Integrate RevealX 360 with Cisco XDR
Integrate ExtraHop RevealX 360 with Cisco XDR, a cloud-based detection and response tool, to enhance endpoint visibility and accelerate detection response. By creating ExtraHop REST API credentials, you can export RevealX device and detection data to Cisco XDR through ExtraHop REST API operations.
Before you begin
You must meet the following system requirements:
- ExtraHop RevealX 360
- Your user account must have privileges on RevealX 360 for System and Access Administration.
- Your RevealX 360 system must be connected to an ExtraHop sensor with firmware version 9.8 or later.
- Your RevealX 360 system must be connected to ExtraHop Cloud Services.
- Cisco XDR
- You must have an Administrator role on Cisco XDR.
- You must have Cisco XDR Advantage or Cisco XDR Premium licensing tier.
-
Complete the following steps to create ExtraHop REST API credentials for the
integration:
-
Complete the following steps to add the ExtraHop integration to Cisco
XDR:
- From your Cisco XDR, click Administration, and then select Integrations.
- Click the Third-Party tab, and then click Get Started or Enable from the ExtraHop RevealX 360 card.
- Click the expand icon to open the integration guide.
- Complete the fields according to the expanded integration guide, which includes entering the ExtraHop REST API credentials that you created and copied for the integration.
- Click Add.
- Export RevealX device and detection data to your Cisco XDR through the ExtraHop REST API.
Thank you for your feedback. Can we contact you to ask follow up questions?