Tip
This article was accurate at the time of writing, but changes happen. If you find the instructions are outdated, leave a description in the comment field below and let us know!
Step 1: Enable console access
The Exabeam Security Management Platform uniquely combines a data lake for unlimited data collection, machine learning for advanced analytics, and automated incident response into an integrated set of products. The SOC analysts requires a dedicated user account, which allows us to respond to security alerts and leverage the data available in Exabeam.
-
At the top right from the menu, navigate to Settings.
-
Under the Exabeam User Management section, select Users.
-
Select Add User. Type the following information for the requested fields:
Field name
What to put in it
User Type
Local
Username
expel
Full Name
Expel SOC
Email
Optional field can be left blank
Password
Enter a password. Save the password to enter later in Workbench.
-
For Role, select Tier 3 Analyst. If a custom role is preferred, complete the next 2 steps. Note the permission requirements. If you don't need a custom role, skip to Step 2 below.
-
For a custom role, type Expel for Role Name and Expel Custom Role for Description.
-
Select Advanced Analytics, and choose the following permissions:
View
View Activities
Required
View Executive Info
Required
View Global Insights
Required
View Infographics
Required
View Insights
Required
View Rules
Required
Edit and Approve
Approve Lockouts
Optional but recommended
Accept Sessions
Optional but recommended
Manage Rules
Optional but recommended
Manage Watchlist
Optional but recommended
Search
Manage Search Library
Optional but recommended
Basic Search
Required
Threat Hunting
Required
View Search Library
Required
Step 2: Generate API credentials
-
Navigate to Settings > Admin Operations > Cluster Authentication Token.
-
On the Cluster Authentication Token menu, click + to add a new token.
-
In the Setup Token dialog box, fill in the Token Name, set Expiry Date to Permanent, and set the Permission Level as Tier 3 Analyst.
-
Copy the generated token for use in the next step.
Step 3: Configure the technology in Workbench
Now that we have all the correct access configured, we can integrate Exabeam with Expel.
-
In a new browser tab, log into https://workbench.expel.io.
-
On the console page, navigate to Settings and click Security Devices.
-
At the top of the page, click Add Security Device.
-
Search for and select Exabeam Advanced Analytics from the list of supported technologies.
-
Complete all fields using the credentials and information you collected in Step 1 and Step 2.
-
(Optional) Select an Assembler from the list. If you have an assembler, select the assembler you set up in Step 2 of the Getting Started with Expel guide.
-
Type Name (give your Exabeam a name).
-
Type the city or site where your Exabeam is located for Location.
-
Under Connection Settings, for Token type the token you generated in Step 2 and for Server Address type the IP address for Exabeam.
-
(Optional) Under Console Login, type the Username and Password you generated in Step 1.
-
Comments
0 comments
Please sign in to leave a comment.