Admin Guides
RevealX 360
- RevealX 360 Setup and Administration Guide
- Connect to RevealX 360 from self-managed sensors
- Create a sensor tag
- Forward session keys to ExtraHop-managed sensors
- Add your own identity provider to RevealX 360
- Integrate RevealX 360 with Axonius
- Integrate RevealX 360 with Cisco XDR
- Integrate RevealX 360 with Cortex XSOAR
- Integrate RevealX 360 with CrowdStrike
- Integrate RevealX 360 with CrowdStrike Falcon Next-Gen SIEM
- Integrate RevealX 360 with LevelBlue
- Integrate RevealX 360 with Microsoft 365
- Integrate RevealX 360 with Netskope
- Integrate RevealX 360 with QRadar
- Integrate RevealX 360 with QRadar SOAR
- Integrate RevealX 360 with ServiceNow Service Graph Connector
- Integrate RevealX 360 with Splunk Enterprise Security SIEM
- Integrate RevealX 360 with Splunk SOAR
System Configuration
- Register your ExtraHop system
- Connect to ExtraHop Cloud Services
- Enable ExtraHop Remote Access
- Configure the system time
- Upgrade the firmware on your ExtraHop system
- Save system settings to the running configuration file
- Download the running configuration as a text file
- Configure the iDRAC IP address with a monitor, keyboard, and mouse
- Enable network overlay decapsulation
- Enable L2 Discovery
- Configure Device Discovery
- Device name precedence
- Configure endpoint lookup links
- Configure IP address discovery through TTL values
- Configure a global packet capture
- Analyze a packet capture file
- Configure a static IP address through the CLI
- Collect traffic from NetFlow and sFlow devices
- Set up shared SNMP credentials for your NetFlow or sFlow networks
- Automate AWS Traffic Mirroring with CloudFormation
- Forward GENEVE-encapsulated traffic from an AWS Gateway Load Balancer
- Mirror Wire Data with VMware
- Configure ERSPAN with the Nexus 1000V
- Configure ERSPAN with VMware
- Configure RSPAN with VMware
- Configure the iDRAC Remote Access Console
- Repair a Degraded RAID 10 Configuration on the EDA 6200
- Analyze Lync Traffic
- Apply an MS SQL key to the ExtraHop system
- Install the TLS Decryption Board
- Configure packet capture
- Port Channeling
- Packet Forwarding with RPCAP
- Configure packet forwarding for Kubernetes pods
- Configure packet forwarding for pods in EKS
- Configure RPCAP for an ExtraHop packetstore
- Replace the Datastore Hard Drive
- Replace the firmware disk in an ExtraHop appliance
- ExtraHop Rescue Media Guide
- Update Lambda function runtime for ExtraHop flow sensor
- ExtraHop Open Data Stream for ELK
- ExtraHop System Notices
- Module Migration
Connected Appliances
- Connect an ExtraHop console to an ExtraHop sensor
- Connect the EXA 5300 to the ExtraHop system
- Connect the EXA 5200 to the ExtraHop system
- Connect sensors and console to the packetstore
- Create a recordstore cluster
- Disable record ingest on an Explore cluster
- Increase the capacity of your ExtraHop recordstore cluster in VMware
User Management
- Add a local user account
- Add an account for a remote user
- Configure remote authentication through LDAP
- Configure remote authentication through SAML
- Configure SAML single sign-on with Microsoft Entra ID
- Configure SAML single sign-on with Google
- Configure SAML single sign-on with JumpCloud
- Configure SAML single sign-on with Okta
- Configure remote authentication through RADIUS
- Configure remote authentication through TACACS+
- Manage imported LDAP user groups
- Migrate to SAML from LDAP
Decryption
- Decrypt TLS traffic with certificates and private keys
- Create a certificate signing request from your ExtraHop system
- Add a trusted certificate to your ExtraHop system
- Decrypt domain traffic with a Windows domain controller
- Install the ExtraHop session key forwarder on a Windows server
- Install the ExtraHop session key forwarder on a Linux server
