Configure ExtraHop RevealX 360 for Arctic Wolf monitoring

You can configure ExtraHop RevealX 360® to send the necessary logs to Arctic Wolf® for security monitoring.

These resources are required:

  • Administrator permissions for ExtraHop RevealX 360
  • An active license for the NDR (Network Detection and Response) module
  • Optional: A cloud-based record store with a Premium Investigation subscription

Generate ExtraHop RevealX 360 API credentials

  1. Sign in to ExtraHop RevealX 360.
  2. Click the System Settings icon.
  3. Under Administration, click API Access.
  4. In the Manage API access section, ensure the Access to REST API status is enabled.
  5. In the REST API Credentials section, click Create Credentials.
  6. In the Create REST API Credentials window, configure these settings:
    • Name — Enter a unique and descriptive name for the integration.
    • System Access — Select one of these options:
      • System and access administration (recommended)
      • Restricted read-only — Select this option if you do not want Arctic Wolf to have admin access. Arctic Wolf will not be able to monitor audit logs.
    • NDR Module Access — Select Full access. This is required for Arctic Wolf to monitor detection logs and network records.
    • NPM Module Access — Select No access.
    • Packet and Session Key Access — Select No access.
  7. Click Save.
  8. Copy the API Endpoint, ID, and Secret values, and then save them in a safe, encrypted location.
  9. Click Done.

Provide ExtraHop RevealX 360 credentials to Arctic Wolf

  1. Sign in to the Arctic Wolf Unified Portal.
  2. In the navigation menu, click Data Collection > Cloud Sensors.
  3. Click Add Account +.
  4. On the Add Account page, click ExtraHop RevealX 360.
  5. Configure these settings:
  6. Click Test and submit credentials.