Skip to main content

Overview

The Symantec integration enables ThreatAware to collect data from Symantec, providing enhanced visibility and security controls.
Connection Method: API Setup Time: 15 minutes Access Required: Administrator account

Setup instructions

Symantec Connection Guide Connect Symantec
ThreatAware Integration
  1. Log in to the ThreatAware dashboard and navigate to Settings > Systems.
  2. In the search bar, type Symantec.
  3. Click Connect. You will see a prompt titled Client Application.

Symantec Console Setup
  1. Log in to your Symantec console.
  2. Go to the Endpoint tab, then navigate to the Integration page and select Client Applications.
  3. Click the Add button.
  4. Enter a suitable name for the application and click Add.
  5. In the side window, ensure you select View permissions for:
    • Devices
    • Alerts & Events
    • Investigation
  6. Click Save to confirm your selections.
  7. Move forward with the next step in the ThreatAware platform.

Symantec API Authorization
  1. From the list, click on the application you just created.
  2. In the side window, click on Client Secret at the top.
  3. Copy both the Client ID and Client Secret displayed[1].
  4. Click Okay, and proceed to the next step in ThreatAware.

Input Details in ThreatAware
  1. Enter the Client ID into ThreatAware using the designated field.
  2. Enter the Client Secret in ThreatAware as well.
  3. Click the Authorize button to complete the connection.

Verification and Troubleshooting
  • Confirm the integration by checking the connection status on the ThreatAware dashboard.
  • If issues arise, ensure that the copied Client ID and Client Secret are correct and that all necessary API permissions are granted.

Footnotes: [1] For more detailed information on permissions, refer to Symantec’s API Permissions Documentation.