For the complete documentation index, see llms.txt. This page is also available as Markdown.

ExtraHop

ExtraHop

The Dropzone AI Platform integrates with ExtraHop, a Network Detection and Response (NDR) platform that provides real-time, packet-level visibility across hybrid and multi-cloud environments.

Integration Overview

To enable these integrations you will perform the following actions:

  • Grant REST API Access

  • Locate your RevealX 360 API Endpoint

  • Generate RevealX 360 API Credentials

  • Enable the Alert source in your Dropzone AI tenant

Grant REST API Access

To grant REST API Access, do the following:

  • As a user with system and access administration privileges, log in to ExtraHop RevealX 360

  • In the top right of the page, navigate to System Settings > All Administration

  • Click "API Access"

  • In the Manage API Access section, click "Enable"

Locate your API Endpoint

In the API Access page of your RevealX360 account, locate your endpoint in the "API Endpoint" section. The hostname does not include the /oauth2/token.

Copy the value shown for use later in the Dropzone UI, where it is called "Hostname."

Create API Credentials

To create API Credentials, do the following:

  • As a user with system and access administration privileges, log in to ExtraHop RevealX 360

  • In the top right of the page, navigate to System Settings > All Administration

  • Click "API Access"

  • Click "Create Credentials"

  • Name the credentials something memorable, such as "Dropzone AI"

  • Grant the credentials the following privilege levels:

Full NPM Module Access is only required if you wish to ingest performance detections as an alert source.

  • In the "Packet Access" section, do not enable packet retrieval

  • Click "Save"

  • Copy and save the ID and Secret values shown for use later in the Dropzone UI, where they are called "ID" and "Secret" respectively

  • Click "Done"

Enable ExtraHop

To enable the Alert Source integration, you will need the following information:

Dropzone Field
Source

ID

The ID value you copied earlier

Secret

The Secret value you copied earlier

Hostname

The hostname of your ExtraHop API, e.g. example.api.cloud.extrahop.com

  • Navigate to your Dropzone AI tenant home page e.g. https://mycompany.dropzone.app

  • In the bottom left hand corner, navigate to Settings > Integrations

Integrations Dropdown
  • Click "Library"

If you have previously integrated this application, click "Configured"

Click Library
  • In the Search bar, search ExtraHop, then click "Configure"

The ExtraHop tile
  • Under the Alert Source header, input the ID, Secret, and Hostname

The ExtraHop Alert Source Configuration (pt 1)
The ExtraHop Alert Source Configuration (pt 2)
  • Input your desired poll interval and lookback

The ExtraHop Alert Source Configuration (pt 3)
  • If you wish to further filter alerts using the Python CEL package, check the box labeled "Use advanced filtering"

  • Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button

  • Contact your Dropzone AI support representative for more information about this feature

The ExtraHop Alert Source Configuration (pt 4)
  • Click "Test & Save" to finish

If you have any errors engage your Dropzone AI support representative.

Last updated

Was this helpful?