Skip to content
Login

Lucidum’s cyber beard is thriving! A Rising in Cyber 2025 Honoree! See the wisdom behind the whiskers → [Learn More!]

Lucidum’s cyber beard is thriving! A Rising in Cyber 2025 Honoree! See the wisdom behind the whiskers → [Learn More!]

  • Home
  • Solutions
    • Modernize Siem Operations
    • Risk Vulnerability/
    • Data Management
    • CISO Tool Kit
  • Product
  • Company
    • About
    • Patents
    • Testimonials
  • Resources
    • E-Books
    • White Papers
    • Videos
    • Blogs
    • Documentation
  • Home
  • Solutions
    • Modernize Siem Operations
    • Risk Vulnerability/
    • Data Management
    • CISO Tool Kit
  • Product
  • Company
    • About
    • Patents
    • Testimonials
  • Resources
    • E-Books
    • White Papers
    • Videos
    • Blogs
    • Documentation
  • Home
  • Solutions

    Solutions

    • Modernize Sec Ops
    • Risk & Vulnerability
    • Data Management
    • CISO Tool Kit
    • MEGAMENU
  • Product
  • Company

    COMPANY

    • About Us
    • Testimonials
    • MEGAMENU
  • Resources

    Resource Library

    • Documentation
    • White Papers
    • Videos
    • Blogs
    • MEGAMENU

What is Lucidum?

  • Overview of Lucidum
  • Protected: Lucidum’s Machine Learning

Getting Started with Lucidum

  • Introduction to Getting Started with Lucidum
  • First Step: User Accounts and Proxy Server
  • Second Step: Connectors
  • Introduction to Dashboards
  • Use Cases for Dashboard

Proxy Server

  • Introduction to Proxy Server
  • Configuring a Proxy Server
  • Renewing a Proxy Server

Managing Users

  • Introduction to User Management
  • Creating and Managing User Accounts
  • Creating and Managing Roles
  • Enabling SSO
  • User Preferences

