This article explains how to connect CylancePROTECT AV to Workbench.
Step 1: Enable console access
Note
Expel secures all login information our SOC analysts need about your devices in a MFA password product. Access to this login information is protected using our internal MFA processes. To learn more about the IP addresses all Expel traffic comes from, go here.
-
Log in to the CylancePROTECT AV Console as an administrator.
-
Click Settings > Users.
-
Add a user for Expel with a Read-Only role.
Step 2: Generate API credentials
-
Log in to the CylancePROTECT AV Console as an administrator. Only administrators can create an application integration.
-
Select Settings > Integrations.
-
Click Add Application.
-
Type an Application Name. This must be unique within your organization.
-
Select Threats READ, Devices READ, and Users READ privileges.
-
Click Save. The application credentials appears.
-
Copy the Tenant ID located in the Integrations page and save for onboarding in Workbench.
-
Note your Cylance Service Endpoint. This can be found by mapping your CylancePROTECT AV in the table below. For example:
https://protect-euc1.cylance.com is https://protectapi-euc1.cylance.com
URL
Service endpoint
https://protect-apne1.cylance.com
https://protectapi-apne1.cylance.com
https://protect-euc1.cylance.com
https://protectapi-euc1.cylance.com
https://protect-au.cylance.com
https://protectapi-au.cylance.com
https://protect-sae1.cylance.com
https://protectapi-sae1.cylance.com
https://protect.us.cylance.com
https://protectapi.us.cylance.com
https://protect.cylance.com
https://protectapi.cylance.com
Step 3: Configure the technology in Workbench
-
In a new browser tab, login to https://workbench.expel.io.
-
On the console page, navigate to Settings and click Security Devices.
-
At the top of the page, click Add Security Device.
-
Search for and select CylancePROTECT AV.
-
For Name type the hostname of the CylancePROTECT AV device.
-
Location type the geographic location of the appliance.
-
Tenant ID type the Tenant ID generated in Step 2.
-
Application ID type the Application ID generated in Step 2.
-
Application secret type the application secret generated in Step 2.
-
Service Endpoint type your correct Service Endpoint from the table in Step 2.
-
-
You can provide console access now or set it up later. Use the instructions below to set it up later.
Comments
0 comments
Please sign in to leave a comment.