This article explains how to connect DEVO to Workbench.
Quick Start
Step 1: Enable console access
This procedure creates a user account for Expel that keeps Expel activity separate from other activity on the DEVO console.
Note
Expel secures all login information our SOC analysts need about your devices in an MFA password product. Access to this login information is protected using our internal MFA processes. To learn more about the IP addresses all Expel traffic comes from, go here.
-
Navigate to Administration > Users and select ADD USER at the upper right of the page.
-
For E-mail type, enter soc+<Your_Organization_Name>@expel.io.
Note
Yes, the "+" sign is part of the email address, and it's important. Click here to find out why. -
For Username, enter soc@expel.io.
-
For Role, select Administrator.
-
Click Save.
Step 2: Enable API Access for Expel
This procedure creates an authentication token that allows access to the DEVO API.
Having read-only access to the interface of your technology allows Expel to dig deeper during incident investigations. Our device health team uses this access to investigate potential health issues with your tech.
-
Navigate to Administration > Credentials and select CREATE NEW API KEY at the upper right of the page.
-
Make note of the newly generated API Key and API Secret.
Step 3: Configure DEVO in Workbench
Now that we have the correct access configured and noted the credentials, we can integrate your tech with Workbench.
-
In a new browser tab, login to https://workbench.expel.io.
-
On the console page, navigate to Settings and click Security Devices.
-
At the top right of the page, click Add Security Device.
-
Search for and select DEVO.
-
Type a Name for the DEVO device.
-
For Location type, enter the geographic location of the appliance.
-
For Server Address, type your DEVO Web URL address (for example, https://apiv2-us.devo.com/).
-
Type the API Key and API Secret generated in Step 2.
-
Select Save.
-
You can provide console access now or set it up later. Use the instructions below to set it up later.
You can see if the device is healthy on the Security Devices page. It may take a few minutes to see the device listed as healthy.
To check if alerts are coming through, navigate to the Alerts Analysis page. Scroll to the device you want to check and click View alerts. Switch to grid view, then check the list for device alerts. It can take 36 to 72 hours for alerts to appear after setup, as we tune your device.
Step 4: Edit the device to add console access
Expel needs console access to your device to allow our SOC analysts to dig deeper during incident investigations. Additionally, our engineering teams use this access to investigate potential health issues, including proper alert ingestion.
Note
Expel secures all login information our SOC analysts need about your devices in an MFA password product. Access to this login information is protected using our internal MFA processes. To learn more about the IP addresses all Expel traffic comes from, go here.
-
Open Workbench. Go to Organization Settings > Security Devices. Next to the device you just connected, select the down arrow and select Edit.
-
In the Console Login area, type these details:
-
Console URL - type the console URL from the Server address in the Connection Settings area above. At the end of the URL, type /login.
-
Username - type the user name you created above.
-
Password - type the password you created above.
-
Two-factor secret key (32-character code) - depending on how your organization enforces log-ins, this field may not apply to you. In these cases, you can leave it blank. This field is optional, and if you have questions or concerns, reach out to your engagement manager or to support.
-
- Click Save.
Note
This article was accurate at the time of writing, but changes happen. If you find the instructions are outdated, leave a description in the comment field below and let us know!