Configure Claroty xDome for Arctic Wolf monitoring

You can configure Claroty xDome for Healthcare Environments® and Claroty xDome for Industrial Environments® to send the necessary logs to Arctic Wolf® for security monitoring.

CAUTION: Make sure that PII, PHI, and other sensitive information are not included in the data ingested through this integration unless explicitly required and authorized. Validate all data sources and configurations to ensure compliance with applicable privacy and regulatory requirements.

These resources are required:

  • Administrator permissions for Claroty xDome

Create an API user and token

  1. Sign in to Claroty xDome.
  2. In the navigation menu, click Settings > Admin Settings.
  3. Click Add User.
  4. In the Create User dialog, configure these settings:
    • User Type — Select API User.
    • Username — Enter a unique name.
    • Site Permissions — Click Edit Site Permissions, select the sites to monitor that meet the regulatory requirements for your organization, and then click Apply.

      CAUTION: Selecting including future sites and groups automatically monitors all sites created in the future.
    • Roles — Select Read-Only Admin.
  5. Click Create User.
  6. In the user list, click Generate Token for the new user.
  7. Select a token expiration date, and then click Generate.
  8. Copy the API Token, and then save it in a safe, encrypted location.

Provide Claroty xDome credentials to Arctic Wolf

Note:

Time-based events are polled with a delay to make sure that data is available. If API credentials fail, for example due to expired credentials, Arctic Wolf notifies you and requests a new set of credentials. Provide refreshed credentials promptly to ensure complete data polling and coverage.

  1. Sign in to the Arctic Wolf Unified Portal.
  2. In the navigation menu, click Data Collection > Cloud Sensors.
  3. Click Add Account +.
  4. On the Add Account page, click Claroty xDome for Healthcare Environments or Claroty xDome for Industrial Environments.
  5. Configure these settings:
    • Account Name — Enter a unique and descriptive name for the account.

    • API Host — In the list, select the regional API host that meets your organization's data residency requirements.
    • API Token — Enter the API token that you saved in Create an API user and token.
    • Credential Expiry — Enter the credential expiration date, if applicable.

  6. Click Test and submit credentials.