Connectors

  • Introduction to Connectors
  • Using Connectors
  • Connectors FAQs
  • List of Connectors
    • List of Connectors
    • 1
      • 1E Tachyon
    • A
      • Abnormal Security
      • Absolute
      • Adaptive Shield
      • Addigy
      • Admin By Request
      • ADP
      • Adobe
      • Adobe Workfront
      • Aha!
      • Airlock
      • Airtable
      • Alcatel-Lucent OmniVista 2500
      • Alcide
      • Alert Logic Cloud Insight
      • AlertSite
      • Appgate Software Defined Perimeter (SDP)
      • Aqua
      • Archer Integrated Risk Management
      • Arista NDR
      • Aruba Central
      • Asana
      • Asset Panda
      • Atera
      • Aternity
      • Atlas Data Center
      • Attivo BOTsink
      • Automox
      • Auvik
      • Aviatrix Enterprise Platform
      • AWS
    • B
      • Barracuda CloudGen Firewall
      • BambooHR
      • Baramundi
      • Barracuda CloudGen Access
      • BeyondTrust BeyondInsight
      • BeyondTrust Endpoint Privilege Management
      • BeyondTrust Password Safe
      • BeyondTrust Privileged Identity
      • BeyondTrust Privilege Management for Windows
      • BigID
      • BigTime Projector
      • Bionic
      • Bitbucket
      • Bitdefender GravityZone
      • bitFit
      • BitSight Security Performance Management
      • BlackBerry Unified Endpoint Management (UEM)
      • Block 64 BlockBox
      • BlueCat Enterprise DNS
      • BlueCat Micetro DNS Management
      • BMC Helix CMDB
      • BMC Helix Discovery
      • BMC TrueSight Presentation Server
      • BMC TrueSight Server Automation
      • Box
      • Broadcom Symantec ProxySG
      • Buildkite
      • Burp Suite
    • C
      • CA Service Management
      • CA Spectrum
      • Cato SASE
      • Canonical Ubuntu Landscape
      • Censys
      • Centrify Identity Services
      • CFEngine
      • ChangeGear
      • Checkmarx SAST (CxSAST)
      • Check Point CloudGuard
      • Check Point Harmony Endpoint
      • Check Point Infinity
      • Check Point Infinity External Risk Management
      • Chef
      • Cherwell Service Management
      • Chorus
      • CIS-CAT Pro
      • Cisco Identity Services Engine (ISE)
      • Cisco Meraki
      • Cisco Secure Endpoint
      • Cisco TACACS
      • Cisco Umbrella
      • Cisco Vulnerability Management
      • Citrix Endpoint Management
      • Claroty
      • CloudConnexa
      • Cloudflare
      • CoalfireOne
      • Code42 Incydr
      • Cohesity
      • ColorTokens Xshield
      • ConnectWise Automate
      • CrowdStrike Falcon Endpoint Protection Platform
      • CrowdStrike Falcon LogScale
      • CSCDomainManager
      • CyberArk Endpoint Privilege Manager (EPM)
      • CyberArk Identity Security Platform Shared Services (ISPSS)
      • CyberCNS
      • Cybereason EDR
      • CyCognito
      • Cyera
      • CylancePROTECT
      • Cymulate
      • Cyware
    • D
      • Darktrace PREVENT
      • Databricks
      • Datadog
      • DataLocker SafeConsole
      • Datto Remote Monitoring and Management (RMM)
      • Dayforce
      • DefenseStorm
      • Delinea Privilege Manager
      • Delinea Secret Server
      • Dell Avamar
      • Dell Integrated Dell Remote Access Controller (iDRAC)
      • Dell OpenManage Enterprise
      • Device42
      • DigiCert CertCentral
      • Digital Guardian
      • DivvyCloud
      • DNS Made Easy
      • Docusign
      • Domain Certificate
      • Domotz
      • Dragos
      • Druva Cloud Platform
      • DTEX InTERCEPT
      • Duo Premier
      • Dynatrace
    • E
      • Eclypsium
      • Edgescan
      • EfficientIP SOLIDserver DDI
      • Elastic
      • Endgame
      • Eracent
      • ExtraHop Reveal(x)
      • ExtremeCloud IQ
      • Extreme Networks ExtremeWireless WiNG
      • EZOfficeInventory
    • F
      • F5 BIG-IP iControl
      • F5 BIG-IQ Centralized Management
      • F5 Distributed Cloud App Infrastructure Protection (AIP)
      • FireMon Security Manager
      • Flexera One
      • FlexNet Manager Suite for Cloud
      • Forcepoint Web Security
      • ForgeRock Directory Services
      • FortiClient Enterprise Management Server (FortiClient EMS)
      • FortiEDR
      • Fortify Software Security Center
      • Fortinet FortiGate
      • Fortra Vulnerability Management
      • Forward Networks
      • FreeIPA
      • Freshdesk
      • Freshservice
    • G
      • Gigamon GigaVUE-FM
      • Gigamon ThreatINSIGHT
      • GitHub
      • GitLab
      • GoDaddy
      • Google Cloud
      • Google Security Operations SIEM
      • Google Workspace Drive
      • Google Workspace Endpoint Manager
      • Greenbone OpenVAS
      • GreyNoise
      • Guardicore Centra Security Platform
      • GYTPOL
    • H
      • Halcyon Anti-Ransomware
      • HashiCorp Consul
      • HCL BigFix
      • Heimdal
      • Hexagon HxGN EAM
      • HiBob
      • HP Device Manager
      • HPE Integrated Lights-Out (iLO)
      • HPE Intelligent Management Center (IMC)
      • HPE OneView
      • HubSpot
      • HYPR Passwordless
    • I
      • IBM Hardware Management Console (HMC)
      • IBM MaaS360
      • IBM Maximo
      • IBM Security Guardium
      • IBM Security QRadar
      • IBM SevOne Network Performance Management (NPM)
      • IBM Security Randori Recon
      • IBM Tivoli Application Dependency Discovery Manager (TADDM)
      • iboss Zero Trust SASE (Secure Access Service Edge)
      • iCIMS
      • Icinga
      • IGEL Universal Management Suite (UMS)
      • Illumio Core Platform
      • Imperva SecureSphere Database Activity Monitoring (DAM)
      • INAP
      • Infinipoint Zero Trust Workforce Access Platform
      • Infoblox BloxOne DDI
      • Infoblox NetMRI
      • Intezer Protect
      • Intel Data Center Manager (DCM)
      • IP Fabric
      • Island Enterprise Browser
      • IT Glue
      • iTop
      • Ivanti Connect Secure
      • Ivanti Endpoint Security
      • Ivanti Neurons for Modern Device Management (MDM)
      • Ivanti Neurons for RBVM
      • Ivanti Security Controls
      • Ivanti Unified Endpoint Manager
    • J
      • Jamf Security Cloud
      • Jamf Pro
      • Jamf Protect
      • JetPatch
      • JFrog Artifactory
      • Jira Cloud Platform
      • JumpCloud
      • Juniper Junos
      • Juniper Junos Space
    • K
      • Kandji
      • Kaseya VSA
      • Kaspersky Security Center
      • Keycloak
      • KnowBe4
      • Kolide K2
    • L
      • Lacework
      • Lakeside Systrack
      • Lansweeper
      • LastPass
      • LaunchDarkly
      • LibreNMS
      • LimaCharlie
      • LinkedIn Sales Navigator
      • Litmos
      • LogicMonitor
      • LogMeIn Central
      • LogRhythm SIEM
      • Lookout Mobile EDR
