- 26 Aug 2024
- 1 Minute to read
- PDF
Integrate ExtraHop Reveal(x) 360 with Red Canary
- Updated on 26 Aug 2024
- 1 Minute to read
- PDF
Integrating ExtraHop Reveal(x) 360 with Red Canary provides a powerful combination of advanced network detection and response capabilities. By combining our expert threat hunting and incident response with ExtraHop’s real-time network visibility and threat detection you can significantly enhance your ability to identify, investigate, and neutralize complex cyberattacks. To integrate ExtraHop Reveal(x) 360 with Red Canary, follow the procedure below from beginning to end.
Step 1: ExtraHop Reveal(x) 360–Create REST API credentials
Red Canary uses your representational state transfer (REST) API credentials to make REST calls to your cloud instance in order to start receiving your alerts.
From your ExtraHop dashboard, click system settings.
From the Administration section, click API Access.
Click Create Credentials.
Name your REST API Credential.
From the System Access section, select Full read-only.
From the NDR Module Access section, select Full access.
From the NPM Module section, select Full access.
From the Packet And Sessions Key Access section, select No access.
Click Save.
Copy and save the API Endpoint, ID and Secret for your REST API Credentials.
Step 2: Red Canary–Connect ExtraHop Reveal(x) 360 API REST credentials to Red Canary
Connect your ExtraHop API REST credentials to Red Canary to start sending your alerts.
From your Red Canary homepage, click Integrations, and See all integrations.
Type and select ExtraHop Reveal(X) 360.
Click Configure.
Enter a Name for your external alert source.
Select a Display Category.
Under the Ingest Format/Method dropdown, select ExtraHop via API Poll.
Enter your ExtraHop Client ID from Step 1.10.
Enter your ExtraHop Client Secret from Step 1.10.
Enter your ExtraHop API Host from Step 1.10.
Click Save Configuration.
Click Edit Configuration.
Click Activate.