- Set up decryption on an MS Exchange server
- Download session keys with packet captures
- Store TLS session keys on connected packetstores
- Session key forwarding from an F5 LTM
Import or Export Data
- Import external data to your ExtraHop system
- Configure an HTTP target for an open data stream
- Configure a Kafka target for an open data stream
- Configure a MongoDB target for an open data stream
- Configure a raw data target for an open data stream
- Configure a syslog target for an open data stream
- Export logs for Machine Learning Service API interactions
3rd-Party Integrations
- Send records from ExtraHop to Google BigQuery
- Send records from ExtraHop to Splunk
- Send records from ExtraHop to CrowdStrike Falcon LogScale
- Integrate ExtraHop with AWS CloudFormation
- Integrate RevealX Enterprise with Cortex XSOAR
- Integrate RevealX Enterprise with Netskope
- Integrate RevealX Enterprise with QRadar
- Integrate RevealX Enterprise with Splunk
- Integrate RevealX Enterprise with Splunk SOAR
- Deploy ERSPAN with an ExtraHop sensor and Brocade 5600 vRouter in AWS
API Guides
REST API
- ExtraHop REST API Guide
- ExtraHop Explore REST API Guide
- ExtraHop Trace REST API Guide
- RevealX 360 REST API Guide
- IDS Sensor REST API Guide
- Add device cloud instance properties through the REST API
- Add observations through the REST API
- Automate virtual appliance deployment with VMware and Ansible
- Back up a sensor or console through the REST API
- Change a dashboard owner through the REST API
- Connect to RevealX 360 from self-managed sensors through the REST API
- Create a device group through the REST API
- Create a trusted TLS certificate through the REST API
- Create custom devices through the REST API
- Enable the REST API for RevealX 360
- Extract files from packets through the REST API
- Extract metrics through the REST API
- Extract the device list through the REST API
- Migrate tuning rules
- Migrate to SAML from LDAP through the REST API
- Query for records through the REST API
- Roll back firmware through the REST API
- Search for a device through the REST API
- Specify custom device makes and models through the REST API
- Specify high value devices through the REST API
- Tag a device through the REST API
- Update network localities
- Upgrade ExtraHop firmware through the REST API
- Upgrade ExtraHop firmware through the REST API with ExtraHop Cloud Services
- Upload IDS rules to the ExtraHop system through the REST API
- Upload STIX files through the REST API
Concepts
References
- Security Overview
- Network Overview
- Perimeter Overview
- Network Activity dashboard
- Network Performance dashboard
- Security Hardening dashboard
- Generative AI Tools dashboard
- Active Directory dashboard
- System Health dashboard
- System Usage dashboard
- Chart types
- ExtraHop System User Guide
- Protocol Metrics Reference
- Default Port Specifications Reference
- ExtraHop Glossary
- Bundles Best Practices Guide
- Supported TLS cipher suites
- Supported browsers
FAQs
- Activity Maps FAQ
- AI Search Assistant FAQ
- Alerts FAQ
- Analysis Priorities FAQ
- Collective Threat Analysis FAQ
- Expanded Threat Intelligence FAQ
- Attack Simulation FAQ
- Detections FAQ
- ExtraHop Hardware FAQ
- Applications FAQ
- Charts FAQ
- Default User Accounts FAQ
- Device Discovery FAQ
- License FAQ
- Metrics FAQ
- Reports FAQ
- Remote Access FAQ
- System Health FAQ
- Triggers FAQ
Deployment
Packet Sensors
- Deploy RevealX Ultra in AWS
- Deploy the EDA 10300 sensor
- Deploy the EDA 10200 sensor
- Deploy the EDA 9300 sensor
- Deploy the EDA 9200 sensor
- Deploy the EDA 8320 sensor
- Deploy the EDA 8200 sensor
- Deploy the EDA 6200 sensor
- Deploy the EDA 1200 sensor
- Deploy an ExtraHop sensor on AWS
- Deploy an ExtraHop sensor on Azure