      • Lucidchart
    • M
      • MalwareBytes
      • ManageEngine Endpoint Center
      • ManageEngine OpManager
      • ManageEngine OpUtils
      • ManageEngine ServiceDesk Plus
      • McAfee MVision Cloud
      • Medigate
      • Mice&Men DNS Management
      • Microsoft Active Directory
      • Microsoft Azure
      • Microsoft Configuration Manager
      • Microsoft Defender for Cloud Apps
      • Microsoft Defender
      • Microsoft Intune
      • Microsoft Lync
      • Microsoft Sentinel
      • Microsoft SharePoint
      • Microsoft System Center Virtual Machine Manager (SCVMM)
      • Monday.com
      • Mosyle
    • N
      • N-able
      • Nagios Core
      • Nagios XI
      • Nasuni
      • Nectus
      • NetApp ONTAP
      • NetBox
      • NetBrain
      • Netdisco
      • Netskope
      • NetSpyGlass
      • Netwrix Privilege Secure
      • New Relic
      • Nexthink Infinity
      • ngrok
      • NinjaOne
      • Nozomi Guardian
      • Nucleus
      • Nutanix AHV
    • O
      • Observium
      • Obsidian Security
      • Okta LDAP
      • Okta SSO
      • Omnissa Horizon 8
      • OnDMARC
      • OneLogin
      • Oomnitza
      • openDCIM
      • OpenLDAP
      • OpenStack
      • OpenText GroupWise
      • OpenText NetIQ Advanced Authentication
      • OpenText NetIQ Identity Manager
      • OpenText Network Node Manager i
      • OpenText Server Automation
      • OpenText SiteScope
      • OpenText Webroot Business Endpoint Protection
      • Opsgenie
      • OpsRamp
      • Opsview
      • OPSWAT MetaDefender IT Access
      • Oracle Cloud Infrastructure
      • Orca Cloud Visibility Platform
      • Oracle Communications Unified Assurance (OCUA)
      • Outpost24 Sweepatic EASM
      • oVirt
      • OX Security
    • P
      • PacketFence
      • PagerDuty
      • Palo Alto Networks Cortex XDR
      • Palo Alto Networks Cortex Xpanse
      • Palo Alto Networks IoT Security
      • Palo Alto Networks Panorama
      • Palo Alto Networks PAN‑OS
      • Palo Alto Networks Prisma Cloud Compute Edition
      • Palo Alto Networks Prisma Cloud CSPM
      • Palo Alto Networks Prisma Cloud CWP
      • Panorays
      • PaperCut
      • Parallels
      • phpIPAM
      • PingID
      • PingOne
      • PK Protect Data Protection Platform
      • PluralSight
      • Portnox Cloud
      • Pritunl
      • PrivX
      • Promisec
      • Proofpoint Identity Threat Defense
      • Proofpoint Insider Threat Management
      • Proofpoint Targeted Attack Protection (TAP)
      • Proofpoint Zero Trust Network Access (ZTNA)
      • Proxmox Virtual Environment (VE)
      • PRTG Network Monitor
      • Pulseway Remote Monitoring and Management (RMM)
      • Pulumi
      • Puppet
      • Pure Storage Pure1
    • Q
      • Qualys Cloud Platform (VM/PC)
      • Qualys Global AssetView
      • Quest KACE Endpoint Systems Management Appliance
      • Quip
    • R
      • Rancher
      • Rapid7 InsightAppSec
      • Rapid7 InsightCloudSec
      • Rapid7 InsightIDR
      • Rapid7 InsightVM (Cloud)
      • Rapid7 InsightVM
      • Rapid7 Nexpose Warehouse
      • RapidFort
      • Red Canary
      • Red Hat Ansible Automation Platform
      • Red Hat Identity Management (IdM)
      • Red Hat OpenShift
      • RedSeal
      • ReliaQuest GreyMatter Digital Risk Protection (DRP)
      • Ring Central
      • RiskIQ Illuminate
      • Riverbed SteelCentral Controller
      • Rubrik
      • runZero Network Discovery
    • S
      • Sage People
      • SailPoint IdentityIQ
      • SailPoint IdentityNow
      • Sal Endpoint Management
      • Salesforce
      • Salesforce ExtremeCloud IQ – Site Engine (XIQ-SE)
      • Salesloft
      • Samsung Knox
      • SAP Concur
      • Saviynt Enterprise Identity Cloud (EIC)
      • Scale Computing HyperCore
      • Schneider Electric EcoStruxure IT
      • ScienceLogic
      • ScopNET
      • Sectigo Certificate Manager (SCM)
      • SecureW2 JoinNow MultiOS
      • Secureworks Taegis VDR
      • Secureworks Taegis XDR
      • SecurityScorecard
      • Sensu Go
      • SentinelOne Singularity Network Discovery
      • SentinelOne Singularity XDR
      • Sentry
      • Server Message Block
      • ServiceNow
      • SFTPGo
      • Shodan
      • Signal Sciences
      • SimpleMDM
      • Site24x7
      • Skybox Firewall Assurance
      • Slack
      • Smartsheet
      • Snipe-IT
      • Snow Software
      • Snyk
      • SolarWinds
      • Sonatype IQ Server
      • SonicWall Network Security Manager
      • SonicWall SonicOS
      • Sophos Central
      • Sophos Endpoint Protection
      • SOTI MobiControl
      • Spacewalk
      • Specops Inventory
      • Spiceworks
      • Splunk
      • StatusCake
      • Sumo Logic
      • Sunbird dcTrack
      • Symantec Cloud Workload Protection (CWP)
      • Symantec Control Compliance Suite (CCS)
      • Symantec Data Loss Prevention (DLP)
      • Symantec Endpoint Management Suite
      • Symantec Endpoint Protection
      • Syxsense Secure
    • T
      • Tableau
      • Tailscale
      • Tanium Discover
      • TCPWave DDI
      • TeamViewer Remote Management
      • Tenable Cloud Security
      • Tenable Nessus
      • Tenable OT Security
      • Tenable Security Center
      • Tenable Vulnerability Management
      • Teqtivity
      • Thinkst Canary
      • ThreatConnect
      • TOPdesk Enterprise Service Management (ESM)
      • Torii
      • Trellix Endpoint Security (HX)
      • Trellix ePolicy Orchestrator
      • Trend Micro Cloud App Security
      • Trend Micro Vision One
      • Trend Micro Worry-Free Services
      • Tufin SecureTrack+
    • U
      • UKG Pro
      • UniFi Controller
      • Universal SSH Key Manager
      • UpGuard Vendor Risk
      • Uptycs
    • V
      • Vectra AI
      • Veeam Backup & Replication
      • Venafi Trust Protection Platform
      • Veracode
      • Vercara UltraDNS
      • VMware Carbon Black Cloud Audit and Remediation
      • VMware Carbon Black Cloud Workload
      • VMware Carbon Black Endpoint
      • VMware Tanzu Application Service (TAS)
      • VMware vCloud Director (VCD)
      • VMware Virtualization Platform
      • VMware vRealize
      • VMware vRealize Automation SaltStack Config
      • VMware Workspace ONE
      • Vulcan Cyber
    • W
      • Wasp AssetCloud
      • Wazuh
      • WhatsUp Gold
      • WithSecure Elements Endpoint Protection
      • Wiz
      • Workday
    • X
      • Xton Access Manager
    • Z
      • Zscaler Private Access
      • Zscaler Internet Access
      • Zabbix
      • Zenoss Cloud
      • ZeroFox
      • Zerto
      • Zoom
      • Zscaler Deception
      • Zscaler Client Connector

