In this article, you will learn how to integrate Cylance's endpoint protection platform (EPP) with Real-Time Coaching. Once you set up this integration, data from Cylance will be available under the Coaching tab in your KnowBe4 Security Awareness Training (SAT) console. This data can be viewed in Real-Time Coaching reports and used to create detection rules for Real-Time Coaching categories. For general information about Real-Time Coaching, see our overview article.
Set Up the Integration in Real-Time Coaching
Before you can set up this integration in your CylancePROTECT platform, you'll need to authorize the configuration and copy your organization key from Real-Time Coaching by following the steps below:
- Log in to your KnowBe4 SAT console.
- Navigate to Coaching > Setup > Security Vendor Integrations.
- Locate the Cylance vendor tile and select Configure.
- Select Authorize.
- In the pop-up window that opens, select OK.
- From the Organization Key section, copy your key and save it somewhere you can access later. You'll need this key to set up the integration in Cylance.
Set Up the Integration in Cylance
To set up the integration in your CylancePROTECT platform, follow the steps below:
- Log in to your CylancePROTECT platform using an Administrator role.
- Navigate to Settings > Application.
- Scroll down to the Integrations section of the page.
- Select the Syslog/SIEM check box. Selecting this check box will prompt Cylance to stream events to Real-Time Coaching.
-
Fill out the remaining fields. For more information, see the screenshot and list below:

- Event Types: Select all checkboxes except Audit Log.
- SIEM: Leave this field blank.
- Protocol: From the drop-down menu, select your preferred protocol.
-
TLS/SSL: Leave this check box unchecked to disable TLS/SSL.
Note:This field will only display if you selected TCP in the Protocol field. -
IP/Domain: Enter the domain for your KnowBe4 instance into the field. To find the domain for your KnowBe4 instance, see the table below:
KnowBe4 Instance Domain United States syslog.training.knowbe4.com European Union syslog.eu.knowbe4.com Canada syslog.ca.knowbe4.com Germany syslog.de.knowbe4.com United Kingdom syslog.uk.knowbe4.com - Port: Enter "4514".
- Severity: From the drop-down menu, select Notice (5).
- Facility: From the drop-down menu, select Internal (5).
- Custom Token: Enter "org_key=x,vendor_code_name=cylance,log_type=endpoint", then replace "x" with the organization key you saved earlier.
- Select Test Connection to confirm that Cylance is able to connect to Real-Time Coaching.
- Select SAVE.
Map Your Users
After you’ve finished integrating Cylance, we recommend mapping your users using mapping rules or by uploading a CSV file. For more information, see our user mapping article.
Manage Detection Rules
Once you’ve successfully authorized this integration, you can also manage Cylance detection rules from Coaching > Detection Rules. For a full list of available system detection rules for this vendor, see our System Detection Rules by Vendor article.
Delete the Integration in Real-Time Coaching
To delete the Cylance integration from Real-Time Coaching, follow the steps below:
- Log in to your KnowBe4 SAT console.
- Navigate to Coaching > Setup > Security Vendor Integrations.
- Locate the Cylance vendor tile and select Edit.
- Select Delete Integration near the bottom of the page.