This article leads you through the process of integrating Lacework with Red Canary. Follow the procedure from beginning to end.
- You must have Lacework Admin access to create the necessary API keys.
- You must have access to create an external service in Red Canary.
Step 1: Lacework–Create your Lacework API keys
Create your Lacework API keys to begin the alert sync between Lacework and Red Canary.
- From the Lacework navigation menu, click Settings.
- Click Users, select Account level tab, and then click +Add New.
- From the Choose a User type dropdown, select Service user.
- Enter a name for your user.
- Enter a description for your user.
- Click Next.
- From the select a user group for added users dropdown, select Power User.
- Click Save.
- From the Configuration section, click API Keys.
- Click the Service user API keys tab.
- Click the ellipses dropdown (...), and then click Download.
- Copy and save the .json file with your API keys. You will use this in a later step.
Step 2: Red Canary–Create External Service
Enter your Lacework API key information into Red Canary to start sending your Lacework alerts to Red Canary.
- From your Red Canary homepage, click Integrations.
- From the Integrations section, locate and then click the security product you want to integrate with Red Canary.
Note: If you do not see your security product listed, click See all integrations.
- In the search bar, type and then select your third-party security source.
- Continue onto the next step by configuring your third-party security source in Red Canary.
Note: Your third-party security source may require that you contact Red Canary to configure.
- Enter the Organization name, Secret Key ID, and Secret Key from the .json file you downloaded in Step 1.11.
Note: For the Organization field, you need to begin the URL with https:// (example: https://orgname.lacwork.net).
- Click Save.