Viewing Data

  • Introduction to Viewing Data in Lucidum
  • Viewing Data About All Assets, All Users, and All Vulnerabilities
  • Protected: Viewing Details about Individual Assets, Users, or Vulnerabilities
  • Protected: Viewing Details About Data Sources for Assets and Users

Using Queries

  • Queries and Data
  • Creating Queries
  • Saved Queries and Historical Queries
  • Using Queries with Nested Lists
  • Protected: Appendix: Fields and Regular Expressions
  • Appendix: Data Types and Operators

Dashboards

  • Overview of Dashboards
  • Channels
  • Viewing a Dashboard
  • Viewing Charts
  • Creating a Dashboard
  • Creating a Chart
  • Managing a Dashboard
  • Managing Charts
  • Exporting and Importing a Dashboard

Value-Oriented Dashboards (VODs)

  • Overview of Value-Oriented Dashboards
  • Protected: Cloud Dashboards
  • Identity Dashboards
  • Inventory Dashboards
  • Security & IT Ops Dashboards
  • Protected: Threat Intelligence Dashboards

Streamlining Queries with SmartLabels and Tags

  • Protected: Introduction to Tags and Smart Labels
  • Protected: Overview of Tags
  • Protected: Migrating Custom Fields to Tags
  • Protected: Creating and Managing Tags
  • Protected: Overview of SmartLabels
  • Protected: Migrating Dynamic Fields to SmartLabels
  • Protected: Creating and Managing SmartLabels
  • Protected: Using Functions in SmartLabels
  • Protected: Examples for Tags and SmartLabels

Value-Oriented SmartLabels (VOSLs)

  • Protected: Overview of Value-Oriented SmartLabels
  • Protected: Using Value-Oriented SmartLabels

