In this article, you will learn how to integrate Cylance's endpoint protection platform (EPP) with Real-Time Coaching. Once you set up this integration, data provided by Cylance will be available under the Coaching tab of your KSAT console. This data can be viewed in Real-Time Coaching reports and used to create detection rules for Real-Time Coaching categories. For general information about Real-Time Coaching, see our Real-Time Coaching Product Manual.
Copy Your Organization Key
Before you can set up this integration in your CylancePROTECT platform, you will need to authorize the configuration and copy your organization key from the Coaching tab of your KSAT console. You will need this key in the Set Up the Integration in Your CylancePROTECT Platform section below.To locate and copy your organization key, follow the steps below:
- Log in to your KSAT console and navigate to Coaching > Setup > Security Vendor Integrations.
- Locate Cylance and click Configure.
- Click Authorize.
- In the pop-up window that opens, click OK.
- In the Organization Key field, copy your key.
Set Up the Integration in Your CylancePROTECT Platform
Before you can set up this integration in your CylancePROTECT platform, you will need to authorize the configuration and copy your organization key from the Coaching tab of your KSAT console.To set up the integration in your KSAT console, follow the steps below:
-
Log in to your CylancePROTECT platform, and navigate to Settings > Application.
Important:You will need to log in as a user with an Administrator role. - Scroll down to the Integrations section of the page.
- Select the Syslog/SIEM check box. Selecting this check box will prompt Cylance to stream events to Real-Time Coaching.
-
Fill out the remaining fields. For more information, see the screenshot and list below:
- Event Types: Select all check boxes except for the >Audit Log check box.
- SIEM: Leave this field blank.
- Protocol: From the drop-down menu, select the protocol that you prefer.
-
TLS/SSL: Leave this check box unchecked to disable TLS/SSL.
Note:This field will only display if you selected TCP in the Protocol field. -
IP/Domain: Enter the domain for your KnowBe4 instance into the field. To find the domain for your KnowBe4 instance, see the table below:
KnowBe4 Instance Domain United States syslog.training.knowbe4.com European Union syslog.eu.knowbe4.com Canada syslog.ca.knowbe4.com Germany syslog.de.knowbe4.com United Kingdom syslog.uk.knowbe4.com - Port: Enter "4514" into the field.
- Severity: From the drop-down menu, select Notice (5).
- Facility: From the drop-down menu, select Internal (5).
- Custom Token: Enter "org_key=x,vendor_code_name=cylance,log_type=endpoint", but replace "x" with your organization key.
- Click Test Connection to confirm that Cylance is able to connect to Real-Time Coaching.
- Click SAVE.
Map Your Users
After you’ve finished integrating Cylance, you can map your users either through mapping rules (recommended) or through a CSV file upload. For more information about user mapping, see our Mapping Users in Real-Time Coaching article.
Once you’ve successfully completed this integration, you can manage detection rules for Cylance on the Detection Rules subtab of Real-Time Coaching. For a full list of available system detection rules for this vendor, see our Which Detection Rules Can I Use with My Vendors? article.
Delete the Integration in Your CylancePROTECT Platform
To delete the Cylance integration from your Real-Time Coaching platform, follow the steps below.
- Log in to your CylancePROTECT platform.
- Click the gear icon, and then click Application.
- Scroll down to the Integrations section of the page.
- Deselect the Syslog/SIEM check box.
