Skip to main content

Overview

The SonicWall Capture Client integration enables ThreatAware to collect read-only data from your SonicWall Capture Client environment, providing visibility into endpoint security status and helping validate your endpoint protection controls.
Connection Method: Credentials with Read-Only Access Setup Time: 15 minutes Access Required: SonicWall Capture Client Administrator account

Data collected

The SonicWall Capture Client integration provides:
  • Device security status
  • Threat detection and response data
  • Endpoint compliance metrics
  • Device inventory and protection details

Use cases

Endpoint Security Tracking

Monitor endpoint protection status across all managed devices

Compliance Validation

Verify endpoint protection policies are properly configured

Threat Management

Track threats and security incidents across your environment

Audit Support

Generate reports showing endpoint protection coverage

Setup instructions

1

Log in to ThreatAware Dashboard

Open the ThreatAware dashboard, navigate to Settings > Systems, and use the search bar to locate SonicWall Capture Client.
2

Click Connect

Click Connect, and a pop-up window will appear.
3

Create Read-Only Account in SonicWall

In the SonicWall Capture Client admin portal:
  • Log in with an administrator account
  • Navigate to User Management
  • Create a new user with Read-Only access
  • Ensure the user has permission to view devices and logs
  • Note the username and password you created
4

Identify SonicWall Server URL

Determine the URL for your SonicWall Capture Client admin portal:
  • This is typically the admin console URL you use to access SonicWall
  • Format: https://your-sonicwall-url.com or similar
5

Configure in ThreatAware

In the ThreatAware integration form, enter the following credentials:
  • Username: The read-only user account created in SonicWall
  • Password: The password for the read-only account
  • Server URL: The URL of your SonicWall Capture Client admin portal
  • Click Authorize to complete the integration setup
6

Verify Connection

After authorising, verify that the Integration Status in ThreatAware displays as Active.

Required credentials

Field Name: SonicWall Username Type: String Description: The username of the read-only account in SonicWall Capture ClientThis should be a dedicated account created specifically for ThreatAware integration.
Field Name: SonicWall Password Type: Password (encrypted) Description: The password for the read-only SonicWall account
Store this credential securely in your organisation’s password manager for future reference.
Field Name: SonicWall Server URL Type: String Description: The URL of your SonicWall Capture Client admin portalFormat: https://your-sonicwall-url.com Example: https://sonicwall.acme.com or https://capture.company.net

Verification and testing

After setup, verify the integration is working correctly:
  1. Check Integration Status
    • Navigate to Settings > Integrations in ThreatAware
    • Confirm the SonicWall Capture Client integration shows Active status
  2. Verify Data Collection
    • Wait 60 minutes for the initial data poll
    • Search for a known device in ThreatAware
    • Check device details for SonicWall protection data
  3. Test Queries
    • Create a test query to filter devices by SonicWall security status
    • Verify the data matches your expectations

Troubleshooting

Symptoms: Integration status shows authentication failureSolutions:
  • Verify that the Username and Password are entered accurately
  • Ensure the read-only user account is still active in SonicWall
  • Check that the account has not been locked or expired
  • Confirm credentials were entered without extra spaces
Symptoms: Integration connects but no data or limited data appearsSolutions:
  • Ensure the read-only user account has the correct permissions assigned
  • Verify the account can view devices and logs in SonicWall
  • Check for any organisational policies restricting API or integration access
  • Review SonicWall Documentation for permission details
Symptoms: Integration fails to connect or times outSolutions:
  • Verify the Server URL is correct and accessible from ThreatAware
  • Check firewall rules allow outbound HTTPS (443) to your SonicWall server
  • Confirm your SonicWall Capture Client portal is accessible via the internet
  • Test the URL in a browser to ensure it’s reachable
Symptoms: Integration shows active but no endpoint data appearsSolutions:
  • Verify there are managed devices in your SonicWall Capture Client environment
  • Check the read-only account’s access to device inventory
  • Ensure devices are properly enrolled in SonicWall
  • Review ThreatAware integration logs (contact support if needed)

Additional resources

SonicWall Documentation

Official SonicWall documentation for user management and configuration

ThreatAware Support

Contact ThreatAware support for integration assistance

Best practices

Credential Management
  • Create a dedicated read-only account specifically for ThreatAware
  • Document credentials in your organisation’s password manager
  • Rotate credentials annually or per your security policy
  • Monitor for authentication failures in ThreatAware regularly
Security Considerations
  • Only grant read-only permissions (never write or administrative access)
  • Limit account scope to necessary devices and data visibility
  • Review user activity logs in SonicWall periodically
  • Follow your organisation’s least privilege principles