The Cato Networks Advanced App is available for log collection only and includes the following schedulers:
Cato Networks Audit Feed Events
Cato Networks Event Feed Events
Cato Networks XDR Stories Events
The API documentation used to create this app can be found here:
Log Collection to fetch Audit Feed Events
Log Collection to fetch Event Feed Events
Log Collection to fetch XDR Stories Events
CONFIGURATION
To configure the app, users will need a valid Host Name, Client ID, and API Key.
To generate an API key from CATO, go to the Resources page in the management console, and then select "API Keys" on the left-hand toolbar under "Integrations & Events". From there, you can generate a new API key to be used in USM Anywhere.
Click on the save button to save the credentials. Once the status is green, the app is configured successfully.
ACTIONS TAB
There are no response actions available for this advanced app at this time. The Actions tab shows the links to the API reference guides for each scheduler. The links will redirect you to the Cato Networks API Reference Guide pages.
SCHEDULER TAB
The Cato Networks App is scheduled to pull logs every 15 minutes by default. Users can change this schedule from the UI by toggling the "enable" button on the scheduler and then editing the job.
HISTORY TAB
For every successful run of the scheduler, a success message along with the number of events fetched will be displayed in the schedulers page and if the scheduler fails to fetch the logs, an error message will be displayed.