↳ GitHub sourceConnector

[Deprecated] Forcepoint CSG via Legacy Agent

Description

Forcepoint Cloud Security Gateway is a converged cloud security service that provides visibility, control, and threat protection for users and data, wherever they are. For more information visit: https://www.forcepoint.com/product/cloud-security-gateway
Declared status
1
Declared author / publisher
Forcepoint

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

read and write permissions are required.
Workspace
Workspace
read permissions to shared keys for the workspace are required. [See the documentation to learn more about workspace keys](https://docs.microsoft.com/azure/azure-monitor/platform/agent-windows#obtain-workspace-id-and-key).
Keys
Workspace

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

1. Linux Syslog agent configuration
This integration requires the Linux Syslog agent to collect your Forcepoint Cloud Security Gateway Web/Email logs on port 514 TCP as Common Event Format (CEF) and forward them to Microsoft Sentinel.
Your Data Connector Syslog Agent Installation Command is:
2. Implementation options
The integration is made available with two implementations options.
2.1 Docker Implementation
Leverages docker images where the integration component is already installed with all necessary dependencies. Follow the instructions provided in the Integration Guide linked below. [Integration Guide >](https://frcpnt.com/csg-sentinel)
2.2 Traditional Implementation
Requires the manual deployment of the integration component inside a clean Linux machine. Follow the instructions provided in the Integration Guide linked below. [Integration Guide >](https://frcpnt.com/csg-sentinel)
3. Validate connection
Follow the instructions to validate your connectivity: Open Log Analytics to check if the logs are received using the CommonSecurityLog schema. >It may take about 20 minutes until the connection streams data to your workspace. If the logs are not received, run the following connectivity validation script: > 1. Make sure that you have Python on your machine using the following command: python -version >2. You must have elevated permissions (sudo) on your machine
Run the following command to validate your connectivity:
4. Secure your machine
Make sure to configure the machine's security according to your organization's security policy [Learn more >](https://aka.ms/SecureCEF).

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
ForcepointCSG
Additional source files 1Solutions/Forcepoint CSG/Data Connectors/ForcepointCloudSecurityGateway.jsonsource ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.