Step 1: Enable console access
Having read-only access to the interface of your technology allows Expel to dig deeper when performing incident investigations. Our device health team uses this access to investigate potential health issues with your tech.
- Log in to the Cylance Console as an administrator.
- Click Settings > Users.
- Add a user for Expel with a Read Only role.
Step 2: Generate API credentials
To integrate the technology with Expel, we need to create secure credentials to the API. Depending on the permissions allowed in Step 1, Expel may be able to generate API credentials. If you're unsure, reach out to your Expel Customer Success Engineer, or email email@example.com.
- Log in to the Cylance Console as an administrator. Only administrators can create an application integration.
- Select Settings > Integrations.
- Click Add Application.
- Type an Application Name. This must be unique within your organization.
- Select Threats READ, Devices READ, and Users READ privileges.
- Click Save. The application credentials appears.
- Copy the Tenant ID located in the Integrations page and save for onboarding in Expel Workbench.
- Note your Cylance Service Endpoint. This can be found by mapping your Cylance in the table below. For example: https://protect-euc1.cylance.com is https://protectapi-euc1.cylance.com
URL Service Endpoint
Step 3: Configure the technology in Workbench
Now that we have the correct access configured and noted the credentials, we can integrate CylancePROTECT (AV) with Expel Workbench.
Register device in Expel Workbench
- In a new browser tab, login to https://workbench.expel.io.
- On the console page, navigate to Settings and click Security Devices.
- At the top right of the page, select Add Security Device.
- Search for and select CylancePROTECT AV.
- For Name type the hostname of the Cylance device.
- Location type the geographic location of the appliance.
- Tenant ID type the Tenant ID generated in Step 2.
- Application ID type the Application ID generated in Step 2.
- Application secret type the application secret generated in Step 2.
- Service Endpoint type your correct Service Endpoint from the table in Step 2.
- Click Save.
After a few minutes, refresh the Security Devices page and you see your device status reporting as Healthy, or if there is an issue, you see details of what the issue may be.
To check if alerts are coming through, navigate to Alerts on the console page. Click the icon in the upper right to switch to grid view, then check the list for device alerts.