Overview
The Cato service generates rich and granular events, providing comprehensive visibility across network and security features. You can directly consume these events in the following ways:
Directly in the Cato Management Application (see Analyzing Events in Your Network)
A high-scale feed to Cloud Storage, such as AWS S3 and Azure Blob Storage
Using the Cato API
Event Integrations let you automatically forward Cato event data to external platforms and storage destinations for retention, monitoring, and analysis. This helps you use Cato events in your existing SOC, SIEM, and data lake workflows without manually exporting data or continuously polling for it.
Depending on the integration type, Cato either continuously uploads events to cloud storage, forwards data directly to a supported third-party platform through a native connector, or streams events and flows to a compatible HTTP endpoint using the Custom HTTP Push integration. Use the Custom HTTP Push integration when the destination platform has no dedicated Cato integration and can accept the standard Cato JSON or NDJSON payload.
Filtering Events
The available filtering options depend on the integration type:
Cloud storage integrations, such as Amazon S3 and Azure Storage, support filtering by event type or sub-type.
Native CMA integrations for SIEMs, such as CrowdStrike, Microsoft Sentinel, and Splunk, support filter groups. These groups let you filter events using fields such as action, severity, rule name, application, site, or user.
Prerequisites
If access to the third-party service is limited to specific IP addresses, see this article for the Cato IP addresses that you need to allow (you must be signed in to view this article).
You can define up to three Event Integrations for your account.
Turnkey Integrations
Forward events directly to the following SIEM solutions and storage accounts using native connectors configured in the CMA.
For information about license requirements for third-party integrations, see License and Apps for Cato Third-Party Integrations.
Vendor | Cato Knowledge Base Documentation |
|---|---|
| |
| |
| |
| |
|
Custom HTTP Push Integration
For organizations that send data to systems for which there isn’t a dedicated Cato integration, we provide the Custom HTTP Push Integration.
Use the Custom HTTP Push integration to stream events, and optionally flows, directly to any external platform that accepts JSON or newline-delimited JSON (NDJSON) over HTTP. Data is pushed continuously as it's generated, rather than retrieved on a scheduled basis. This allows downstream systems to receive near real-time updates without polling.
Third-party Integrations
To learn about the many other services which integrate with Cato, see catonetworks.com/integrations/



.png?sv=2026-02-06&spr=https&st=2026-09-02T12%3A50%3A52Z&se=2026-09-02T13%3A02%3A52Z&sr=c&sp=r&sig=mXmS6UAdvhF%2FVNt1CK2F8ySASIBtQgvmTE5GqnAyxlU%3D)
.png?sv=2026-02-06&spr=https&st=2026-09-02T12%3A50%3A52Z&se=2026-09-02T13%3A02%3A52Z&sr=c&sp=r&sig=mXmS6UAdvhF%2FVNt1CK2F8ySASIBtQgvmTE5GqnAyxlU%3D)