Connecting the Expel Workbench to a Varonis installation requires a Varonis domain user account with access to DatAlerts. The first step is to configure the account with the proper roles. After that's complete, you can connect Varonis to Workbench and test the connection.
Step 1: Create and configure Varonis domain user account
- In Varonis, create a domain user account. Make a note of the username and password on the account for later reference.
- Navigate the Varonis management console > Configuration > Security.
- Assign the domain user the following roles:
- Alerts View User
- Directory Services Trends View User
- File System Trends View User
- Log View User
- Reports View User
- Web UI User
Step 2: Configure the technology in Workbench
Now that we have the correct access configured and noted the credentials, we can integrate Varonis with Expel.
- In a new browser tab, log into https://workbench.expel.io.
- On the console page, navigate to Settings and click Security Devices.
- At the top right of the page, select Add Security Device.
- Search for and select Varonis.
- Select an Assembler from the list. Select the assembler you set up in Step 2 of the Getting Started with Expel guide.
- Type Assembler Name and Location. For example: Varonis and Expel Lab.
- For URL type the Varonis instance URL.
- For API username and API password type the credentials created in Step 1.
- (Optional) For Verify tls type y or n. Note: Type y to verify your server's TLS certificates.
- (Optional) For Console Login type the credentials created in Step 1.
- Click Save.
After a few minutes, refresh the Security Devices page and you see your device status reporting as Healthy, or if there is an issue, you see details of what the issue may be.
To check if alerts are coming through, navigate to Alerts on the console page. Click the icon in the upper right to switch to grid view, then check the list for device alerts.