Skip to main content
 

Tip

This article was accurate at the time of writing, but changes happen. If you find the instructions are outdated, leave a description in the comment field below and let us know!

Step 1: Enable console access

The Exabeam Security Management Platform uniquely combines a data lake for unlimited data collection, machine learning for advanced analytics, and automated incident response into an integrated set of products. The SOC analysts require a dedicated user account, which allows us to respond to security alerts and leverage the data available in Exabeam Fusion XDR.

  1. From the menu at the top right, click Settings.

    Screen Shot 2021-03-05 at 10.50.08 AM.png
  2. In the Exabeam User Management section, select Users.

  3. Select Add User. Type the following information for the fields:

    Field name

    What to put in it

    User Type

    Local

    Username

    expel

    Full Name

    Expel SOC

    Email

    Optional field can be left blank

    Password

    Enter a password. Save the password to enter later in Workbench.

    Screen Shot 2021-03-05 at 10.50.39 AM.png
  4. For Role, select Tier 3 Analyst. If a custom role is preferred, complete the next 2 steps. Note the permission requirements. If you don't need a custom role, skip to Step 2 below.

    Screen Shot 2021-03-05 at 10.51.23 AM.png
  5. For a custom role, type Expel for Role Name and Expel Custom Role for Description.

  6. Select Advanced Analytics, and select the following permissions:

    View

    View Activities

    Required

    View Executive Info

    Required

    View Global Insights

    Required

    View Infographics

    Required

    View Insights

    Required

    View Rules

    Required

    Edit and Approve

    Approve Lockouts

    Optional but recommended

    Accept Sessions

    Optional but recommended

    Manage Rules

    Optional but recommended

    Manage Watchlist

    Optional but recommended

    Search

    Manage Search Library

    Optional but recommended

    Basic Search

    Required

    Threat Hunting

    Required

    View Search Library

    Required

Step 2: Generate API credentials

  1. Navigate to Settings > Admin Operations > Cluster Authentication Token.

    image-20210730-163054.png
  2. On the Cluster Authentication Token menu, click + to add a new token.

  3. In the Setup Token dialog box, fill in the Token Name, set Expiry Date to Permanent, and set the Permission Level as Tier 3 Analyst.

    image-20210730-163714.png
  4. Copy the generated token for use in the next step.

Step 3: Configure the technology in Workbench

  1. Go to https://workbench.expel.io/settings/security-devices?setupIntegration=exabeam_fusion_xdr.

  2. Complete the fields using the credentials and information you collected in Step 1 and Step 2.

    ExabeamFusionXDR_AddSecDev.png
    • (Optional) Select an Assembler from the list. If you have an assembler, select the assembler you set up in Getting connected to Expel Workbench

    • For Name, type a name that's meaningful to you.

    • Type the city or site where your Exabeam installation is located for Location.

    • Under Connection Settings, for Token type the token you generated in Step 2 and for Server Address type the IP address for Exabeam.

    • <verifying this>(Optional) Under Console Login, type the Username and Password you generated in Step 1.