Skip to main content

Overview

The ESET OnPrem integration enables ThreatAware to collect data from your ESET OnPrem deployment, providing visibility into endpoint security posture and threat detection status across your organisation.
Connection Method: API Setup Time: 10 minutes Access Required: ESET Administrator account

Data collected

The ESET OnPrem integration provides:
  • Endpoint security status
  • Threat detection events
  • Malware and detection logs
  • Protection status across devices

Use cases

Endpoint Security Monitoring

Track ESET protection status across all managed endpoints

Threat Detection

Monitor malware detections and security events in real-time

Compliance Validation

Verify endpoint protection is active on required systems

Incident Response

Correlate ESET threat data with device inventory for faster response

Setup instructions

1

Log in to ThreatAware

Access the ThreatAware dashboard and navigate to Settings > Integrations.
2

Find and Select ESET OnPrem

Use the search bar to find ESET OnPrem in the integrations list and click Connect.A configuration dialog will appear.
3

Enter ESET Server Details

Provide the following information:
  • API Token: The API token provided by ESET for integration access
  • Server IP Address: The IP address of your ESET OnPrem server
Contact your ESET administrator if you need help obtaining the API token or server IP address.
4

Configure API Permissions

Ensure that the API token has the appropriate permissions configured in ESET:
  • Read access to endpoint data
  • Read access to threat logs
  • Read access to device inventory
For more details, refer to ESET’s API documentation.
5

Complete the Connection

Click Connect to establish the integration. ThreatAware will test the connection.
6

Verify Connection Status

Once connected, verify the connection status in ThreatAware under Connected Systems.Ensure all data from ESET OnPrem is visible and up to date in your dashboard.

Required credentials

Field Name: ESET API Token Type: Password (encrypted) Description: The API token generated in ESET OnPrem for integration access
Store this credential securely in your organisation’s password manager.
Field Name: ESET Server IP Type: String Description: The IP address of your ESET OnPrem serverExample: 192.168.1.100 or 10.0.0.50

Verification and testing

After setup, verify the integration is working correctly:
  1. Check Integration Status
    • Navigate to Settings > Integrations in ThreatAware
    • Confirm the ESET OnPrem integration shows Active status
  2. Verify Data Collection
    • Wait up to 1 hour for initial data sync
    • Check that ESET device data appears in your inventory
  3. Test Queries
    • Create a test query to filter devices by ESET protection status
    • Verify the data matches your expectations

Troubleshooting

Symptoms: Connection fails immediately or shows authentication errorSolutions:
  • Verify the API Token is entered correctly without extra spaces
  • Confirm the Server IP Address is accessible and correct
  • Test connectivity to the ESET server from your network
  • Contact your ESET administrator to regenerate the API token if needed
Symptoms: Integration fails to connect or times outSolutions:
  • Verify the ESET server is online and accessible
  • Check firewall rules allow outbound access to the ESET server
  • Confirm the server IP address is reachable from your ThreatAware instance
  • Test the connection using a network connectivity tool
Symptoms: Integration shows active but no ESET data appearsSolutions:
  • Verify there is endpoint data in ESET to collect
  • Check the API token has read access to endpoint data
  • Wait up to 1 hour for the initial data sync
  • Review ThreatAware integration logs for errors
Symptoms: Integration connects but returns permission denied errorsSolutions:
  • Verify the API token has read permissions to:
    • Endpoint data
    • Threat logs
    • Device inventory
  • Refer to ESET’s API documentation for required permissions
  • Contact ESET support to verify token permissions

Additional resources

ESET API Documentation

Official ESET API documentation for detailed configuration and permissions

ThreatAware Support

Contact ThreatAware support for integration assistance

Best practices

Credential Management
  • Store the API token securely in your password manager
  • Rotate API tokens annually or per your security policy
  • Monitor for authentication failures in ThreatAware logs
  • Use a dedicated API token for ThreatAware integration
Security Considerations
  • Only grant read permissions to the API token
  • Limit API token scope to necessary data endpoints
  • Review ESET audit logs periodically to monitor API usage
  • Follow your organisation’s least privilege principles