MetaBlocks

  • Introduction
  • Creating and Managing MetaBlocks

Actions

  • Overview of Actions and Actions Workflows
  • List of Actions
    • List of Actions
    • A
      • Active Directory Actions
      • Atera Actions
      • Automox Actions
      • AWS Actions
    • B
      • Barracuda Actions
      • BigPanda Actions
      • BitSight Actions
      • BMC Helix CMDB Actions
    • C
      • Checkmarx Actions
      • Check Point Infinity Actions
      • Cisco AppDynamics Actions
      • Cisco Vulnerability Management (formerly Kenna VM) Actions
      • Commvault Actions
      • Connectwise Automate Actions
      • CrowdStrike Falcon Endpoint Protection Actions
      • Crowdstrike Falcon LogScale Actions
      • CyberArk Actions
      • Cybereason Actions
      • Cyderes Actions
    • D
      • Darktrace Actions
      • Databricks Actions
      • Datadog Actions
      • Delinea Actions
      • Delinea Secret Server Actions
      • Digital Defense Fortra Vulnerability Manager (formerly Frontline VM) Actions
      • Dynatrace Actions
    • E
      • Elastic Cloud Actions
      • Email Actions
      • Exabeam Actions
    • F
      • F5 BIG-IQ Centralized Management Actions
      • F5 Distributed Cloud App Infrastructure Protection (AIP) (formerly F5 Threat Stack) Actions
      • Forescout Actions
      • Fortinet FortiGate Actions
      • Fortra HelpSystems Actions
      • Freshworks Actions
    • G
      • Google Security Operations SIEM Actions
      • Google Security Operations SOAR Actions
    • H
      • Halo Service Solutions Actions
      • HappyFox Actions
      • Heimdal Security Actions
      • Hunters Actions
    • I
      • IBM QRadar Actions
      • Imperva Actions
      • Infoblox Actions
      • Ivanti Endpoint Security Actions
      • Ivanti Security Controls Actions
      • Ivanti Unified Endpoint Manager Actions
    • J
      • Jira Cloud Actions
      • JumpCloud Actions
    • K
      • Kaspersky Security Center Actions
      • KnowBe4 Actions
    • L
      • LogicMonitor Actions
      • LogRhythm Actions
    • M
      • ManageEngine Endpoint Center Actions
      • ManageEngine ServiceDesk Plus Actions
      • Microsoft Azure Monitor Actions
      • Microsoft Defender Actions
      • Microsoft Sentinel Actions
      • Microsoft System Center Service Manager Actions
      • Microsoft Teams Actions
      • Moogsoft Actions
    • N
      • New Relic Actions
    • O
      • Okta Actions
      • One Identity Actions
      • OpenTelemetry Action
      • Opsgenie Actions
      • Optiv Actions
      • Orca Cloud Visibility Platform Actions
    • P
      • Pager Duty Actions
      • Palo Alto Networks Cortex XDR Actions
      • Palo Alto Networks Panorama Actions
      • Proofpoint SIEM Actions
    • Q
      • Qualys Cloud Platform Actions
      • Qualys Global AssetView Actions
    • R
      • Rackspace Cloud Actions
      • Rapid7 Actions
      • Recorded Future Actions
      • RiskIQ Illuminate Actions
    • S
      • Salesforce Actions
      • ScienceLogic Actions
      • Secureworks Taegis XDR Actions
      • SentinelOne Singularity XDR Actions
      • ServiceNow Actions
      • Slack Actions
      • Snowflake Actions
      • SolarWinds Actions
      • Sophos Central Actions
      • Splunk Actions
      • Sumo Logic Actions
      • SysAid Actions
    • T
      • Tanium Discover Actions
      • Telos Actions
      • Tenable Vulnerability Management Actions
      • ThreatConnect Actions
      • ThreatQuotient Actions
      • TOPdesk Enterprise Service Management (ESM) Actions
      • Trellix Actions
      • Trellix ePolicy Orchestrator Actions
      • Trend Micro Cloud App Security Actions
      • Trend Micro Vision One Actions
      • Trustwave MailMarshal Actions
    • W
      • Webhook Actions
      • Webroot Business Endpoint Protection Actions
      • Wiz Actions
    • Z
      • ZeroFox Actions

Risk

  • Protected: Introduction to Risk
  • Protected: Risk Measurements

Use Cases

  • Protected: Overview of Use Cases
  • Full Inventory of Assets and Users
  • Full Inventory of Assets for Providers
  • Assets with End-of-Life Operating Systems
  • AWS Security Groups
  • Azure Lift and Shift
  • Binding Operational Directives
  • Certificates About to Expire or Already Expired
  • Cloud Resources and Cost
  • How Secure Are Your Assets?
  • Identity and Access Management
  • Lucidum and Cyber Insurance Requirements
  • Protected: Lucidum Normalization
  • Microsoft Defender Missing
  • Microsoft Sentinel Missing
  • Sending Lucidum Data to Microsoft Sentinel
  • Unencrypted Storage
  • Zero-Day Vulnerabilities
  • Zero-Day Vulnerabilities and CVEs
  • Zombie Users and Improper Offboardings
  • Cybersecurity Regulations for the Kingdom of Saudi Arabia
    • Protected: Overview of Cybersecurity Controls
    • Asset Management
    • Business Continuity and Disaster Recovery
    • Cloud Security
    • Compliance
    • Configuration Management
    • Continuous Monitoring
    • Data Classification and Handling
    • Endpoint Security
    • Identification and Authentication
    • Protected: Incident Response
    • Protected: Threat Management

