Integrate Reveal(x) 360 with Cortex XSOAR
This integration enables you to export Reveal(x) 360 detections to Cortex XSOAR and run response playbooks, as well as query Reveal(x) 360 packets and device activity.
To configure this integration, you must create Cortex XSOAR credentials and then add those credentials when you configure the ExtraHop Reveal(x) integration for Cortex XSOAR.
System requirements
ExtraHop Reveal(x) 360
- Your user account must have privileges on Reveal(x) 360 for System and Access Administration.
- Your Reveal(x) 360 system must be connected to an ExtraHop sensor with firmware version 9.2 or later.
- Your Reveal(x) 360 system must be connected to ExtraHop Cloud Services.
Cortex XSOAR
- You must have Cortex XSOAR version 6.5 or later.
- You must have the following Cortex XSOAR content packs:
- Base version 1.31.62 or later
- Common Playbooks version 2.2.4 or later
- Common Scripts version 1.11.22 or later
- Filters and Transformers version 1.0.2 or later
- CVE Search version 1.0.14 or later
Create Cortex XSOAR integration credentials
The credential is also added to the ExtraHop REST API Credentials page
where you can view the credential status, copy the ID, or delete the
credential.
Thank you for your feedback. Can we contact you to ask follow up questions?