ExtraHop
ExtraHop
The Dropzone AI Platform integrates with ExtraHop, a Network Detection and Response (NDR) platform that provides real-time, packet-level visibility across hybrid and multi-cloud environments.
Integration Overview
To enable these integrations you will perform the following actions:
Grant REST API Access
Locate your RevealX 360 API Endpoint
Generate RevealX 360 API Credentials
Enable the Alert source in your Dropzone AI tenant
Grant REST API Access
To grant REST API Access, do the following:
As a user with system and access administration privileges, log in to ExtraHop RevealX 360
In the top right of the page, navigate to System Settings > All Administration
Click "API Access"
In the Manage API Access section, click "Enable"
Locate your API Endpoint
In the API Access page of your RevealX360 account, locate your endpoint in the "API Endpoint" section. The hostname does not include the /oauth2/token.
Copy the value shown for use later in the Dropzone UI, where it is called "Hostname."
Create API Credentials
To create API Credentials, do the following:
As a user with system and access administration privileges, log in to ExtraHop RevealX 360
In the top right of the page, navigate to System Settings > All Administration
Click "API Access"
Click "Create Credentials"
Name the credentials something memorable, such as "Dropzone AI"
Grant the credentials the following privilege levels:
Full NDR Module Access
Full NPM Module Access
In the "Packet Access" section, do not enable packet retrieval
Click "Save"
Copy and save the ID and Secret values shown for use later in the Dropzone UI, where they are called "ID" and "Secret" respectively
Click "Done"
Enable ExtraHop
To enable the Alert Source integration, you will need the following information:
ID
The ID value you copied earlier
Secret
The Secret value you copied earlier
Hostname
The hostname of your ExtraHop API, e.g. example.api.cloud.extrahop.com
Navigate to your Dropzone AI tenant home page e.g. https://mycompany.dropzone.app
In the bottom left hand corner, navigate to Settings > Integrations

Click "Library"

In the Search bar, search ExtraHop, then click "Configure"

Under the Alert Source header, input the ID, Secret, and Hostname

Under "Detection filters," select which detection categories you want Dropzone to ingest. By default, all are selected
Check the box labeled "Recommended for triage" to limit your detections to those recommended for triage
Input your minimum risk score severity

Input your desired poll interval and lookback

If you wish to further filter alerts using the Python CEL package, check the box labeled "Use advanced filtering"
Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
Contact your Dropzone AI support representative for more information about this feature

Click "Test & Save" to finish
If you have any errors engage your Dropzone AI support representative.
Last updated
Was this helpful?