Running Headless with Webhooks

  • Overview of Webhooks
  • Creating a Webhook Configuration
  • Creating Queries
  • Creating a Webhook Action
  • Use Case: Sumo Logic

Lucidum API v1

  • Introduction
  • Tokens, Response Codes, Pagination, Methods, Caveats
  • Authentication
  • Endpoints
  • Protected: Examples

Lucidum API v2

  • Overview of Lucidum API v2
  • Authentication in API v2
  • Protected: Endpoints for Assets and Users
  • Endpoints for Assets and Users with LDG Data Only
  • Endpoints for Change Management
  • Endpoints for System Metrics
  • Endpoints for Connectors and Connector Profiles
  • Endpoints for Data Ingestion
  • Pagination
  • Response Codes
  • Operators and Data Types
  • Protected: Examples for Lucidum API v2

Managing Your Lucidum System

  • Introduction to Managing Your Lucidum System
  • Data Scheduler
  • License Settings
  • Notifications
  • System Settings
  • Theme Management

Lucidum MoM (Manager of Managers)

  • Using MoM

Sending Alerts to Slack

  • Introduction
  • Installing and Configuring the Lucidum App
  • Using the Lucidum App

Using the Luci Chatbot

  • Using the Luci Chatbot

Videos

  • AWS Connector Videos
  • Slack Actions Video
View Categories
  • Home
  • Docs
  • Proxy Server
  • Renewing a Proxy Server

Renewing a Proxy Server

Estimated Reading Time: 8 min read

When to Renew the Tunnel Proxy #

There are two circumstances that require you to renew your existing tunnel proxy:

  • Lucidum releases a new version of the proxy image. Periodically, Lucidum updates the proxy image. The latest image includes the latest OS updates and latest package updates and is therefore most secure. The current tunnel proxy image is v1.1.2.

To determine the latest image version:

    1. Log in to Lucidum.

    2. Go to Settings > Tunnel Proxy Settings.

    3. In the Tunnel Proxy Settings page, click the View Setup Instruction (briefcase) icon.

    4. The last line of code in Step 8 displays the latest image version.

  • VPN certificate expired or is soon to expire. The Lucidum tunnel proxy uses OpenVPN and creates its own self-signed certificate with a 2-year lifetime. When the certificate expires, the tunnel proxy will no longer work. Prior to certificate expiration, follow the steps in this chapter to to renew your tunnel proxy.

To determine when your certificate will expire:

    1. Log in to Lucidum

    2. go to Settings > Tunnel Proxy Settings.

    3. In the Tunnel Proxy Settings page, view the Expires On column to determine the expiration date for each tunnel proxy.

Prerequisites #

To perform the steps in this chapter, you must know the root user name and password for the Linux server that serves as the proxy. Note that Lucidum has no way to track or retrieve the root user name and password.

If you cannot locate the root user name and password, you can rebuild the Linux server using these steps in the chapter on Configuration a Proxy Server:

  1. Deploy and Prep the Virtual Machine or Server

  2. Validate Network Connectivity

  3. Install and Configure Docker

You can then return to this chapter and perform the steps in this chapter.

Lucidum: Delete the Current Proxy #

To renew your tunnel proxy, you need to first delete the existing tunnel proxy from Lucidum. To do this:

  1. Login to your Lucidum system.

  2. Go to Settings > Tunnel Proxy Settings.

  3. In the Tunnel Proxy Settings page, find the tunnel proxy you want to renew and click the Delete Tunnel Proxy (trashcan) icon.

    updated_tunnel_proxy_settings_20.0.png

  4. When prompted, click Confirm.

Linux Server: Stop Docker and Remove the Docker Container #

You must delete the existing docker container from the Linux server. To do this:

  1. Either log in to the console of the proxy server or use SSH to access the server

  2. Open a shell session.

  3. View a list of docker containers that are running. To do this, at the shell prompt, type:

    docker ps

  4. In the output, you should see a container with NAMES of “lucidum-tunnel“. This is the tunnel proxy for Lucidum.

  5. Stop the docker container. To do this, at the shell prompt, type:

    docker stop lucidum-tunnel

  6. Delete the docker container. To do this, at the shell prompt, type:

    docker rm lucidum-tunnel

Lucidum: Define the new Tunnel Proxy and Download client.conf #

To create the proxy server, Lucidum supplies a file called client.conf.

