 1
-
-
Set the Message Format to External system default template (CEF)
-
Click
Save TemplateOK.
Step 3: Enable Alerts to Send via Syslog
Step 4: Configure Your SIEM to Ingest LogsAQUILA.
Create anew log sourceorsyslog input:Source Type: Syslog (TCP/UDP)Port: Match what you configured in VaronisLog Format: CEF (or Custom parser for Varonis CEF)
Create aparserto extract CEF fields:Example fields:suser,src,filePath,act,deviceSeverityMany SIEMs (like Splunk, Elastic, QRadar) include CEF parsers
Step 5: Test and Validate
Simulate an alert in Varonis (e.g., access a sensitive file or trigger a test alert).Check your SIEM/Cinch logs for messages like:CEF:0|Varonis|DatAlert|1.0|100|Sensitive File Access|10|src=10.0.1.15 suser=john.doe filePath=\\server\hr\payroll.xls act=accessConfirm:Syslog message is receivedParsed fields are correctAlerts or dashboards are populating as expected
(Optional) Step 6: API Integration for Enrichment
Varonis also offers a REST API for:
User activity reportsFile system access logsSensitive data classification results
For enrichment:
Obtain API credentials from Varonis admin portalPoll /api/alerts, /api/files, or /api/permissionsIngest results into your SIEM/Cinch as contextual data
Please provide the following information to CyTech Support:
-
IP Address
-
Port Address
-
Protocol (TCP or UDP)
If you need further assistance, kindly contact our support at support@cytechint.com for prompt assistance and guidance.