Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Connector ID | CayosoftGuardianConnector |
| Publisher | Cayosoft |
| Used in Solutions | Cayosoft Guardian |
| Collection Method | AMA |
| Connector Definition Files | CayosoftGuardian_connectorDefinition.json |
The Cayosoft Guardian data connector automatically ingests threat alerts from Cayosoft Guardian into Microsoft Sentinel. Cayosoft Guardian writes threat alerts to the Windows Event Log as Event ID 2. The Azure Monitor Agent (AMA) collects these events by using Data Collection Rules (DCRs) and sends the parsed data to the custom Log Analytics table named CayosoftThreatAlerts_CL. After the data is ingested, Microsoft Sentinel can use it for monitoring, analytics, incident creation, investigation, and automated response across your hybrid identity environment.
This connector ingests data into the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
CayosoftThreatAlerts_CL |
? | ✓ | ? |
💡 Tip: Tables with Ingestion API support allow data ingestion via the Azure Monitor Data Collector API, which also enables custom transformations during ingestion.
Resource Provider Permissions:
Custom Permissions:
⚠️ Note: These instructions were automatically generated from the connector's user interface definition file using AI and may not be fully accurate. Please verify all configuration steps in the Microsoft Sentinel portal.
1. Prerequisites and Infrastructure Setup
Before configuring the integration, make sure the following requirements are met:
2. Deploy the Data Collection Rule (DCR)
Cayosoft Guardian streams threat alerts via the Azure Monitor Agent, which requires a Data Collection Rule (DCR) linked to your Arc-enabled server or Azure VM. This is a one-time deployment, separate from the solution install.
Click the button below.
Select your Subscription, Resource Group, and Region.
Enter your Workspace Name (the Microsoft Sentinel-enabled Log Analytics workspace) and Arc Machine Name (the exact name of the Arc-enabled server or Azure VM running Cayosoft Guardian).
Click Review + Create, then Create.
3. Configure Cayosoft Guardian Logging
Enable the event log generation within the product:
4. Install the Workbook
The Cayosoft Guardian solution includes a prebuilt workbook that visualizes threat alerts and incidents, including severity distribution, alerts by system type, alert trends over time, and recent incidents and alerts.
5. Enable the Analytics Rules
The Cayosoft Guardian solution also includes scheduled analytics rule templates that convert Cayosoft Guardian threat alerts into Microsoft Sentinel incidents.
SecurityIncident records used by the workbook's Incidents & recent alerts table.6. Verify the Integration
After configuring the connector, verify that Microsoft Sentinel is receiving Cayosoft Guardian threat alert data:
CayosoftThreatAlerts_CL | sort by TimeGenerated desc | take 50 Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