Skip to main content
 

Tip

This article was accurate at the time of writing, but changes happen. If you find the instructions are outdated, leave a description in the comment field below and let us know!

Step 1: Enable console access

This procedure creates a user account for Expel that keeps the Expel activity separate from other activity on the VMware Carbon Black Defense console.

Create an analyst account

  1. Navigate to gear icon on left side and click Users. Then click Add User on the top right of the screen.

    Screen Shot 2021-03-05 at 8.30.39 AM.png
  2. For First name type Expel.

    Screen Shot 2021-03-05 at 8.31.15 AM.png
    • For Last name type SOC.

    • For Email: soc+<Your_Organization_Name>@expel.io.

      Tip

      Yes, the "+" sign is part of the email address (as in soc+megacorp@expel.io) and it's important. Click here to find out why.

    • For Role select Level 2 Analyst.

Step 2: Generate API credentials and SIEM access

This procedure creates an authentication token that allows the Expel Assembler to access the VMware Carbon Black Defense API and SIEM.

Obtain the API and SIEM key for the Expel account

  1. Navigate to gear icon on left side and click Users. Then click Add User on the top right of the screen.

    Screen Shot 2021-03-05 at 8.30.39 AM.png
  2. For Name type Expel.

    Screen Shot 2021-03-30 at 7.48.06 AM.png
    • For Access Level select API.

    • For Authorized IP address, type the IP address of the externally facing IP of the Expel Assembler. If you're unsure, the following code can be run on the Assembler to list the current IP: curl -s http://ipchicken.com | egrep -o ‘([[:digit:]]{1,3}\.){3}[[:digit:]]{1,3}’

  3. For SIEM access, follow the same steps above and select SIEM for Access level.

  4. Make note of the API, SIEM API, and API IDs for each. These are used in Step 3 for registration within Workbench.

Subscribe to notifications

  1. Navigate to the gear icon on the left side, click Notifications, then click ADD NOTIFICATION.

  2. For Name type Expel Threat.

    Screen Shot 2021-03-30 at 7.48.39 AM.png
  3. For Notify when select Threat and select Alert priority 3.

  4. For Policy select All Policies.

  5. Click in Search for API field and search for the SIEM API Key created for Expel in Obtain the API and SIEM key for the Expel account.

Step 3: Configure the technology in Workbench

  1. In a new browser tab, login to https://workbench.expel.io.

  2. On the console page, navigate to Settings and click Security Devices.

  3. At the upper right of the page, select Add Security Device.

  4. Search for and select VMware Carbon Black Defense.

    Screen Shot 2021-03-30 at 7.49.10 AM.png
  5. Complete all fields using the credentials and information you collected in Step 1 and Step 2.

    Screen Shot 2021-03-30 at 7.49.42 AM.png
  6. Select an Assembler from the list. Select the assembler you set up in Getting Connected to Expel Workbench.

  7. Type Assembler Name and Location. For example: VMware Carbon Black Defense and Expel Lab.

    Screen Shot 2021-03-30 at 7.50.15 AM.png
    • For Server address type the URL for the VMware Carbon Black Defense server, including the port.

    • For SIEM key, type the SIEM API Key generated in Step 2.

    • For API connect, type API ID generated in Step 2.

    • For SIEM connect, type the SIEM API ID generated in Step 2.

    • For API key type the API generated in Step 2.

    • Username and Password fields are optional and can be left blank.