↳ GitHub sourceConnector
[Deprecated] Forcepoint CSG via Legacy Agent
Description
Forcepoint Cloud Security Gateway is a converged cloud security service that provides visibility, control, and threat protection for users and data, wherever they are. For more information visit: https://www.forcepoint.com/product/cloud-security-gateway
- Declared status
- 1
- Declared author / publisher
- Forcepoint
Declared sources
Metadata from the source file. No dependencies inferred from KQL.
Data types
Declared permissions
read and write permissions are required.
Workspace
Workspace
read permissions to shared keys for the workspace are required. [See the documentation to learn more about workspace keys](https://docs.microsoft.com/azure/azure-monitor/platform/agent-windows#obtain-workspace-id-and-key).
Keys
Workspace
Connector instructions
Content published in the repository. Refer to the original file for all parameters.
1. Linux Syslog agent configuration
This integration requires the Linux Syslog agent to collect your Forcepoint Cloud Security Gateway Web/Email logs on port 514 TCP as Common Event Format (CEF) and forward them to Microsoft Sentinel.
Your Data Connector Syslog Agent Installation Command is:
2. Implementation options
The integration is made available with two implementations options.
2.1 Docker Implementation
Leverages docker images where the integration component is already installed with all necessary dependencies.
Follow the instructions provided in the Integration Guide linked below.
[Integration Guide >](https://frcpnt.com/csg-sentinel)
2.2 Traditional Implementation
Requires the manual deployment of the integration component inside a clean Linux machine.
Follow the instructions provided in the Integration Guide linked below.
[Integration Guide >](https://frcpnt.com/csg-sentinel)
3. Validate connection
Follow the instructions to validate your connectivity:
Open Log Analytics to check if the logs are received using the CommonSecurityLog schema.
>It may take about 20 minutes until the connection streams data to your workspace.
If the logs are not received, run the following connectivity validation script:
> 1. Make sure that you have Python on your machine using the following command: python -version
>2. You must have elevated permissions (sudo) on your machine
Run the following command to validate your connectivity:
4. Secure your machine
Make sure to configure the machine's security according to your organization's security policy
[Learn more >](https://aka.ms/SecureCEF).
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
629d1d3↗- Source identifier
ForcepointCSG
Additional source files 1
Solutions/Forcepoint CSG/Data Connectors/ForcepointCloudSecurityGateway.jsonsource ↗GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC