Skip to content

Varonis Data Security - SaaS

Overview

Varonis offers solutions to track and protect data.

Warning

Important note - This format is currently in beta. We highly value your feedback to improve its performance.

  • Vendor: Varonis
  • Supported environment: SaaS
  • Detection based on: Alert
  • Supported application or feature: Data loss prevention

Configure

How to create API token

  1. Log in the Varonis console
  2. Go to Configuration > API Keys

    Varonis Data Security SaaS configure - 1

  3. Click + New API Key

    Varonis Data Security SaaS configure - 2

  4. Type a name

  5. Select Threat Detection Integrator as a role
  6. Type a description
  7. Click Generate Key

    Varonis Data Security SaaS configure - 3

  8. Copy the generated API Key

  9. Click Done

    Varonis Data Security SaaS configure - 4

Create an intake

  1. Go to the intake page and create a new intake from the format Varonis Data Security SaaS.
  2. Set up the intake configuration with the Base URL (looks like https://YOUR_TENANT.varonis.io) and API token.

Detection section

The following section provides information for those who wish to learn more about the detection capabilities enabled by collecting this intake. It includes details about the built-in rule catalog, event categories, and ECS fields extracted from raw events. This is essential for users aiming to create custom detection rules, perform hunting activities, or pivot in the events page.