  1. Login to your Lucidum system.

  2. Go to Settings > Tunnel Proxy Settings.

  3. In the Tunnel Proxy Settings page, click the Add (plus sign) icon.

    updated_tunnel_proxy_settings_20.0.png

  4. In the Add Tunnel Proxy modal page, supply a name of the proxy and click Save.

    add_tunnel_proxy2.png

  5. The new tunnel proxy appears in the Tunnel Proxy Settings page.

  6. Click the Download Configuration (download) icon for the new tunnel proxy. Lucidum will download a file named client.conf to your local computer.

  7. The client.conf file includes:

    • FQDN and port for the tunnel endpoint

    • Keys

    • TLS certs

Linux Server: Update client.conf #

You now must replace the existing file, client.conf, with the new version you downloaded from Lucidum.

The easiest way to do this is by editing the existing file and replacing its contents. To do this:

  1. Either log in to the console of the proxy server or use SSH to access the server.

  2. Navigate to the directory /usr/lucidum/tunnel. To do this, at the shell prompt, type:

    cd /usr/lucidum/tunnel

  3. Using vi (or an editor of your choice) open the file client.conf.

    vi client.confl

  4. Delete the contents of client.conf.

  5. To do so, first press the [Esc] key. Then press the colon ( : ) key. This enables a command line at the bottom of the file.

  6. At the colon command line at the bottom of the page, enter %d

  7. Press the [Enter] key.

  8. Leave the file open.

  9. On your local computer, navigate to the directory where you downloaded the latest version of client.conf. Copy its contents.

  10. Back at the shell prompt, in the open file, press the [Esc] key and press the [i] key. This enables insert mode.

  11. Paste the copied text with [ctrl] + [v]

  12. Press the [Esc] key. Then press the colon ( : ) key. This enables a command line at the bottom of the file.

  13. At the colon command line at the bottom of the page, enter wq

  14. The client.conf file is saved with the new content.

Linux Server: Start Docker and Run the Docker Image #

Next, you must start docker and run the docker image.

  1. Either log in to the console of the proxy server or use SSH to access the server.

  2. On the proxy server, open a shell session.

  3. See if Docker is running. To do this, at the shell prompt, type:

    docker ps

  4. If you see the message “Cannot connect to Docker daemon…”, you must start Docker.

  5. Start Docker. To do this, at the shell prompt, type:

    sudo systemctl start docker

  6. See if Docker is running. To do this, at the shell prompt, type:

    docker ps

  7. If you are using Red Hat Enterprise Linux, enter the following commands to start the new Docker container. At the shell prompt, type:

    docker run -d --cap-add=NET_ADMIN \

    --device=/dev/net/tun \

    --restart=unless-stopped \

    --network=bridge \

    -v /usr/lucidum/tunnel: /data:ro \

    --name=lucidum-tunnel \

    --ulimit nofile=1048576:1048576 \

    public.ecr.aws/lucidum/tunnel-client:v1.1.2

  8. If you are using any version of Linux except Red Hat Enterprise Linux, enter the following commands to start the new Docker container. At the shell prompt, type:

    docker run -d --cap-add=NET_ADMIN \

    --device=/dev/net/tun \

    --restart=unless-stopped \

    --network=bridge \

    -v /usr/lucidum/tunnel: /data:ro \

    --name=lucidum-tunnel \

    public.ecr.aws/lucidum/tunnel-client:v1.1.2

  9. After the you enter the last command, Docker will:

    • download the latest image from the Lucidum public repository and create a Docker container from the image

    • read the connection and certificate information from /usr/lucidum/tunnel/client.conf

    • attempt to connect to the server defined in the client.conf file. The server is defined in the line that begins with “remote“, usually line 7 of the file.

Lucidum: Verify Connection #

To verify the tunnel proxy connection:

  1. Login to your Lucidum system.

  2. Go to Settings > Tunnel Proxy Settings.

  3. In the Tunnel Proxy Settings page, find the new proxy.

    updated_tunnel_proxy_settings_20.0.png

  4. If the Status column displays a green checkmark, the connection is healthy.

  5. If the Status column displays a red box, the connection has errors.

Troubleshooting #

The first step in troubleshooting the tunnel proxy is to examine the Docker logs. To do this:

  1. Either log in to the console of the proxy server or use SSH to access the server.

  2. On the proxy server, open a shell session.

  3. View the logs for the tunnel connection. To do this, at the shell prompt, type:

    docker logs lucidum-tunnel

  4. If you see this error in the log:

    Options error: In [CMD-LINE]:1: Error opening configuration file: /data/client.conf

    Docker was unable to read the file /usr/lucidum/tunnel/client.conf file.

