You can configure Mimecast® to send the necessary logs to Arctic Wolf® for security monitoring.
Note: If you are migrating from Mimecast API version 1.0 to 2.0, complete the steps in Delete the Arctic Wolf API 1.0 application after configuring the new application.
These resources are required:
A Mimecast plan with a Targeted Threat Protection (TTP) license
Tip: If the New Menu toggle is enabled, navigate to Account > Admin Roles.
Click New Role, and then in the Properties section, configure these settings:
Role Name — Enter a unique name for the role. For example, Arctic Wolf App Role.
Description — Enter a description for the role.
In the Application Permissions section, clear all of the checkboxes.
Select these checkboxes:
Account Menu > Logs > Read
Monitoring Menu > Attachment Protection > Read
Monitoring Menu > Impersonation Protection Logs > Read
Monitoring Menu > URL Protection > Read
Click Save and Exit.
Create the API application
Note:
Based on your cloud firewall settings, add firewall exceptions for Arctic Wolf IP addresses if necessary. To see all the IP addresses that you must allowlist, sign in to the Arctic Wolf Unified Portal, click Resources > Allowlist Requirements, and then view the IP addresses in the section for your product.
Description — Enter a description for the API application.
Click Next.
On the Add Mimecast API 2.0 Application page, in the Notifications section, configure these settings:
Technical Point of Contact — Enter the name of the person who Mimecast should contact if necessary. For example, the active user configuring the API application.
Email — Enter the email address of the technical point of contact. This email address must be valid in your Mimecast directory.
Click Next.
Click Add and Generate Keys.
In the Manage API 2.0 Credentials for <application_name> dialog, copy the Client ID and Client Secret values, and then paste them in a safe, encrypted location. You will provide them to Arctic Wolf later.
Note:
This is the only time the client secret value is available.
Optional: Set admin IP address ranges:
Note:
You must set admin IP address ranges to apply IP address restrictions. For example, a public IP address range.
In the Administration menu, click Account > Account Settings.
In the User Access and Permissions tab, in the Admin IP Ranges field, enter the IP addresses.
CAUTION:
Do not only enter Arctic Wolf IP addresses. This restricts sign in permissions for all other accounts except for managed service providers.
Provide Mimecast credentials to Arctic Wolf
Note:
Time-based events are polled with a delay to make sure that data is available. For new deployments, Arctic Wolf begins polling and reviewing activity from approximately one hour prior to configuration success. If API credentials fail, for example due to expired credentials, Arctic Wolf notifies you and requests a new set of credentials. After receiving refreshed credentials, Arctic Wolf can only retrieve data from the previous 12 hours. Provide refreshed credentials within 12 hours of expiry to enable complete data polling and coverage.