- Deploy an ExtraHop sensor on Google Cloud Platform
- Deploy an ExtraHop sensor on Hyper-V
- Deploy an ExtraHop sensor on Linux KVM
- Deploy the ExtraHop sensor on VMware
- Sensor and console post-deployment checklist
- Safety information for the EDA 1200 sensor
Consoles
- Deploy the ECA VM in AWS
- Deploy the ExtraHop ECA VM console in Azure
- Deploy the ExtraHop ECA VM console in Google Cloud Platform
- Deploy the ExtraHop ECA VM console with Hyper-V
- Deploy the ExtraHop ECA VM console on Linux KVM
- Deploy the ExtraHop console with VMware
- Virtual ExtraHop Console Performance Guidelines
- Sensor and console post-deployment checklist
Recordstores
- Deploy the EXA 5300 recordstore
- Deploy the EXA 5200 recordstore
- Deploy an ExtraHop recordstore in AWS
- Deploy an ExtraHop recordstore in Azure
- Deploy an ExtraHop recordstore with Hyper-V
- Deploy an ExtraHop recordstore on Linux KVM
- Deploy the ExtraHop recordstore with VMware
- Increase the capacity of your ExtraHop recordstore cluster in VMware
- Recordstore Post-deployment Checklist
- Send records from ExtraHop to Google BigQuery
- Send records from ExtraHop to Splunk
Packetstores
- Deploy the ETA 9350 packetstore
- Deploy the ETA 8250 packetstore
- Deploy the ETA 6150 packetstore
- Deploy the ExtraHop packetstore in AWS
- Deploy an ExtraHop packetstore in Azure
- Deploy the ExtraHop packetstore on Google Cloud Platform
- Deploy the ExtraHop packetstore with VMware
- Add storage capacity to an ExtraHop packetstore
- Packetstore Post-deployment Checklist
How To's
Charts
- Create a chart
- Copy a chart
- Edit a chart with the Metric Explorer
- Drill down
- Display a rate or count in a chart
- Display percentiles or a mean in a chart
- Edit metric labels in a chart legend
- Add a dynamic baseline to a chart
- Add a static threshold line to a chart
- Display device group members in a chart
- Create regular expression filters
- Find all devices talking to external IP addresses
- Monitor a device for external IP address connections
Dashboards
- Create a dashboard
- Copy a dashboard
- Display a dashboard in a NOC or SOC
- Create a dashboard with dynamic sources
- Edit a dashboard layout
- Edit a chart with the Metric Explorer
- Edit a text box widget
- Edit a dashboard region
- Change the time interval for a dashboard region
- Edit dashboard properties
- Create a dashboard collection
- Set a personal default dashboard
- Share a dashboard
- Share a dashboard collection
- Share a dashboard with a restricted user
- Present a dashboard
- Export data
- Create a PDF file
- Create a scheduled report
Detections
- Tune detections
- Filter and Tune Hardening Detections
- Optimizing detections
- Suppress detections with tuning parameters
- Hide detections with tuning rules
- Track a detection
- Create an investigation
- Acknowledge detections
- Create a detection notification rule
- Create a detection catalog notification rule
- Create a threat briefing notification rule
- Create a custom detection
- Contain CrowdStrike devices from a detection
- Investigate performance detections
- Investigate security detections
- Share a detection
- Enable or disable detection markers
- Upload custom IDS rules
Devices
- Find a device
- Create a device group
- Create a device group based on discovery time
- Change a device name
- Change a device role
- Change a device model
- Manually identify a device as high value
- Create a device tag
- Create a custom device
- Delete or disable a custom device
- Configure remote sites for custom devices
- Prioritize groups for Advanced Analysis
- Prioritize groups for Standard Analysis
- Add a device to the watchlist
- Remove a device from the watchlist
- Transfer management of analysis priorities
- Specify a network locality
- Configure endpoint lookup links