Varonis DatAlert
Connect Varonis DatAlert to Radiant Security to forward alerts for AI triage.
Varonis DatAlert is a data security platform that detects insider threats, ransomware, and unauthorized access to file shares, email systems, and other data stores. Connecting Varonis DatAlert forwards alerts to Radiant Security over syslog.
Varonis DatAlert can forward alerts to Radiant Security in two ways:
Through the Radiant Agent (recommended). Forward to a Radiant Agent deployed in your environment.
Direct to Radiant Security. Forward over TLS to the Radiant syslog cluster. Use only when a Radiant Agent is not available.
Prerequisites
Add the data connector in Radiant Security
Sign in to Radiant Security.
From the navigation menu, click Settings > Data Connectors, then click + Add Connector.
Search for and select Radiant Agent, then click Data Feeds.
Under Select your data feeds, select Varonis DatAlert, then click Credentials.
Under Credential Name, enter an identifiable name for the Radiant Agent integration (e.g.,
Radiant Agent Integration). To reuse an existing Radiant Agent credential, select it from the drop-down menu.Click Add Connector.
Sign in to Radiant Security.
From the navigation menu, click Settings > Data Connectors, then click + Add Connector.
Search for and select Varonis DatAlert (syslog), then click Data Feeds.
Under Select your data feeds, select Varonis DatAlert (syslog), then click Credentials.
Under Credential Name, enter an identifiable name for this credential (e.g.,
Varonis). To reuse an existing credential, select it from the drop-down menu.In the Connector tag field, enter a random value. This value acts as the salt to randomize the Token generated for your connector.
Click Add Connector.
Click Done to save your changes.
Configure Varonis DatAlert to forward syslog through the Radiant Agent
Before starting, confirm the IP address of the Radiant Agent and the port configured to receive Varonis data. If you do not know the port, contact your Customer Success representative.
Sign in to Varonis.
In Data Advantage, select Tools > DatAlert.
In the menu, click Configuration.
In Syslog Message Forwarding, enter the following:
Syslog Server: the IP address of the Radiant Agent.
Port: the port configured on the Radiant Agent to receive Varonis data.
Facility Name:
1 - user-level messages
Click OK.
In the menu, click Alert Templates.
Select Varonis LEEF Template, then click Edit Alert Template.

Under Apply to alert methods, select Syslog message.

Click OK.
Configure Varonis DatAlert to forward syslog directly to Radiant Security
Use this path only when a Radiant Agent is not available.
Sign in to Varonis.
In Data Advantage, select Tools > DatAlert.
In the menu, click Configuration.
In Syslog Message Forwarding, enter the following:
Syslog Server:
cluster.syslog.radiantsecurity.aiPort:
6514Facility Name:
1 - user-level messages
Click OK.
In the menu, click Alert Templates.
Select Varonis LEEF Template, then click Edit Alert Template.
Under Apply to alert methods, select Syslog message.
Click OK.
Apply syslog forwarding to DatAlert rules
In Varonis, open the DatAlert rules table.
Select the rules to forward, then click Edit Rule.
On the left menu, select Alerts Method.
Click the Edit icon, then select the Syslog message checkbox.

Click OK.
Verify ingestion
After Varonis begins forwarding, confirm alerts are reaching Radiant.
In Radiant, navigate to Log Management.
Filter by
rs_connectorType:"varonis_datalert".Confirm recent alerts appear.
Allow several minutes for alerts to be parsed, indexed, and available for search.
Last updated
Was this helpful?