Skip to main content

Overview

The ESET integration enables ThreatAware to collect data from your ESET deployment, providing visibility into endpoint security posture and threat detection status across your organisation.
Connection Method: API Setup Time: 15 minutes Access Required: ESET Administrator account

Data collected

The ESET integration provides:
  • Endpoint security status
  • Threat detection events
  • Malware and detection logs
  • Protection status across devices
  • Compliance and policy status

Use cases

Endpoint Security Monitoring

Track ESET protection status across all managed endpoints

Threat Detection

Monitor malware detections and security events

Compliance Validation

Verify endpoint protection is active on required systems

Incident Response

Correlate ESET threat data with device inventory for faster response

Setup instructions

1

Log in to ThreatAware

Access the ThreatAware dashboard and navigate to Settings > Systems.
2

Find and Select ESET

Use the search bar to find ESET in the systems list and click Connect.A configuration dialog will appear.
3

Create an ESET Admin Account

We recommend creating a new ESET Admin account specifically for ThreatAware API integration.In your ESET management console:
  • Create a dedicated admin user (e.g., threataware-api)
  • Ensure the account has read permissions to endpoint data
  • Generate or note the password for this account
4

Copy Admin Account Credentials

From the ESET admin account you created, gather:
  • Username: The admin account username
  • Password: The admin account password
Ensure the admin account has the necessary read permissions but no write permissions for security.
5

Enter Credentials in ThreatAware

In the ThreatAware connection dialog:
  • Paste the Admin username into the username field
  • Paste the Admin password into the password field
6

Authorize and Verify

Click the Authorize button to complete the connection.For detailed API permissions, refer to the ESET API Documentation.
7

Verify Connection Status

After authorization, verify the connection:
  • Check that ESET devices appear in your ThreatAware dashboard
  • Confirm all data from ESET is visible and up to date
  • Ensure the integration status shows Active

Required credentials

Field Name: ESET Admin Username Type: String Description: The username for the ESET admin account created for ThreatAware integrationExample: threataware-api or svc_threataware
Field Name: ESET Admin Password Type: Password (encrypted) Description: The password for the ESET admin account
Store this credential securely. The admin account should have read-only permissions to endpoint data.

Verification and testing

After setup, verify the integration is working correctly:
  1. Check Device Listing
    • Navigate to your ThreatAware device inventory
    • Verify ESET devices are listed and displayed
    • Confirm device counts match your ESET environment
  2. Verify Data Collection
    • Check that ESET device details are visible
    • Confirm threat and protection status data is appearing
    • Look for recent update timestamps
  3. Test Queries
    • Create a test query to filter devices by ESET protection status
    • Verify the data matches your expectations
    • Test filtering by threat or vulnerability data

Troubleshooting

Symptoms: Connection fails with authentication errorSolutions:
  • Verify the Admin username is entered correctly without extra spaces
  • Confirm the Admin password is correct
  • Test the credentials by logging into ESET directly
  • Ensure the admin account is active and not locked
  • Check if the password has expired
Symptoms: Connection succeeds but no data appearsSolutions:
  • Verify the admin account has read permissions to endpoint data
  • Check that the account permissions include access to device inventory
  • Review the ESET API Documentation for required permissions
  • Contact ESET support to verify account permissions
Symptoms: Connection is active but ESET devices don’t show in inventorySolutions:
  • Verify there are devices in ESET with data to collect
  • Check the admin account can access all device groups in ESET
  • Wait up to 1 hour for initial data sync
  • Review ThreatAware integration logs for errors
  • Verify ESET is collecting data from managed endpoints
Symptoms: Integration fails to connect or frequently disconnectsSolutions:
  • Verify the ESET service is online and accessible
  • Check network connectivity between ThreatAware and ESET
  • Ensure firewall rules allow outbound access to ESET
  • Verify the admin account is not locked or expired
  • Contact ESET support if service issues persist

Additional resources

ESET API Documentation

Official ESET API documentation for detailed configuration and permissions

ThreatAware Support

Contact ThreatAware support for integration assistance

Best practices

Credential Management
  • Create a dedicated admin account specifically for ThreatAware
  • Store credentials securely in your organisation’s password manager
  • Rotate credentials annually or per your security policy
  • Monitor for authentication failures in ThreatAware logs
Security Considerations
  • Only grant read permissions to the API account
  • Limit the account scope to necessary device groups
  • Review ESET audit logs periodically to monitor API usage
  • Follow your organisation’s least privilege principles