This article explains how to connect Lacework to Workbench.

Step 1: Enable console access

Create a user in Lacework for Workbench or create an SSO user for Workbench with access to Lacework.

Step 2: Generate API credentials

Lacework provides a combination of API Access keys and tokens to be used by clients and client applications to access the Lacework API. API access key IDs and secret access keys are created using the Lacework Console. Temporary access (bearer) tokens, used by clients, are created using the Lacework API.

Only administrators can create API access keys with a limit of 2 per user. An API access key doesn't expire but can be disabled or deleted. After creation, administrators can download and securely store the secret key.

  1. To create an API key, navigate to Settings > API Keys and click + Create New.

  2. Type a name for the key and an optional description and click Save.

  3. To get the secret key, download the generated API key file and open it in an editor.

    Docs reference: https://support.lacework.com/hc/en-us/articles/360011403853-Generate-API-Access-Keys-and-Tokens

Step 3: Configure the technology in Workbench

Note

Expel secures all login information our SOC analysts need about your devices in a MFA password product. Access to this login information is protected using our internal MFA processes. To learn more about the IP addresses all Expel traffic comes from, go here.

  1. In a new browser tab, login to https://workbench.expel.io.

  2. On the console page, navigate to Settings and click Security Devices.

  3. At the top of the page, click Add Security Device.

  4. Search for and select your technology.

    Screen Shot 2021-03-05 at 12.29.16 PM.png
  5. Complete all fields using the credentials and information you collected in Step 1 and Step 2.

    • For Name type the host name of the Lacework device.

    • For Location type the geographic location of the appliance.

    • For URL type the host name or IP address of the Lacework management interface. Device IP can be found in the Lacework console under Dashboard > General Information > MGT IP Address.

    • For API key type the API generated in Step 2.

    • For API secret, type the secret generated in Step 2.

  6. You can provide console access now or set it up later. Use the instructions below to set it up later.

Tip

This article was accurate at the time of writing, but changes happen. If you find the instructions are outdated, leave a description in the comment field below and let us know!