In this article, you'll learn how to integrate SonicWall Capture Client with Real-Time Coaching. Once you set up this integration, data from SonicWall will be available under the Coaching tab of your KnowBe4 Security Awareness Training (SAT) console. This data can be viewed in Real-Time Coaching reports and used to create detection rules for Real-Time Coaching categories. For general information about Real-Time Coaching, see our overview article.
Set Up the Integration in SonicWall
Before you can set up the integration in Real-Time Coaching, you'll need to create a SonicWall Capture Client admin account by following the steps below:
- Navigate to your SonicWall Capture Client console and select Login with MySonicWall.
- From the sidebar, navigate to Management > Administrators.
-
Select the + sign on the right to open the Administrators window.
- Enter the desired email, name, and password for your new admin account.
- Select Create.
Obtain Your SentinelOne API Key
To obtain your API key, create a support ticket from your SonicWall console and request your SentinelOne API key from the SonicWall support team.
Set Up the Integration in Real-Time Coaching
Once you've created your SonicWall Capture Client admin account and obtained your SentinelOne API key, you can set up the integration in Real-Time Coaching. To set up the integration, follow the steps below:
- Log in to your KnowBe4 SAT console.
- Navigate to Coaching > Setup > Security Vendor Integrations.
- Locate the SonicWall Capture Client vendor tile and select Configure.
- In the User Name field, enter the email address of the admin account you created earlier.
- In the Password field, enter the password of the admin account you created earlier.
- In the URL field, enter your SonicWall Capture Client console URL. Your SonicWall Capture Client console URL will be similar to "https://captureclient-01.sonicwall.com".
- In the API Key field, enter your SentinelOne API key.
- Select Authorize.
Map Your Users
After you've finished integrating SonicWall Capture Client, you can map your users either through mapping rules (recommended) or through a CSV file upload. For more information about user mapping, see our user mapping article.
Manage Detection Rules
Once you've successfully authorized this integration, you can also manage SonicWall Capture Client detection rules from Coaching > Detection Rules. For a full list of available system detection rules for this vendor, see our System Detection Rules by Vendor article.
Delete the Integration in Real-Time Coaching
If you want to delete the SonicWall Capture Client integration from Real-Time Coaching, follow these steps:
- Log in to your KnowBe4 SAT console.
- Navigate to Coaching > Setup > Security Vendor Integrations.
- Locate the SonicWall Capture Client vendor tile and select Edit.
- Select Delete Integration near the bottom of the page.
