Lacework is a cloud-based security platform that provides compliance checks, automated threat defense, and intrusion detection for cloud workloads and services on AWS, GCP, Azure, and Kubernetes.
Lucidum uses the Lacework Connector to ingest data from Lacework.
Requirements #
To use the Lacework Connector in Lucidum:
-
Before configuring the Lacework connector in Lucidum, you must first define an API Key and API Secret in Lacework. Lucidum will use the app and its token to access Lacework.
-
You can then configure the Lacework connector in Lucidum and start ingesting data from Lacework.
Prerequisite: Defining an API Key and API Secret #
-
Login to Lacework as an administrator.
-
Follow these steps to create a service account for the Lucidum connector: https://docs.lacework.net/onboarding/manage-access-account-level#create-service-users-for-an-account
-
Assign the role Read-only user.
-
To generate an API key for the service account, follow these steps: https://docs.lacework.net/console/api-access-keys.
-
Download the generated API key file and save is to your local computer.
Configuring the Lacework Connector #
To configure Lucidum to ingest data from Lacework:
-
Log in to Lucidum.
-
In the left pane, click Connector.
-
In the Connector page, click Add Connector.
-
Scroll until you find the Connector for Lacework. Click Connect. The Settings page appears.
-
In the Settings page, enter the following
-
API Key. The API key that you generated in the previous section.
-
API Secret. The API Secret that you generated in the previous section.
-
Lacework Account. Specify the Lacework account from which the Lucidum connector will ingest data. An organization can contain multiple accounts so you can also manage components such as alerts, resource groups, team members, and audit logs at a more granular level inside an organization
-
Lacework Subaccount. Optional. One or more Lacework sub-accounts from which the Lucidum connector will ingest data.
-
-
To test the configuration, click Test.
-
-
If the connector is configured correctly, Lucidum displays a list of services that are accessible with the connector.
-
If the connector is not configured correctly, Lucidum displays an error message.
-
-
API Documentation #
API v2