↳ GitHub sourceConnector

CTERA Syslog

Description

The CTERA Data Connector for Microsoft Sentinel offers monitoring and threat detection capabilities for your CTERA solution. It includes a workbook visualizing the sum of all operations per type, deletions, and denied access operations. It also provides analytic rules which detects ransomware incidents and alert you when a user is blocked due to suspicious ransomware activity. Additionally, it helps you identify critical patterns such as mass access denied events, mass deletions, and mass permission changes, enabling proactive threat management and response.
Declared status
1
Declared author / publisher
CTERA Networks Ltd

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

write permission is required.
Workspace
Workspace

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

Step 1: Connect CTERA Platform to Syslog
Set up your CTERA portal syslog connection and Edge-Filer Syslog connector
CTERA Syslog Configuration
Portal Syslog connection
Connect CTERA Portal to syslog server, see instructions https://kb.ctera.com/v1/docs/en/managing-log-settings?highlight=logg
Edge Filer Audit logs
Enable Audit logs on the desired Edge-filers
Edge-Filer Syslog Service
Enable Edge-Filer Syslog service, see instructions https://kb.ctera.com/v1/docs/en/setting-up-the-edge-filer-syslog-service-2?highlight=Edge%20Filer%20Syslog
Step 2: Install Azure Monitor Agent (AMA) on Syslog Server
Install the Azure Monitor Agent (AMA) on your syslog server to enable data collection.
Install Azure Monitor Agent
Log in to Azure Portal
Use your Azure credentials to log in to the Azure Portal.
Navigate to Azure Arc
In the Azure Portal, go to 'Azure Arc' and select your connected syslog server.
Select Extensions
In the Azure Arc settings for your syslog server, navigate to the 'Extensions' section.
Add Extension
Click on 'Add' and select 'Azure Monitor Agent' from the list of available extensions.
Install AMA
Follow the prompts to install the Azure Monitor Agent on your syslog server. For detailed instructions, refer to the official documentation: [Install Azure Monitor Agent](https://learn.microsoft.com/en-us/azure/azure-monitor/agents/azure-monitor-agent-manage?tabs=azure-portal)

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
CTERA
Additional source files 2Solutions/CTERA/Data Connectors/CTERA_Data_Connector.jsonsource ↗Solutions/CTERA/Data/Solution_CTERA.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.