Skip to content

Commit 2e2387e

Browse files
authored
Varonis (apps) (#6018)
* Varonis (apps) * Update varonis.md
1 parent f12fbf0 commit 2e2387e

File tree

7 files changed

+142
-1
lines changed

7 files changed

+142
-1
lines changed

blog-service/2025-11-12-apps.md

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
---
2+
title: Varonis (Apps)
3+
image: https://assets-www.sumologic.com/company-logos/_800x418_crop_center-center_82_none/SumoLogic_Preview_600x600.jpg?mtime=1617040082
4+
keywords:
5+
- apps
6+
- varonis
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
We're excited to introduce the new Sumo Logic app for Varonis. This app provides a unified view of threat intelligence and detection activity for faster and more informed analysis by collecting alerts from the Varonis platform. [Learn more](/docs/integrations/saas-cloud/varonis/).

cid-redirects.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2959,6 +2959,7 @@
29592959
"/cid/1113": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/databricks-audit-source/",
29602960
"/cid/1117": "/docs/integrations/saas-cloud/chatgpt-compliance",
29612961
"/cid/1118": "/docs/integrations/saas-cloud/databricks-audit",
2962+
"/cid/1121": "/docs/integrations/saas-cloud/varonis",
29622963
"/cid/1120": "/docs/integrations/saas-cloud/github-copilot",
29632964
"/Cloud_SIEM_Enterprise": "/docs/cse",
29642965
"/Cloud_SIEM_Enterprise/Administration": "/docs/cse/administration",

docs/integrations/product-list/product-list-m-z.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -204,7 +204,7 @@ For descriptions of the different types of integrations Sumo Logic offers, see [
204204
| Logo | Vendors and Products | Integrations |
205205
| :-- | :-- | :-- |
206206
| <img src={useBaseUrl('img/integrations/web-servers/varnish-cache.png')} alt="Thumbnail icon" width="75"/> | [Varnish](https://www.varnish-software.com/) | Apps: <br/>- [Varnish](/docs/integrations/web-servers/varnish/) <br/>- [Varnish - OpenTelemetry](/docs/integrations/web-servers/opentelemetry/varnish-opentelemetry/) |
207-
| <img src={useBaseUrl('img/integrations/misc/varonis-logo.png')} alt="Thumbnail icon" width="75"/> | [Varonis](https://www.varonis.com/) | Cloud SIEM integration: [Varonis](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/20270f89-127e-4055-96ec-56045e67e163.md) <br/>Collector: [Varonis Alerts](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/varonis-source) |
207+
| <img src={useBaseUrl('img/integrations/misc/varonis-logo.png')} alt="Thumbnail icon" width="75"/> | [Varonis](https://www.varonis.com/) | App: [Varonis](/docs/integrations/saas-cloud/varonis) <br/>Cloud SIEM integration: [Varonis](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/20270f89-127e-4055-96ec-56045e67e163.md) <br/>Collector: [Varonis Alerts](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/varonis-source) |
208208
| <img src={useBaseUrl('img/platform-services/automation-service/app-central/logos/vectra.png')} alt="Thumbnail icon" width="75"/> | [Vectra](https://www.vectra.ai/) | App: [Vectra](/docs/integrations/saas-cloud/vectra) <br/> Automation integration: [Vectra](/docs/platform-services/automation-service/app-central/integrations/vectra/) <br/>Collector: [Vectra Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/vectra-source) <br/>Cloud SIEM integration: [Vectra](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/7a3d1a5c-ba67-4597-971f-7057e8f6c8bb.md) |
209209
| <img src={useBaseUrl('img/platform-services/automation-service/app-central/logos/virustotal.png')} alt="Thumbnail icon" width="75"/> | [VirusTotal](https://www.virustotal.com/) | Automation integrations: <br/>- [VirusTotal](/docs/platform-services/automation-service/app-central/integrations/virustotal/) <br/>- [VirusTotal V3](/docs/platform-services/automation-service/app-central/integrations/virustotal-v3/) |
210210
| <img src={useBaseUrl('img/platform-services/automation-service/app-central/logos/vmray.png')} alt="Thumbnail icon" width="75"/> | [VMRay](https://www.vmray.com/) | Automation integration: [VMRay](/docs/platform-services/automation-service/app-central/integrations/vmray/) |

