Having read-only access to the interface of your technology allows Expel to dig deeper when performing incident investigations. Our device health team uses this access to investigate potential health issues with your tech.
Step 1: Enable console access
- Administration > User Accounts > Configure.
- Select +Add within the Users List.
- For User Type select local.
- Select Privileges checkbox for Admin.
- For Username type expelsoc.
- For First Name type Expel.
- For Last Name type SOC.
- Type a Password.
Note: After console access is established for Expel, the remaining onboarding steps for this technology can also be performed by Expel. Reach out to your Engagement Manager and we're happy to complete the integration!
Step 2: Logging Attivo using Sumo Logic and Splunk
Refer to your SIEM documentation or work with your SIEM representative to port in Attivo logs. You can also refer to the following web references for creating a new Syslog source:
Step 3: Configure Attivo in Workbench
Now that we have the correct access configured, we can integrate your Attivo with Expel.
Register device in Expel Workbench
- In a new browser tab, go to https://workbench.expel.io/settings/security-devices?setupIntegration=attivo.
- Select the Assembler with network connectivity to the Attivo device.
- For Name type the hostname of the Attivo device.
- For Location type the geographic location of the appliance.
- For Source Category, type the Sumo Logic source category for this device.
- For Source Type (SIEM that contains the data) type the Splunk source type for this device.
- For Username type expelsoc from Step 1.
- For Password type the expelsoc admin password previously created in the Attivo console in Step 1.
- Click Save.
After a few minutes, refresh the Security Devices page and you see your device status reporting as Healthy, or if there is an issue, you see details of what the issue may be.
To check if alerts are coming through, navigate to Alerts on the console page. Click the icon in the upper right to switch to grid view, then check the list for device alerts.