Overview
The Symantec integration enables ThreatAware to collect data from Symantec, providing enhanced visibility and security controls.Connection Method: API
Setup Time: 15 minutes
Access Required: Administrator account
Setup instructions
Symantec Connection Guide Connect SymantecThreatAware Integration
- Log in to the ThreatAware dashboard and navigate to
Settings>Systems. - In the search bar, type
Symantec. - Click
Connect. You will see a prompt titled Client Application.
Symantec Console Setup
- Log in to your Symantec console.
- Go to the
Endpointtab, then navigate to theIntegrationpage and selectClient Applications. - Click the
Addbutton. - Enter a suitable name for the application and click
Add. - In the side window, ensure you select
View permissions for:- Devices
- Alerts & Events
- Investigation
- Click
Saveto confirm your selections. - Move forward with the next step in the ThreatAware platform.
Symantec API Authorization
- From the list, click on the application you just created.
- In the side window, click on
Client Secretat the top. - Copy both the
Client IDandClient Secretdisplayed[1]. - Click
Okay, and proceed to the next step in ThreatAware.
Input Details in ThreatAware
- Enter the
Client IDinto ThreatAware using the designated field. - Enter the
Client Secretin ThreatAware as well. - Click the
Authorizebutton to complete the connection.
Verification and Troubleshooting
- Confirm the integration by checking the connection status on the ThreatAware dashboard.
- If issues arise, ensure that the copied
Client IDandClient Secretare correct and that all necessary API permissions are granted.
Footnotes: [1] For more detailed information on permissions, refer to Symantec’s API Permissions Documentation.