Skip to content

Cato Networks SASE

You can integrate Cato Networks SASE with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

Cato Networks SASE product overview

Cato Networks is a Secure Access Service Edge (SASE) platform that combines networking (SD-WAN and a global private backbone) and security services, such as firewall-as-a-service, secure web gateway, CASB, DLP, IPS, and Zero Trust Network Access, into a single, cloud-native global service.

What we ingest

Sophos XDR collects Cato Networks logs from an Amazon S3 bucket. You configure Cato to forward its event logs to an S3 bucket, then deploy a Lambda function that forwards them to Sophos XDR. The following log categories are collected:

  • Malware detections: Cato Anti-Malware detections.
  • Intrusion detections: Cato IPS detections.
  • Authentication: Cato authentication events.
  • DHCP activity: Cato DHCP lease events.

Event and data types

We ingest the following event and data types from Cato Networks SASE:

  • Malware detections: Cato Anti-Malware detections, including the threat, file, and action. Normalized to antivirus telemetry.
  • Intrusion detections: Cato IPS (intrusion prevention) detections, including the signature and endpoints. Normalized to third-party security alert telemetry.
  • Authentication: Cato user and administrative authentication events, with the user and result. Normalized to authentication telemetry.
  • DHCP activity: Cato DHCP lease events, including the IP address and client. Normalized to DHCP telemetry.

Data provided by this integration

Data provided by Cato Networks SASE gets normalized to the following schemas:

  • antivirus
  • auth
  • dhcp
  • thirdpartyalert

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation