Set up
- Follow the shared Log Forwarders guide to add Varonis DatAdvantage and open Forwarder Details (or ask Chat for the listener
ip:port) - In DatAdvantage, go to Tools > DatAlert and open Configuration
- Under Syslog Message Forwarding, set the syslog server IP and port from Forwarder Details. When the listener shows UDP/TCP, choose either TCP or UDP on the DatAlert destination. When it shows only one transport, use that one.
- Go to Alert Templates, select External system default template (CEF), and set Apply to alert methods to Syslog message
- For each DatAlert rule you want Wirespeed to receive, set the alert method to Syslog message
- Events will begin showing up shortly

