Integrate ExtraHop Enterprise with Zscaler MDR

Prev Next

Integrating ExtraHop Enterprise with Zscaler MDR amplifies threat detection and response capabilities by combining real-time network visibility with advanced threat hunting. We leverage ExtraHop’s comprehensive network traffic analysis to identify suspicious activities, providing you with a robust defense against cyberattacks. To integrate ExtraHop Enterprise with Zscaler MDR, follow the procedure below from beginning to end.

Step 1: Zscaler MDR–Create your Zscaler MDR generated URL

Create a Zscaler MDR generated-URL to send ExtraHop RevealX alerts for ingestion. 

  1. In the Zscaler MDR portal, click Integrations, then click Add Integration.

    Add a new Red Canary integration

  2. Type and select ExtraHop Enterprise.

  3. Click Configure.

  4. Enter a Name for your external alert source.  

  5. Select a Display Category.

  6. Under the Ingest Format/Method dropdown, select ExtraHop via HTTP.

  7. Click Save Configuration.

  8. Click Edit Configuration.

  9. Click Activate.

  10. Copy and save the URL and Port number.

    2.png

Step 2: ExtraHop RevealX–Create an open data stream

Enable your Zscaler MDR alert source endpoint as a valid data export stream from your ExtraHop dashboard.

  1. From your ExtraHop dashboard, click System Settings.

  2. From the Administration section, click All Administration.

    3.png

  3. From the System Configuration section, click Open Data Streams.

  4. Click Add Target.

  5. From the Target Type dropdown, select HTTP

  6. For the Name field, enter RedCanary (all one word).

  7. For the Host field, enter the host name from the URL provided in Step 1.11.

    Example:

    URL: https://testprod-use9-abcdefg.prod1.collectors.redcanary.io:123/random/

    Host name: testprod-use9-abcdefg.prod1.collectors.redcanary.io

  8. For the Port field, enter the Port number from Step 1.11.

  9. From the Type dropdown, select HTTPS.

  10. Scroll down, and then click Save.

    4.png

Step 3: ExtraHop RevealX–Upload the Zscaler MDR bundle into ExtraHop

Upload the Zscaler MDR provided bundle into ExtraHop to start sending telemetry to Zscaler MDR.

  1. Download this ExtraHop bundle.

  2. To upload and install the bundle into your ExtraHop system, follow these instructions.

  3. From your ExtraHop dashboard, click System Settings.

  4. From the Administration section, click Triggers.

    5.png

  5. Click the Zscaler MDR Data Stream trigger.

  6. Click Edit Trigger Script.

  7. Copy and paste the URL from Step 1.11 into the integration URL line.

    Example: https://testprod-use9-abcdefg.prod1.collectors.redcanary.io:123/random/

  8. Copy and paste the Stream name from Step 2.6 into the remoteStreamName line.

    7.png

  9. Click Save.