⚠️ Cato Networks Events (Push)

⚠️ Unpublished: This item is from a solution that is not yet published on Azure Marketplace or not installed in Content Hub.

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Connectors Index


Attribute Value
Connector ID CatoNetworksEventsPush
Publisher Cato Networks
Used in Solutions CatoNetworks
Collection Method CCF Push
Connector Definition Files CatoNetworks_ConnectorDefinition.json
DCR Definition Files CatoNetworks_DCR.json
CCF Configuration CatoNetworks_dataConnector.json
CCF Capabilities Push
Ingestion API Log Ingestion API — CCF Push connectors use DCR-based Log Ingestion API

The Cato Networks connector pushes security and networking telemetry from the Cato Management Application into Microsoft Sentinel in near real time, using the Codeless Connector Framework (CCF) Push pattern. Data lands in a custom Log Analytics table, ready for hunting, analytics, and visualization. See the Cato Event Schema for the fields carried on each record.

Tables Ingested

This connector ingests data into the following tables:

Table Transformations Ingestion API Lake-Only
CatoNetworksEvents_CL ? ✓ ?

💡 Tip: Tables with Ingestion API support allow data ingestion via the Azure Monitor Data Collector API, which also enables custom transformations during ingestion.

Permissions

Resource Provider Permissions:

Custom Permissions:

Setup Instructions

⚠️ Note: These instructions were automatically generated from the connector's user interface definition file using AI and may not be fully accurate. Please verify all configuration steps in the Microsoft Sentinel portal.

1. Create ARM Resources and Provide the Required Permissions

This connector enables the Cato Cloud to push events directly to Microsoft Sentinel via the Azure Monitor Logs Ingestion API.

Automated Configuration and Secure Data Ingestion with Entra Application

Clicking on "Deploy" will trigger the creation of a Log Analytics table and a Data Collection Rule (DCR). It will then create an Entra application, link the DCR to it, and set the entered secret in the application. This setup enables data to be sent securely to the DCR using an Entra token.

One connector per workspace

The Data Collection Rule and the CatoNetworksEvents_CL table are named from this workspace, so deploying the connector again in the same Log Analytics workspace reuses them rather than creating a second set. A workspace holds one Cato connector.

Events from more than one Cato account can be sent to the same connector; they share the table and are distinguished by account_id and account_name. To keep feeds in separate tables, with their own retention or access control, use a separate Log Analytics workspace for each. Deploy Cato Networks connector resources

2. Configure the connector in the Cato Management Application

In the Cato Management Application, go to Resources > Integrations > Configured Integrations, click New, select Microsoft Sentinel, and enter the values below. For full setup instructions, see Integrating Cato Events with Microsoft Sentinel.

3. Keeping the schema up to date

Cato periodically adds fields to its event schema. Because upgrading this solution leaves your connector's existing custom table and Data Collection Rule unchanged, new fields must be applied separately using the dedicated schema update template.

Apply the current schema

Deploy the schema update

Select the subscription and the resource group holding this workspace, then enter the workspace name. That is the only value you supply.

Your ingestion URL, Entra application and client secret are unchanged, and nothing has to be re-entered in the Cato Management Application. Ingestion continues throughout.

Allow up to 30 minutes for new fields to start arriving. Events are still accepted during that window and the new fields are simply empty, so confirm with a query rather than assuming a failure.


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Connectors Index