# CATO Networks API Integration

#### **<span style="color: rgb(53, 152, 219);">1. Overview</span>**

<span style="color: rgb(0, 0, 0);">**Cato Networks** is a cloud-native Secure Access Service Edge (SASE) platform that converges networking and security into a single, unified service. It provides SD-WAN, secure internet access, zero-trust network access, and advanced threat protection over a global private backbone, simplifying operations and enhancing security and performance for organizations.</span>

#### <span style="color: rgb(53, 152, 219);">**2. Vendor configuration**</span>

In this configuration, you will set up the Cato Networks API Key and Account ID parameter to access the Cato networks API.

- In the Cato Management Application, only account administrators with the **Editor** privilege can generate keys. (CMA).
- To ingest security events, you must enable the events feeds on your account. To enable the events feed, follow the steps below: 
    1. In the navigation panel, select **System &gt; API Access Management**.
    2. <span style="color: rgb(0, 0, 0);">Select **Event Feed Enabled**. After this, your account starts sending events to the Cato API server.</span>  
        <span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-07/scaled-1680-/CCRdEQ05uuymb9fl-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-07/CCRdEQ05uuymb9fl-image.png)</span>

#### <span style="color: rgb(0, 0, 0);">**3. API Key**</span>

<span style="color: rgb(0, 0, 0);">All access to Cato networks requires an API Key. Follow the below instructions to set up an API Key.</span>

1. <span style="color: rgb(0, 0, 0);">In the navigation menu, click **Administration &gt; API Management**.</span>

<span style="color: rgb(0, 0, 0);">[ ![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-07/scaled-1680-/c4u0oIDSbEqZXVpB-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-07/c4u0oIDSbEqZXVpB-image.png)</span>

<span style="color: rgb(0, 0, 0);"> 2. On the **API Keys** tab, click **New**. The **Create API Key** panel opens.</span>

<span style="color: rgb(0, 0, 0);"> 3. Enter a **Key Name**.</span>

<span style="color: rgb(0, 0, 0);">[ ![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-07/scaled-1680-/ireVyydZcNnD5pp3-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-07/ireVyydZcNnD5pp3-image.png)</span>

<span style="color: rgb(0, 0, 0);">4. Select **View** in the **API Permission**.</span>

<span style="color: rgb(0, 0, 0);">5. Select **Any IP** to allow this API key for any IP address under the **Allow Access from IPs** section.</span>

<span style="color: rgb(0, 0, 0);">6. (Optional) Select a date when the API key expires. If you select an expiration date, then you need to update the source configuration with a new API key, or else an unauthorized error will be received.</span>

<span style="color: rgb(0, 0, 0);">7. Click **Apply**. The API key is added, and a pop-up window containing the new API key is displayed.</span>

<span style="color: rgb(0, 0, 0);">8. Copy the API Key generated by the Cato Management Application and save it in a secure location.</span>

<p class="callout info"><span style="color: rgb(0, 0, 0);">Note: </span>  
<span style="color: rgb(0, 0, 0);">The API key value will not be available after closing this window. Kindly ensure that you copy and securely save the API key before closing the window.</span></p>

<span style="color: rgb(0, 0, 0);">9. Click **OK** to close the pop-up window.</span>

<span style="color: rgb(0, 0, 0);">Reference link: [https://support.catonetworks.com/hc/en-us/articles/4413280536081-Generating-API-Keys-for-the-Cato-API](https://support.catonetworks.com/hc/en-us/articles/4413280536081-Generating-API-Keys-for-the-Cato-API)</span>

#### <span style="color: rgb(0, 0, 0);">**4. Build a Collector to Pull Events**</span>

<span style="color: rgb(0, 0, 0);">Elastic doesn’t natively support Cato, but you can use: **Logstash**</span>

<span style="color: rgb(0, 0, 0);">You need to create a **Logstash pipeline**. ***Install Logstash if not already.***</span>

