Documentation Index

Fetch the complete documentation index at: https://knowledge.catonetworks.com/llms.txt

Use this file to discover all available pages before exploring further.

Getting Started with Event Integrations

Prev Next

Overview

The Cato service generates rich and granular events, providing comprehensive visibility across network and security features. You can directly consume these events in the following ways:

Event Integrations let you automatically forward Cato event data to external platforms and storage destinations for retention, monitoring, and analysis. This helps you use Cato events in your existing SOC, SIEM, and data lake workflows without manually exporting data or continuously polling for it.

Depending on the integration type, Cato either continuously uploads events to cloud storage, forwards data directly to a supported third-party platform through a native connector, or streams events and flows to a compatible HTTP endpoint using the Custom HTTP Push integration. Use the Custom HTTP Push integration when the destination platform has no dedicated Cato integration and can accept the standard Cato JSON or NDJSON payload.

Filtering Events

The available filtering options depend on the integration type:

  • Cloud storage integrations, such as Amazon S3 and Azure Storage, support filtering by event type or sub-type.

  • Native CMA integrations for SIEMs, such as CrowdStrike, Microsoft Sentinel, and Splunk, support filter groups. These groups let you filter events using fields such as action, severity, rule name, application, site, or user. 

Prerequisites

  • If access to the third-party service is limited to specific IP addresses, see this article for the Cato IP addresses that you need to allow (you must be signed in to view this article).

  • You can define up to three Event Integrations for your account.

Turnkey Integrations

Forward events directly to the following SIEM solutions and storage accounts using native connectors configured in the CMA.

For information about license requirements for third-party integrations, see License and Apps for Cato Third-Party Integrations.

Custom HTTP Push Integration

For organizations that send data to systems for which there isn’t a dedicated Cato integration, we provide the Custom HTTP Push Integration.

Use the Custom HTTP Push integration to stream events, and optionally flows, directly to any external platform that accepts JSON or newline-delimited JSON (NDJSON) over HTTP. Data is pushed continuously as it's generated, rather than retrieved on a scheduled basis. This allows downstream systems to receive near real-time updates without polling.

Third-party Integrations

To learn about the many other services which integrate with Cato, see catonetworks.com/integrations/