Integrating with 3rd Party Syslog and Threat Detection Platforms

Description

Capture Client is the unified client offering from SonicWall that includes the best-in-class NGAV and endpoint threat management technology from SentinelOne. As part of this offering, SonicWall also offers support for integration with multiple 3rd party log management and security operations platforms (SIEM/XDR/MDR) through the out of the box integrations supported with SentinelOne by various vendors. All 3rd party integrations typically involve one or both of the following mechanisms:

  1. Log Collection via Syslog
  2. Integration via SentinelOne APIs

Note: If you would like to take advantage of this capability, please consult with your platform vendor if they support SentinelOne out of the box before attempting these integrations. SonicWall does not offer any custom integration features or services.

Resolution

To enable log collection via Syslog for a single Tenant

  1. Login to the Capture Client console
  2. Change your scope to the tenant whose logs you want to integrate with the platform
  3. Navigate to Management -> Tenant Settings
  4. In the wizard, on Step 3, configure the Syslog Settings on the screen as shown below:

To enable log collection via Syslog for an Account

  1. For multi-tenant administrators that have access to the Account scope, this setting can be enforced at the account level for ALL tenants by using the “Inheritance” switch on this screen. To configure the Syslog settings at the Account scope, change to the Account scope and navigate to Management -> Account Settings, as in the screen below:

To enable integration via SentinelOne APIs

Related Articles

  • How to Generate a Capture Client (SentinelOne) API Key Using a Service User
    Read More
  • Integrating SonicWall Capture Client with SonicWall Firewalls
    Read More
  • How to use Resource Monitor to see if a Capture Client Interoperability Exclusion is Being Applied
    Read More
not finding your answers?