##### <span style="color: rgb(53, 152, 219);">**Step 1:** ***Install Logstash On Linux (Ubuntu/Debian example)***</span>

```
wget -qO - https://artifacts.elastic.co/GPG-KEY-elasticsearch | sudo apt-key add -
sudo apt-get install apt-transport-https
echo "deb https://artifacts.elastic.co/packages/8.x/apt stable main" | sudo tee /etc/apt/sources.list.d/elastic-8.x.list
sudo apt-get update
sudo apt-get install logstash

```

<span style="color: rgb(0, 0, 0);">**Verify installation:**</span>

```
logstash --version
```

##### <span style="color: rgb(53, 152, 219);">**Step 2: Create Logstash Pipeline**</span>

**<span style="color: rgb(0, 0, 0);">2.1: Location</span>**

Create file: /etc/logstash/conf.d/cato-pipeline.conf

<span style="color: rgb(0, 0, 0);"> **Pipeline Configuration:**</span>

```
input {
  http_poller {
    urls => {
      cato => {
        method => post
        url => "https://api.catonetworks.com/v1/graphql"
        headers => {
          "x-api-key" => "YOUR_CATO_API_KEY"
          "Content-Type" => "application/json"
        }
        body => '{
          "query": "query { eventsFeed { eventType eventTime eventDetails } }"
        }'
      }
    }
    request_timeout => 60
    schedule => { cron => "* * * * *" }
    codec => "json"
    metadata_target => "http_poller_metadata"
  }
}

filter {
  if [data] {
    mutate {
      replace => { "[events]" => "%{[data][eventsFeed]}" }
    }
    split {
      field => "[events]"
    }

    mutate {
      add_field => {
        "event_type" => "%{[events][eventType]}"
        "event_time" => "%{[events][eventTime]}"
      }
    }

    json {
      source => "[events][eventDetails]"
      target => "event_details"
    }

    date {
      match => [ "event_time", "ISO8601" ]
      target => "@timestamp"
    }

    mutate {
      remove_field => [ "data", "events", "[events][eventDetails]", "http_poller_metadata" ]
    }
  }
}

output {
  elasticsearch {
    hosts => [ "http://localhost:9200" ]
    index => "cato-events-%{+YYYY.MM.dd}"
    user => "elastic"
    password => "your_elastic_password"
  }

  stdout {
    codec => rubydebug
  }
}
```

<span style="color: rgb(0, 0, 0);">**Replace:**</span>

- <span style="color: rgb(0, 0, 0);">`YOUR_CATO_API_KEY` with your Cato API</span><span style="color: rgb(0, 0, 0);"> key</span>
- <span style="color: rgb(0, 0, 0);">Elastic credentials (user, password, host)</span>

##### <span style="color: rgb(53, 152, 219);">**Step 3: Test the Pipeline**</span>

<span style="color: rgb(0, 0, 0);">**Run syntax test:**</span>

```
sudo /usr/share/logstash/bin/logstash --path.settings /etc/logstash -t
```

<span style="color: rgb(0, 0, 0);">✅ You should see: Configuration OK</span>

##### <span style="color: rgb(53, 152, 219);">**Step 4: Start Logstash**</span>

```
sudo systemctl start logstash
sudo systemctl enable logstash
```

<span style="color: rgb(0, 0, 0);">**Check logs:**</span>

```
sudo journalctl -u logstash -f
```

##### <span style="color: rgb(53, 152, 219);">**Step 5: Verify Data in Kibana**</span>

- <span style="color: rgb(53, 152, 219);"> **<span style="color: rgb(0, 0, 0);">Open Kibana: http://&lt;your-server&gt;:5601</span>** </span>
- <span style="color: rgb(0, 0, 0);"> **Log in** </span>
- <span style="color: rgb(0, 0, 0);"> **Go to: Stack Management → Data Views → Create data view** </span>
- <span style="color: rgb(0, 0, 0);"> **Name**</span><span style="color: rgb(0, 0, 0);">**:** </span>
- ```
    cato-events-*
    ```
- <span style="color: rgb(0, 0, 0);">**Save**</span><span style="color: rgb(0, 0, 0);"> </span>

<span style="color: rgb(0, 0, 0);">Then go to **Discover**, select the new data view, and explore your Cato event logs!</span>