AgileBlue's Cerulean AI SecOps platform can monitor alert logs generated by Darktrace, a network monitoring solution, with a couple of integration methods avialable.
Supported Data Streams
By leveraging Darktrace's REST API or collecting the same data via Syslog, AgileBlue is able to ingest alert logs from the following data streams:
- AI Analyst Alert
- Model Breach Alert
- System Status Alert (Syslog only)
Supported Versions
The integration is tested against the following Darktrace versions:
- Darktrace Threat Visualizer v5.2
Setup Steps (API - Recommended)
- Access your Darktrace Threat Visualizer console and collect the Hostname URL
- Access the following link in order to leverage Darktrace to generate a Public and Private API Token:
- Securely send the collected values to AgileBlue Support (support@agileblue.com)
- Darktrace Console URL
- Public API Token
- Private API Token
Setup Steps (Syslog - Optional)
- Follow this guide to install the Cerulean Agent in syslog mode on a device in your environment
- NOTE: If you have previously configured syslog collection on the Cerulean platform, you can skip step No. 1
- Contact AgileBlue Support to confirm the target device is enrolled in your Syslog policy; support will respond with dedicated UDP port numbers for each of the following data streams:
- AI Analyst Alert Logs
- Model Breach Alert Logs
- System Status Alert Logs
- Access your Darktrace Threat Visualizer Dashboard then select Main Menu > Admin in order to access your System Config page
- Click Modules
- Select Workflow Integrations > Syslog
- Choose Syslog JSON then click New
- Under IP Address, enter the IP of the device running the Cerulean Agent in syslog mode, which was configured in step one
- Enter the specific port numbers provided by AgileBlue support for each of the corresponding data streams
Need Help?
AgileBlue is always here to support you and ensure you are 100% successful. If there are any issues with the installation or if you have any questions, please reach out to AgileBlue Support.
Email: support@agileblue.com
Phone: (216) 606-9400🚨