Configure Cato SSE 360 for Arctic Wolf monitoring
You can configure Cato SSE 360® to send the necessary logs to Arctic Wolf® for security monitoring.
These resources are required:
- A Cato Management Application account administrator role with Editor permissions.
Enable the events feed
- Sign in to the Cato Management Application.
- Click Resources.
- In the side navigation pane, click Event Integrations
- On the Event Integrations page, click the Enable integration with Cato events toggle to the on position.
Disable allowlist event tracking
Allowlist event tracking generates a high volume of data that is not security-relevant and too fast to be queried through the API, causing operational issues. You must disable allowlist event tracking to reduce noise and prevent polling timeouts.
- Sign in to the Cato Management Application.
- Click Security.
- In the side navigation pane, click IPS.
- Click the Allow List tab.
- For each entry on the Allow List tab:
- Click Save.
Create an API key
Find the account ID
Provide Cato SSE 360 credentials to Arctic Wolf
Time-based events are polled with a delay to make sure that data is available. For new deployments, Arctic Wolf begins polling and reviewing activity from approximately one hour prior to configuration success. If API credentials fail, for example due to expired credentials, Arctic Wolf notifies you and requests a new set of credentials. After receiving refreshed credentials, Arctic Wolf can only retrieve data from the previous 12 hours. Provide refreshed credentials within 12 hours of expiry to enable complete data polling and coverage.