Select the action you wish to take and jump to the relevant section:
- Create Integration
- View Integrations
- View Integration Configuration
- Integration Status
- Delete Integration
If you are new to integrations you should review Integrations Overview
Create Integration
- From your Samurai XDR application tenant select Telemetry > Integrations from the main menu
- Click Create
- The Create Integrations widget is displayed, select the product you wish to integrate with Samurai XDR
- Click Next. Dependent on how we collect telemetry, the product may be integrated via a Cloud Collector or Local Collector. Follow the steps based on the Collector type:
Cloud Collector
- If the integration is cloud-based it will be added to the Cloud Collector which shall be displayed - Select Next
- Select Configuration Guide which will direct you to the Help Center article outlining how to configure your product and obtain required fields.
- Once you have configured your product, complete the required fields
- Select Finish
Local Collector
- Your Local Collector(s) will be listed. Select the Local Collector that you will integrate the product with
- Click Next (typically this is the syslog destination host when configuring your device). If you do not have a Local Collector setup and deployed, select Create Collector and follow the steps in our Samurai XDR Local Collector article.
- The Local Collector IP Address will be displayed, copy the IP address or take note of it
- Click Configuration Guide which will direct you to the Help Center article outlining how to configure your product.
- Based on the product, Extended Telemetry Collection may be displayed, if so jump to Extended Telemetry Collection
- Click Finish
You do not need to follow the steps above for a Local Collector integration, however we advise you follow the steps to determine if extended telemetry collection is available for the product, and if you wish to enable it. You may choose to follow our configuration guides to send logs directly to your Local Collector, Samurai XDR will auto detect the vendor and product for supported integrations. If we do not support the product, your integration will be displayed as 'unknown' under the Vendor and Product fields, however Samurai XDR will store the telemetry data.
Extended Telemetry Collection
For many products we are able to collect extended telemetry enhancing our threat detection capabilities and accuracy, for example Packet Capture (PCAP) data. This option will be displayed during configuration of an integration.
- If extended telemetry collection is available for the product, you can choose to enable or disable via the toggle. If you choose to disable, Select Finish
- If you choose to enable extended telemetry collection you must complete all the necessary fields. The parameters for each field are derived from following the associated product configuration guide. Once complete, Select Finish.
You can choose to follow the configuration guide at anytime during the process, however if your product is not configured, Samurai XDR will obviously not receive any telemetry.
All third-party product configuration guides can be found on the Samurai Help Center
View Integration
There are multiple methods of viewing your integrations.
If you wish to view integrations associated with a specific collector:
- From your Samurai XDR application tenant select Telemetry > Collectors
- Select
(expand) next to the corresponding collector
- Your integrated telemetry sources will be listed with associated information
- Alternatively at step 2. select the name of your collector and you will be shown a summary of all integrations associated with the collector which includes Status.
You can also view all integrations regardless of collector:
- Select Telemetry > Integrations in the main menu
- All of your Integrations will be listed
A single product integration may be displayed multiple times based on telemetry data ingested. For example, if you enabled Extended Telemetry Collection whilst creating an integration the individual product will be displayed multiple times with different Type fields associated - see below for further explanation.
What are all the Integration fields?
- Vendor: vendor name of the product
- Product: product name
- Type: integration type used to gather or ingest telemetry. Potential entries you could see here include:
- Log: displayed when a telemetry source sends logs (typically via syslog).
- Local: displayed when we leverage an API from the local collector to gather telemetry
- Cloud: displayed when we leverage an API from a Samurai XDR cloud collector to gather telemetry
- Name: integration name you provided during configuration
- Collector: the collector name associated with the integration
- Hostname: hostname of the integrated telemetry source derived from the logs
- Description: an optional description you provided during integration configuration
- Last Event Seen: the last event seen from the telemetry source in the format [yyyy:mm:dd], [hh:mm:ss] with time represented in Universal Time Coordinated (UTC).
- Created: date and time of integration creation in the format [yyyy:mm:dd], [hh:mm:ss] with time represented in Universal Time Coordinated (UTC).
View Integration Configuration
There are multiple methods of viewing your integration configuration. If you wish to view integration configuration associated with a specific Collector:
- From your Samurai XDR application select Telemetry > Collectors
- Select the relevant collector for your list
- You will now see all integrations associated with the collector
- On the right hand side of the relevant integration, click on
(more options) and select View Configuration
- You will now see all configuration parameters for that integration
You can also view all integration configuration regardless of collector:
- Selecting Telemetry > Integrations in the main menu on the left of the screen
- Find your integrated product
- Select View Configuration by clicking on
(more options)
View Integration Status
There are multiple methods of viewing your Integration status.
If you wish to view integration status associated with a specific Collector:
- From your Samurai XDR application select Telemetry > Collectors
- Select the relevant collector from your list
- All integrations listed related to the collector will be displayed alongside a summary of Healthy and Not Healthy integrations
You can also view status of all integrations regardless of collector:
- From your Samurai XDR application select Telemetry > Integrations
- All integrations shall be displayed with a status color.
Potential status displayed are included in the table below:
Status |
Description |
---|---|
Not Available | Unsuccessful or failed |
Not-Healthy | One of more components unhealthy |
Healthy | All components healthy |
Provisioning | Telemetry components installing / provisioning |
For more information about Integration status, please see the article on how to manage Integration Health.
Delete Integration
If you delete an integration, it cannot be reversed! however events from the telemetry source will remain within Samurai XDR. However if the integration is auto-detected, it will reappear as type log if your telemetry source remains sending logs.
If you wish to delete an integration associated with a specific Collector:
- From your Samurai XDR application select Telemetry > Collectors
- Select the relevant collector from your list
- You will now see all integrations associated with the collector
- On the right hand side of the relevant integration, click on
(more options) and select Delete Integration
- The following warning will appear: 'Warning: This is a destructive action and cannot be reversed.'. To ensure you intended to delete the integration you will need to type in the highlighted 'Integration's Hostname' and select Delete Integration
You can also complete delete configuration from the Integrations menu item:
- Select Telemetry > Integrations in the main menu
- Find your integrated product
- Select Delete Configuration by clicking on
(more options)
- See step 5 above!
Comments
0 comments
Article is closed for comments.