Overview
The SonicWall Capture Client integration enables ThreatAware to collect read-only data from your SonicWall Capture Client environment, providing visibility into endpoint security status and helping validate your endpoint protection controls.Connection Method: Credentials with Read-Only Access
Setup Time: 15 minutes
Access Required: SonicWall Capture Client Administrator account
Data collected
The SonicWall Capture Client integration provides:- Device security status
- Threat detection and response data
- Endpoint compliance metrics
- Device inventory and protection details
Use cases
Endpoint Security Tracking
Monitor endpoint protection status across all managed devices
Compliance Validation
Verify endpoint protection policies are properly configured
Threat Management
Track threats and security incidents across your environment
Audit Support
Generate reports showing endpoint protection coverage
Setup instructions
1
Log in to ThreatAware Dashboard
Open the ThreatAware dashboard, navigate to Settings > Systems, and use the search bar to locate SonicWall Capture Client.
2
Click Connect
Click Connect, and a pop-up window will appear.
3
Create Read-Only Account in SonicWall
In the SonicWall Capture Client admin portal:
- Log in with an administrator account
- Navigate to User Management
- Create a new user with Read-Only access
- Ensure the user has permission to view devices and logs
- Note the username and password you created
4
Identify SonicWall Server URL
Determine the URL for your SonicWall Capture Client admin portal:
- This is typically the admin console URL you use to access SonicWall
- Format:
https://your-sonicwall-url.comor similar
5
Configure in ThreatAware
In the ThreatAware integration form, enter the following credentials:
- Username: The read-only user account created in SonicWall
- Password: The password for the read-only account
- Server URL: The URL of your SonicWall Capture Client admin portal
- Click Authorize to complete the integration setup
6
Verify Connection
After authorising, verify that the Integration Status in ThreatAware displays as Active.
Required credentials
Username
Username
Field Name: SonicWall Username
Type: String
Description: The username of the read-only account in SonicWall Capture ClientThis should be a dedicated account created specifically for ThreatAware integration.
Password
Password
Field Name: SonicWall Password
Type: Password (encrypted)
Description: The password for the read-only SonicWall account
Server URL
Server URL
Field Name: SonicWall Server URL
Type: String
Description: The URL of your SonicWall Capture Client admin portalFormat:
https://your-sonicwall-url.com
Example: https://sonicwall.acme.com or https://capture.company.netVerification and testing
After setup, verify the integration is working correctly:-
Check Integration Status
- Navigate to Settings > Integrations in ThreatAware
- Confirm the SonicWall Capture Client integration shows Active status
-
Verify Data Collection
- Wait 60 minutes for the initial data poll
- Search for a known device in ThreatAware
- Check device details for SonicWall protection data
-
Test Queries
- Create a test query to filter devices by SonicWall security status
- Verify the data matches your expectations
Troubleshooting
Invalid Credentials Error
Invalid Credentials Error
Symptoms: Integration status shows authentication failureSolutions:
- Verify that the Username and Password are entered accurately
- Ensure the read-only user account is still active in SonicWall
- Check that the account has not been locked or expired
- Confirm credentials were entered without extra spaces
Permission Issues
Permission Issues
Symptoms: Integration connects but no data or limited data appearsSolutions:
- Ensure the read-only user account has the correct permissions assigned
- Verify the account can view devices and logs in SonicWall
- Check for any organisational policies restricting API or integration access
- Review SonicWall Documentation for permission details
Connection Timeout
Connection Timeout
Symptoms: Integration fails to connect or times outSolutions:
- Verify the Server URL is correct and accessible from ThreatAware
- Check firewall rules allow outbound HTTPS (443) to your SonicWall server
- Confirm your SonicWall Capture Client portal is accessible via the internet
- Test the URL in a browser to ensure it’s reachable
No Data After 1 Hour
No Data After 1 Hour
Symptoms: Integration shows active but no endpoint data appearsSolutions:
- Verify there are managed devices in your SonicWall Capture Client environment
- Check the read-only account’s access to device inventory
- Ensure devices are properly enrolled in SonicWall
- Review ThreatAware integration logs (contact support if needed)
Additional resources
SonicWall Documentation
Official SonicWall documentation for user management and configuration
ThreatAware Support
Contact ThreatAware support for integration assistance