AQUILA - Varonis (DLP) Integration
Purpose
This document outlines the procedure to integrate Varonis DatAlert or DatAdvantage with a SIEM platform using Syslog (CEF). The integration provides visibility into sensitive data access, permissions changes, and threat alerts.
Prerequisites
-
Admin access to Varonis DatAlert Console
-
IP address and port of your SIEM/syslog collector
-
Network/firewall access from Varonis to SIEM (UDP or TCP port open)
-
(Optional) CEF parsing support in your SIEM
Step 1: Configure Varonis DatAlert for Syslog forwarding
-
Log in to
theyour VaronisDatAlertUIConsole.using admin credentials. - In Data Advantage, Navigate to:
Tools → DatAlert →ConfigurationSelect→SyslogDatAlert.
Click3. Now, select AddConfiguration.
4. In Syslog ServerMessage Forwarding.
Input the following:,
ServerSyslogName:MessageDescriptive name (e.g., AquilaSyslog)IP
AddressAddress::AQUILA log collector IPPortPort::9035Common(ifoptions:the514portorhas10514already been used, you can set another one)ProtocolTransport protocol:: Choose UDP or TCP (enable encryption if needed)Message Format:ChooseCEFUDP or TCP (if not already an option; some Varonis versions infer it)- Facility name: Choose a different facility.
5. Click ApplyApply..
Step 2: Create Alert Template in Varonis DatAlert
Go to:Tools→In DatAlert,→select Alert Templates.Click on the Green Plus sign to add a New
Template.Alert Template.Enter:Template Name: e.g., “AQUILA Syslog CEF Export”Description: Template for sending alerts to AQUILA
In the
AlertTemplateOutputsname,section:CheckSyslog MessageChoose the syslog server created inStep 1
Setselect theMessage Formatto'External system default template (CEF)'- In the Apply to alert methods, select the 'Syslog message'
- Click OK.
Step 3: Configuring alerts for single or multiple rules
To select the Syslog alert method for a single rule:
- From the DatAlert rules table, select the rule, then click Edit Rule. The rule editing menu appears.
- From the left menu, select Alerts Method. The “Alert Method” window appears.
- Select Syslog message.
- Click OK.
StepTo 3:select Enable Alerts to Send viathe Syslog alert method for multiple rules:
- From
Navigatetheto:
DatAlert→rules table, select theRulesrules, then click Edit Rule. The rule editing menu appears. - From
Selectthealeftrulemenu,(e.g.,select Alerts Method. The “MassAlertfileMethod”access”windoworappears,“SensitiveandFileitsAccess”)contents are disabled for selection. - Click
the edit icon for the Syslog message option, then click the checkbox next to Syslog message.
- Click
EditOKon the rule.. Go to theOutputssection:CheckSyslog MessageAssign your custom template (e.g., “Syslog CEF Export”)
ClickSave.Repeat for each alert rule you want to forward to AQUILA.
Please provide the following information to CyTech Support:
-
IP Address Port Address
-
Protocol (TCP or UDP)
If you need further assistance, kindly contact our support at support@cytechint.com for prompt assistance and guidance.



