cato networks alert.md

Cato Networks

Cato Networks

The Dropzone platform integrates with Cato Networks, a cloud-native Secure Access Service Edge (SASE) platform that provides capabilities such as SD-WAN, secure web gateway (SWG), firewall-as-a-service (FWaaS), zero trust network access (ZTNA), and cloud access security broker (CASB).

By integrating with Cato Networks, Dropzone AI can leverage network and VPN telemetry to enhance security investigations by analyzing network traffic associated with alerts, identifying devices behind IP addresses, and correlating user and VPN activity across the environment.

Obtain Account ID and API Key

Cato Networks requires an Account ID and an API key to enable. You will need access to an account administrator with the Editor privilege to generate keys.

To locate your Account ID, do the following:

The Account ID

To generate an API key, do the following:

Navigate to "Administration"

Click "API Management"

Click New

Create New API Key

Enable Cato Networks

To enable the Data Source integration, you will need the following information:

Dropzone Field Source
Cato Networks API FQDN The FQDN of your Cato Networks API instance, e.g. api.catonetworks.com
Account ID The Account ID value you copied earlier
API Key The API key value you copied earlier

Integrations Dropdown

Click Available

The Cato Networks tile

The Cato Networks Alert Configuration (pt 1)

{% hint style="info" %} Cato Networks assigns actions to each event that occurs in your account, which Dropzone then uses to filter. For more information, click here {% endhint %}

The Cato Networks Alert Configuration (pt 2)

The Cato Networks Alert Configuration (pt 3)

The Cato Networks Alert Configuration (pt 4)

If you have any errors engage your Dropzone AI support representative.