Configure Imprivata ITDR for Arctic Wolf monitoring

You can configure ® to send the necessary logs to Arctic Wolf® for security monitoring.

These resources are required:

  • An account with administrator permissions
  • One of these licenses:
    • An APA license for Enterprise Access Management (EAM)
    • An IADT license for Privileged Access Security (PAS)

Get the webhook token and URL

  1. Sign in to the Arctic Wolf Unified Portal.
  2. Klicken Sie im Navigationsmenü auf Datenerfassung > Cloud-Sensoren.
  3. Click Add Account +.
  4. On the Add Account page, click Imprivata ITDR.
  5. In the Name field, enter a unique and descriptive name for the account.
  6. Click Get credentials.
  7. Copy the webhook token and webhook URL, and then save them in a safe, encrypted location.

Configure a custom destination in Imprivata ITDR

  1. Sign in to https://app.verosint.com/ with administrator permissions.
  2. Go to Profile > Settings > Integrations > Custom Webhook, and then click Add or Edit.

    If a webhook is already configured, click Edit. If no webhook is configured, click Add.

  3. Configure these settings:
    • Webhook URL — Enter the webhook URL that you saved in Get the webhook token and URL.
    • Authorization Token — Enter the webhook token that you saved in Get the webhook token and URL using the format Bearer token_value.
    • HTTP method — Select POST.
    • Verify SSL — Turn on the toggle.
    • Threats and Rule Set Evaluations — Select both checkboxes.
  4. Optional: To test the webhook connection, click Test.

    A green pop-up message indicates the connection was successful. If a red pop-up message appears, regenerate the webhook URL and authorization token in Get the webhook token and URL, and then repeat this procedure.

  5. Click Save.