Overview
The Heimdal integration enables ThreatAware to collect read-only data from your Heimdal Security platform, providing visibility into endpoint threats, security events, and device compliance.Connection Method: API
Setup Time: 10 minutes
Access Required: Heimdal Administrator account
Data collected
The Heimdal integration provides:- Endpoint threat data
- Security events and alerts
- Device compliance information
- API access controls
Use cases
Threat Monitoring
Monitor endpoint threats detected by Heimdal
Security Events
Track security events across your infrastructure
Device Compliance
Validate device security compliance status
Incident Response
Generate reports on security incidents and threats
Setup instructions
1
Log in to Heimdal Security Console
Access the Heimdal Security Console with an account that has administrator privileges.
2
Generate API Token
In the Heimdal console:
- Navigate to Settings > API Access
- Click Generate API Token
- Set permissions to Read-only or monitoring permissions as required for ThreatAware
- Copy the API Token once it’s generated
3
Retrieve Console URL
Make note of your Heimdal Security Console URL. This is typically:Example:
https://portal.heimdalsecurity.com4
Configure in ThreatAware
Complete the integration setup in ThreatAware:
- Navigate to Settings > Integrations
- Search for and select Heimdal
- Enter the required credentials:
- API Token: The token generated in Heimdal Security
- Heimdal Console URL: Your Heimdal Security Console instance URL
- Click Connect to establish the integration
5
Verify Connection
After connecting, verify the integration is working:
- Check that the Integration Status shows as Active
- Confirm that threat and security event data is appearing in ThreatAware
Required credentials
API Token
API Token
Field Name: Heimdal API Token
Type: Password (encrypted)
Description: The token generated for API access in Heimdal Security
Heimdal Console URL
Heimdal Console URL
Field Name: Heimdal URL
Type: String
Description: The URL of your Heimdal Security Console instanceFormat:
https://portal.heimdalsecurity.com
Example: https://portal.heimdalsecurity.com or your organisation’s custom Heimdal instance URLVerification and testing
After setup, verify the integration is working correctly:-
Check Integration Status
- Navigate to Settings > Integrations in ThreatAware
- Confirm the Heimdal integration shows Active status
- Check the last sync timestamp
-
Verify Data Collection
- Wait 5-10 minutes for the initial data sync
- Check for threat and security event data in ThreatAware
- Verify device compliance information is being collected
-
Test Queries
- Create a test query to filter data from Heimdal
- Verify the threat data matches your expectations
Troubleshooting
Invalid Token Error
Invalid Token Error
Symptoms: Integration status shows authentication failureSolutions:
- Verify the API Token is exactly as displayed in Heimdal (no extra spaces)
- Ensure the token has not expired
- Regenerate a new API token in Heimdal if the current one is suspect
- Confirm your Heimdal account has administrator privileges
Permission Denied
Permission Denied
Symptoms: Integration connects but fails to retrieve dataSolutions:
- Verify the API token has read permissions for threat and security event data
- Check that the token has access to the necessary Heimdal resources
- Review the Heimdal API Documentation for permission details
- Ensure your API token has not been revoked or disabled
Connection Timeout
Connection Timeout
Symptoms: Integration fails to connect or times outSolutions:
- Verify the Heimdal Console URL is correct and accessible
- Check firewall rules allow outbound HTTPS (443) to Heimdal servers
- Test the URL in a browser to ensure it’s reachable
- Confirm your Heimdal Security platform is online and responsive
No Data After 10 Minutes
No Data After 10 Minutes
Symptoms: Integration shows active but no threat data appearsSolutions:
- Verify there is threat or security event data in Heimdal to collect
- Check that your endpoints are monitored by Heimdal
- Confirm the API token has access to threat and security event data
- Wait up to 15 minutes for the initial sync to complete
Additional resources
Heimdal API Documentation
Official Heimdal API documentation for detailed permissions and configuration
ThreatAware Support
Contact ThreatAware support for integration assistance