> ## Documentation Index
> Fetch the complete documentation index at: https://docs.wirespeed.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Varonis DatAdvantage

> Forward DatAlert syslog events from Varonis DatAdvantage

## Set up

1. Follow the shared [Log Forwarders](/integrations/log-forwarders) guide to add **Varonis DatAdvantage** and open **Forwarder Details** (or ask Chat for the listener `ip:port`)
2. In DatAdvantage, go to **Tools** > **DatAlert** and open **Configuration**
3. Under **Syslog Message Forwarding**, set the syslog server IP and port from **Forwarder Details**. When the listener shows **UDP/TCP**, choose either TCP or UDP on the DatAlert destination. When it shows only one transport, use that one.
4. Go to **Alert Templates**, select **External system default template (CEF)**, and set **Apply to alert methods** to **Syslog message**
5. For each DatAlert rule you want Wirespeed to receive, set the alert method to **Syslog message**
6. Events will begin showing up shortly

Wirespeed parses DatAlert Common Event Format (CEF) headers and the default template fields (rule, actor, file, mailbox, and outcome). Additional CEF extensions are stored with the original message.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.