Step 1: Enable console access
Having read-only access to the interface of your technology allows Expel to dig deeper when performing incident investigations. Our device health team uses this access to investigate potential health issues with your tech.
This procedure creates a user account for Expel that keeps the Expel activity separate from other activity on the Elastic Endpoint Security console. Note: Elastic Endpoint was formerly called Endgame.
Create an admin account
- Navigate to Administration icon on the left, click Users tab, and click Create New User.
- For First name add Expel.
- For Last name type Admin.
- For Username type expel.
- For User Role select Admin. Note: LEVEL 3 access can be selected here although Expel can't view security policies for the device to advise on best practices and configuration. Detection remains unaffected.
- Create a Password for Expel.
Note: After console access is established for Expel, the remaining onboarding steps for this technology can also be performed by Expel. Reach out to your Engagement Manager if you want us to help.
Step 2: Configure the technology in Workbench
Now that we have the correct access configured and noted the credentials, we can integrate with Expel.
Register device in Expel Workbench
- In a new browser tab, log into https://workbench.expel.io.
- On the console page, navigate to Settings and click Security Devices.
- At the upper right of the page, select Add Security Device.
- Search for and select Endgame.
- For Name, type the hostname of the Elastic Endpoint Security device.
- For Location, type the geographic location of the appliance.
- For Username, type expel from Step 1.
- For Acknowledge alerts, type “y” to have Endgame alerts marked as “viewed” after Expel processes them.
- For Server address type the management/console IP address of the device to be connected through https. For example: https://127.0.0.1.
- For Password, enter the password used in Step 1.
- Click Save.
After a few minutes, refresh the Security Devices page and you see your device status reporting as Healthy, or if there is an issue, you see details of what the issue may be.
To check if alerts are coming through, navigate to Alerts on the console page. Click the icon in the upper right to switch to grid view, then check the list for device alerts.