Connecting the Expel Workbench to a Varonis installation requires a Varonis domain user account with access to DatAlerts. The first step is to configure the account with the proper roles. After that's complete, you can connect Varonis to Workbench and test the connection.
Step 1: Create and configure Varonis domain user account
-
In Varonis, create a domain user account. Make a note of the username and password on the account for later reference.
-
Navigate to the Varonis management console > Configuration > Security.
-
Assign the domain user the following roles:
-
Alerts View User
-
Directory Services Trends View User
-
File System Trends View User
-
Log View User
-
Reports View User
-
User
-
Web UI User
-
Step 2: Configure the technology in Workbench
-
In a new browser tab, log into https://workbench.expel.io.
-
On the console page, navigate to Settings and click Security Devices.
-
At the top of the page, click Add Security Device.
-
Search for and select Varonis.
-
Select an Assembler from the list. Select the assembler you set up in Getting connected to Expel Workbench.
-
Type Assembler Name and Location. For example: Varonis and Expel Lab.
-
For API username and API password, type the credentials created in Step 1.
-
For URL, type the Varonis instance URL.
-
(Optional) For Verify tls, type y or n.
Note
Type y to verify your server's TLS certificates.
-
- Click Save.
-
You can set up console access now or use the instructions below to set it up later.
Step 3: Edit the device to add console access
Expel needs console access to your device to allow our SOC analysts to dig deeper during incident investigations. Additionally, our engineering teams use this access to investigate potential health issues, including proper alert ingestion.
Note
Expel secures all login information our SOC analysts need about your devices in a MFA password product. Access to this login information is protected using our internal MFA processes. To learn more about the IP addresses all Expel traffic comes from, go here.
-
Open Workbench. Go to Organization Settings > Security Devices. Next to the device you just connected, click the down arrow and click Edit.
-
In the Console Login area, type these details:
-
Console URL: type the console URL from the Server address in the Connection Settings area above. At the end of the URL, type /login.
-
Username: type the user name you created above.
-
Password: type the password you created above.
-
Two-factor secret key (32-character code): depending on how your organization enforces log-ins, this field may not apply to you. In these cases, you can leave it blank. This field is optional and if you have questions or concerns, reach out to your engagement manager or to support.
-
- Click Save.