- 21 Jul 2025
- 1 Minute to read
- PDF
Integrate ExtraHop RevealX with Red Canary
- Updated on 21 Jul 2025
- 1 Minute to read
- PDF
Integrating ExtraHop RevealX with Red Canary provides a powerful combination of advanced network detection and response capabilities. By combining our expert threat hunting and incident response with ExtraHop’s real-time network visibility and threat detection you can significantly enhance your ability to identify, investigate, and neutralize complex cyberattacks. To integrate ExtraHop RevealX with Red Canary, follow the procedure below from beginning to end.
Step 1: ExtraHop RevealX–Create REST API credentials
Red Canary uses your representational state transfer (REST) API credentials to make REST calls to your cloud instance in order to start receiving your alerts.
From your ExtraHop dashboard, click system settings.
From the Administration section, click API Access.
Click Create Credentials.
Name your REST API Credential.
From the System Access section, select Full read-only.
From the NDR Module Access section, select Full access.
From the NPM Module Access section, select Full access.
From the Packet And Session Key Access section, select No access.
Click Save.
Copy and save the API Endpoint, ID, and Secret for your REST API Credentials.
Step 2: Red Canary–Connect ExtraHop RevealX API REST credentials to Red Canary
Connect your ExtraHop API REST credentials to Red Canary to start sending your alerts.
From your Red Canary homepage, click Integrations, and See all integrations.
Type and select ExtraHop RevealX.
Click Configure.
Enter a Name for your external alert source.
Select a Display Category.
Under the Ingest Format/Method dropdown, select ExtraHop via API Poll.
Enter your ExtraHop Client ID from Step 1.10.
Enter your ExtraHop Client Secret from Step 1.10.
Enter your ExtraHop API Host from Step 1.10.
Click Save Configuration.
Click Edit Configuration.
Click Activate.