Possible reasons for this failure:

Problem Diagnostics and Repair
File does not exist Check that the file exists:

  1. Log in to the console of the proxy server or use SSH to access the server.
  2. Open a shell session
  3. Enter the following at the shell prompt:
    cd /usr/lucidum/tunnel
    ls
  4. Output should include client.conf
File has incorrect permissions Check read permissions for the file

  1. Log in to the console of the proxy server or use SSH to access the server.
  2. Open a shell session
  3. Enter the following at the shell prompt:
    cd /usr/lucidum/tunnel
    ls -l
  4. Note the permissions for client.conf
  5. If client.conf does not include read permissions, enter the following at the shell prompt:

chmod +r client.conf

Path has incorrect permissions Check read permissions for the path

  1. Log in to the console of the proxy server or use SSH to access the server.
  2. Open a shell session
  3. Enter the following at the shell prompt:
    cd /
    ls -l
  4. Note the permissions for /usr
  5. Enter the following at the shell prompt:
    cd /usr
    ls -l
  6. Note the permissions for lucidum
  7. Enter the following at the shell prompt:
    cd /usr/lucidum
    ls -l
  8. Note the permissions for tunnel
  9. The easiest solution is to make the entire path readable to all users. To do this, enter the following at the shell prompt:
    chmod a=r /usr/lucidum/tunnel
The contents of /usr/lucidum/tunnel/client.conf are incorrect View the file:

  1. Log in to the console of the proxy server or use SSH to access the server.
  2. Open a shell session
  3. Enter the following at the shell prompt:
    cd /usr/lucidum/tunnel
    vi client.conf
  4. Ensure that you erased the previous contents
  5. Ensure that you fully copied the contents of the new client.conf file.
Outbound network connection has been filtered by firewall rules View client.conf to find the hostname

  1. Log in to the console of the proxy server or use SSH to access the server.
  2. Open a shell session
  3. Enter the following at the shell prompt:
    cat /usr/lucidum/tunnel/client.conf
  4. Note the value in line 7. It looks like:
    remote tunnel.yourcompany.lcuidum.cloud 1194 tcp
  5. Exit the file.
  6. Use this command to check connectivity:
    nc -zv tunnel.acme.lucidum.cloud 1194
  7. If the connection is healthy, you will see:
    Connection to tunnel.acme.lucidum.cloud (n.n.n.n) 1194 port [tcp/openvpn] succeeded!
  8. If the connection is not healthy, contact your Lucidum account representative for help.
  9. Use this command to check the connectivity again:
    nmap -Pn -p 1194 tunnel.acme.lucidum.cloud
  10. If the connection is healthy, you will see:
    Nmap scan report for tunnel.acme.lucidum.cloud (n.n.n.n)
    Host is up (0.00090s latency).rDNS record for 54.208.148.32: ec2-n-n-n-n.compute-1.amazonaws.com
    PORT     STATE SERVICE
    1194/tcp open  openvpn
    Nmap done: 1 IP address (1 host up) scanned in 0.03 seconds
  11. If the connection is not healthy, contact your Lucidum account representative for help.
Your egress IP changed, and Lucidum needs to update the allow-list for your organization. For your protection, Lucidum maintains a strict allow-list of IP addresses that are allowed to attempt connection to your system.When your proxy was initially configured, we added your current egress IP to the list of allowed addresses.

If your egress IP changes, contact your Lucidum account representative. We can update the Lucidum allow-list. Let us know via email or Slack and we will make the change and verify that the proxy connection succeeds.

All other issues: Contact your Lucidum account representative for assistance.
What are your Feelings

Share This Article :

  • Facebook
  • X
  • LinkedIn
  • Pinterest
Still stuck? How can we help?

Still stuck? How can we help?

Updated on September 8, 2025
Configuring a Proxy Server
Table of Contents
  • When to Renew the Tunnel Proxy
  • Prerequisites
  • Lucidum: Delete the Current Proxy
  • Linux Server: Stop Docker and Remove the Docker Container
  • Lucidum: Define the new Tunnel Proxy and Download client.conf
  • Linux Server: Update client.conf
  • Linux Server: Start Docker and Run the Docker Image
  • Lucidum: Verify Connection
  • Troubleshooting

Quick LInks

  • splunk Splunk
  • Elastic
  • Chronicle
  • Sentinel
  • SumoLogic_Lockup_SumoBlue_RGBCreated with Sketch. Sumo Logic
  • CrowdStrike
Linkedin Youtube X-twitter Facebook

@ 2025 Lucidum, Inc. Design By Sandman Studios

SOLUTIONS

COMPANY

RESOURCES

Solutions

  • Modernize Sec Ops
  • Risk & Vulnerability
  • Data Management
  • CISO Tool Kit

COMPANY

  • About Us
  • Testimonials
  • Patents

Resource Library

  • Documentation
  • E-Books
  • White Papers
  • Videos
  • Blogs