docs/integrations/saas-cloud/index.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -453,6 +453,12 @@ Learn about the Sumo Logic apps for SaaS and Cloud applications.
453453
<p>Analyze authentication events, user activities, and potential security threats.</p>
454454
</div>
455455
</div>
456+
<div className="box smallbox card">
457+
<div className="container">
458+
<a href={useBaseUrl('docs/integrations/saas-cloud/varonis')}><img src={useBaseUrl('img/integrations/misc/varonis-logo.png')} alt="icon" width="100"/><h4>Varonis</h4></a>
459+
<p>Identify and evaluate security threats and behaviors across your Varonis platform.</p>
460+
</div>
461+
</div>
456462
<div className="box smallbox card">
457463
<div className="container">
458464
<a href={useBaseUrl('docs/integrations/saas-cloud/vectra')}><img src={useBaseUrl('img/platform-services/automation-service/app-central/logos/vectra.png')} alt="icon" width="100"/><h4>Vectra</h4></a>
Lines changed: 121 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,121 @@
1+
---
2+
id: varonis
3+
title: Varonis
4+
sidebar_label: Varonis
5+
description: The Sumo Logic app for Varonis provides insights into your organization's cybersecurity practices to strengthen security.
6+
---
7+
8+
import useBaseUrl from '@docusaurus/useBaseUrl';
9+
10+
<img src={useBaseUrl('img/integrations/misc/varonis-logo.png')} alt="thumbnail icon" width="100"/>
11+
12+
The Sumo Logic app for Varonis provides a centralized view of threat intelligence and detection activity across your Varonis environment. It helps you quickly evaluate threat volume, confidence levels, types, and associated detection sources and techniques.
13+
14+
## Log types
15+
16+
This app uses Sumo Logic’s [Varonis source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/varonis-source/) to collect the alerts from the Varonis platform.
17+
18+
## Sample log messages
19+
20+
<details>
21+
<summary>Varonis Alert</summary>
22+
23+
```json
24+
{
25+
"escalationType": null,
26+
"eventsCount": 1,
27+
"hasSensitiveResource": false,
28+
"hasTaggedResource": false,
29+
"id": "EBB74744-5D3A-47B5-8CD3-81C4B70026A0",
30+
"isAssignedToVaronis": false,
31+
"status": "NEW",
32+
"closedBy": {
33+
"name": null
34+
},
35+
"closeReason": {
36+
"id": "0",
37+
"name": null
38+
},
39+
"dataSource": [
40+
{
41+
"id": "9",
42+
"name": "psg49574-Proxy1",
43+
"type": "PROXY"
44+
}
45+
],
46+
"generationTime": {
47+
"dateTimeUtc": "2025-11-04T12:13:52.034Z"
48+
},
49+
"note": null,
50+
"policy": {
51+
"category": "EXFILTRATION",
52+
"id": "89",
53+
"name": "Abnormal behavior: an unusual amount of data was uploaded to email websites",
54+
"severity": "HIGH"
55+
}
56+
}
57+
```
58+
</details>
59+
60+
## Sample queries
61+
62+
```sql title="Total Alerts"
63+
_sourcecategory=*varonis*
64+
| json "id", "dataSource", "policy.category", "policy.severity", "policy.name", "generationTime.dateTimeUtc", "escalationType", "status" as threat.id, detection.source, detection.technique, detection.confidence, threat.name, event.time, event.type, finding.status nodrop
65+
| where detection.confidence !=NULL
66+
67+
| timeslice 1d
68+
| count as frequency by _timeslice, detection.confidence
69+
| fillmissing timeslice, values all in detection.confidence
70+
| transpose row _timeslice column detection.confidence
71+
```
72+
73+
## Collection configuration and app installation
74+
75+
import CollectionConfiguration from '../../reuse/apps/collection-configuration.md';
76+
77+
<CollectionConfiguration/>
78+
79+
:::important
80+
Use the [Cloud-to-Cloud Integration for Varonis](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/varonis-source/) to create the source and use the same source category while installing the app. By following these steps, you can ensure that your Varonis app is properly integrated and configured to collect and analyze your Varonis data.
81+
:::
82+
83+
### Create a new collector and install the app
84+
85+
import AppCollectionOPtion1 from '../../reuse/apps/app-collection-option-1.md';
86+
87+
<AppCollectionOPtion1/>
88+
89+
### Use an existing collector and install the app
90+
91+
import AppCollectionOPtion2 from '../../reuse/apps/app-collection-option-2.md';
92+
93+
<AppCollectionOPtion2/>
94+
95+
### Use an existing source and install the app
96+
97+
import AppCollectionOPtion3 from '../../reuse/apps/app-collection-option-3.md';
98+
99+
<AppCollectionOPtion3/>
100+
101+
## Viewing the Varonis dashboards​​
102+
103+
import ViewDashboards from '../../reuse/apps/view-dashboards.md';
104+
105+
<ViewDashboards/>
106+
107+
### Security Overview
108+
109+
The **Varonis - Security Overview** dashboard provides a unified view of security threats detected across your environment. It surfaces key insights such as threat volume, confidence levels, detection techniques, and data sources including Active Directory, SharePoint, and Exchange Online. You can easily spot spikes in activity, monitor emerging or ongoing threats, and identify recurring issues such as abnormal data uploads or policy violations. The detailed threat summary table enables deeper investigation by presenting event-level data, detection methods, and associated confidence levels. Together, these capabilities help security teams assess risk exposure and prioritize incident response more effectively. <br/><img src={useBaseUrl('img/integrations/saas-cloud/Varonis-SecurityOverview.png')} alt="Varonis - Security Overview Dashboard" />
110+
111+
## Upgrading the Varonis app (Optional)
112+
113+
import AppUpdate from '../../reuse/apps/app-update.md';
114+
115+
<AppUpdate/>
116+
117+
## Uninstalling the Varonis app (Optional)
118+
119+
import AppUninstall from '../../reuse/apps/app-uninstall.md';
120+
121+
<AppUninstall/>

sidebars.ts

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2623,6 +2623,7 @@ integrations: [
26232623
'integrations/saas-cloud/trellix-mvision-epo',
26242624
'integrations/saas-cloud/trend-micro-vision-one',
26252625
'integrations/saas-cloud/trust-login',
2626+
'integrations/saas-cloud/varonis',
26262627
'integrations/saas-cloud/vectra',
26272628
'integrations/saas-cloud/vmware-workspace-one',
26282629
'integrations/saas-cloud/webex',
303 KB
Loading

0 commit comments

Comments
 (0)