Skip to main content

Set up

  1. Follow the shared Log Forwarders guide to add Varonis DatAdvantage and open Forwarder Details (or ask Chat for the listener ip:port)
  2. In DatAdvantage, go to Tools > DatAlert and open Configuration
  3. Under Syslog Message Forwarding, set the syslog server IP and port from Forwarder Details. When the listener shows UDP/TCP, choose either TCP or UDP on the DatAlert destination. When it shows only one transport, use that one.
  4. Go to Alert Templates, select External system default template (CEF), and set Apply to alert methods to Syslog message
  5. For each DatAlert rule you want Wirespeed to receive, set the alert method to Syslog message
  6. Events will begin showing up shortly
Wirespeed parses DatAlert Common Event Format (CEF) headers and the default template fields (rule, actor, file, mailbox, and outcome). Additional CEF extensions are stored with the original message.