Exabeam is currently migrating all users from Exabeam Fusion SIEM to Exabeam Fusion New-Scale SIEM.

For the New-Scale SIEM version of this article, refer to Exabeam Fusion New-Scale SIEM setup for Workbench.

This article explains how to connect Exabeam Fusion SIEM to Workbench.

Step 1: Enable console access

The Exabeam Security Management Platform uniquely combines a data lake for unlimited data collection, machine learning for advanced analytics, and automated incident response into an integrated set of products. The SOC analysts requires a dedicated user account, which allows us to respond to security alerts and leverage the data available in Exabeam Fusion SIEM.


Expel secures all login information our SOC analysts need about your devices in an MFA password product. Access to this login information is protected using our internal MFA processes. To learn more about the IP addresses all Expel traffic comes from, go here.

  1. At the bottom of the homepage, navigate to Exabeam Admin Operations.

  2. Under the Exabeam User Management section select Users.

  3. Type the following information for the fields:

    Field Name

    What to put in it

    User Type




    Full Name

    Expel SOC


    This optional field can be left blank.


    Type a password. Save the password to enter later in the Workbench.

  4. For Role, select Tier 3 Analyst. If a custom role is preferred, complete the next 2 steps. Note the permission requirements. If you don't need a custom role, skip to Step 2 below.

  5. For a custom role, type Expel for Role Name and Expel Custom Role for Description.

  6. Select Advanced Analytics, and choose the following permissions:


    View Activities


    View Executive Info


    View Global Insights


    View Infographics


    View Insights


    View Rules


    Edit and Approve

    Approve Lockouts

    Optional but recommended

    Accept Sessions

    Optional but recommended

    Manage Rules

    Optional but recommended

    Manage Watchlist

    Optional but recommended


    Manage Search Library

    Optional but recommended

    Basic Search


    Threat Hunting


    View Search Library


Step 2: Generate API credentials

  1. Navigate to Settings > Admin Operations > Cluster Authentication Token.

  2. On the Cluster Authentication Token menu, click + to add a new token.

  3. In the Setup Token dialog box, fill in the Token Name, set Expiry Date to Permanent, and set the Permission Level(s) as Tier 3 Analyst.

  4. Copy the generated token for use in the next step.

Step 3: Configure the technology in Workbench

  1. Go to

  2. Complete all fields using the credentials and information you collected in Steps 1 and 2:

    • (On-prem only) Select an Assembler from the list. If you have an assembler, select the assembler you set up in Getting Connected to Workbench.

    • Type Name (give your Exabeam a name).

    • Type the city or site where your Exabeam is located for Location.

    • Under Connection Settings, for Token type the token you generated in Step 2 and for Server Address type the IP address for Exabeam.

    • For Username and Password, use the information you created in Step 1.

  3. You can provide console access now or set it up later. Use the instructions below to set it up later.


This page was accurate at the time of writing, but changes happen. If you find the instructions are outdated, let us know via your engagement manager or account representative.