Actions for Exabeam #
- Send Data to Exabeam. Sends a custom set of Lucidum data to Exabeam.
Use Cases #
Below are the possible use cases for these actions:
-
If you want to run Lucidum “headless”, you can send relevant data to Exabeam on a regular schedule.
- You can send normalized, enriched Lucidum data to Exabeam to be indexed, searched, and analyzed.
Prerequisites #
To execute Exabeam actions, you must
Configure a Exabeam API connection beforehand. The required parameters are described in the instructions for creating a Exabeam connector in Lucidum https://lucidum.io/docs/microsoft-active-directory.
NOTE. The specified account should have read and write permissions.
Workflows #
- Creating a new Configuration and a new Action
- Cloning an Existing Action
- Creating a new Action from the Location Results page
- Editing a Configuration
- Editing an Action
- Viewing Information about an Action
Exabeam Configuration #
To create a configuration for Exabeam actions:
-
Configuration Name. Identifier for the Configuration. This name will appear in the Lucidum Action Center.
- URL. URL of the Exabeam API. For example, https://api.us-west.exabeam.cloud.
-
Client ID. Client ID for a Exabeam account with read and write access to the Exabeam API. For details on generating a Client ID and Client Secret, see https://docs.exabeam.com/en/collectors/all/cloud-collectors-administration-guide/onboard-cloud-collectors/sophos-central-cloud-collector/prerequisites-to-configure-the-sophos-central-cloud-collector.html#UUID-ed0e202c-f7a7-53e5-2501-00e82943ec67_section-idm4597653341710433976921053498
- Client Secret. Client ID for a Exabeam account with read and write access to the Exabeam API. For details on generating a Client ID and Client Secret, see https://docs.exabeam.com/en/collectors/all/cloud-collectors-administration-guide/onboard-cloud-collectors/sophos-central-cloud-collector/prerequisites-to-configure-the-sophos-central-cloud-collector.html#UUID-ed0e202c-f7a7-53e5-2501-00e82943ec67_section-idm4597653341710433976921053498
-
Max # of Records per Payload. The maximum number of records to send to Exabeam in each action. The default value is “50”.
Create a New Action #
To create an action for Exabeam, contact Lucidum customer care.