Configure ExtraHop RevealX 360 for Arctic Wolf monitoring

You can configure ® to send the necessary logs to Arctic Wolf® for security monitoring.

These resources are required:

  • Administrator permissions for
  • An active license for the NDR (Network Detection and Response) module
  • Optional: A cloud-based record store with a Premium Investigation subscription

Generate ExtraHop RevealX 360 API credentials

  1. Sign in to .
  2. Click the System Settings icon.
  3. Under Administration, click API Access.
  4. In the Manage API access section, ensure the Access to REST API status is enabled.
  5. In the REST API Credentials section, click Create Credentials.
  6. In the Create REST API Credentials window, configure these settings:
    • Name — Enter a unique and descriptive name for the integration.
    • System Access — Select one of these options:
      • System and access administration (recommended)
      • Restricted read-only — Select this option if you do not want Arctic Wolf to have admin access. Arctic Wolf will not be able to monitor audit logs.
    • NDR Module Access — Select Full access. This is required for Arctic Wolf to monitor detection logs and network records.
    • NPM Module Access — Select No access.
    • Packet and Session Key Access — Select No access.
  7. Click Save.
  8. Copy the API Endpoint, ID, and Secret values, and then save them in a safe, encrypted location.
  9. Click Done.

Provide ExtraHop RevealX 360 credentials to Arctic Wolf

  1. Sign in to the Arctic Wolf Unified Portal.
  2. Klicken Sie im Navigationsmenü auf Datenerfassung > Cloud-Sensoren.
  3. Click Add Account +.
  4. On the Add Account page, click ExtraHop RevealX 360.
  5. Configure these settings:
  6. Click Test and submit credentials.