Integrate BlackBerry CylanceOPTICS
You can integrate BlackBerry CylanceOPTICS with Sophos XDR so that it sends data to Sophos for analysis.
Key steps
The key steps in a BlackBerry CylanceOPTICS integration are as follows:
- Get details of your CylanceOPTICS service.
- Generate an application secret in CylanceOPTICS.
- Configure the integration in Sophos XDR.
Requirements
The following is required for BlackBerry CylanceOPTICS configuration:
- An administrator account in the BlackBerry CylanceOPTICS console.
Add a BlackBerry CylanceOPTICS integration
To integrate BlackBerry CylanceOPTICS, you must first gather certain details from BlackBerry, then provide them in Sophos XDR.
Get the API details from your service
To get the BlackBerry CylanceOPTICS API details you need for integration, do as follows:
- Sign in to the CylanceOPTICS management console as an administrator.
- Go to Settings > Integrations.
- Find your Tenant ID and copy it to use later.
-
Find the Base URL for your service and copy it to use later. This may be one of the following:
- Europe Central:
https://protectapi-euc1.cylance.com/ - Asia-Pacific North:
https://protectapi-apne1.cylance.com/ - Asia-Pacific Southeast:
https://protectapi-au.cylance.com/ - North America:
https://protectapi.cylance.com/ - South America:
https://protectapi-sae1.cylance.com/ - US Government:
https://protectapi.us.cylance.com/
- Europe Central:
-
Click Add Application.
- Enter an application name. This must be unique within your organization.
- Select the access privileges for
Detection. - Click Save.
-
You're shown an Application ID and Application secret. Copy these to use later in Sophos XDR.
You can view the application ID and secret in the CylanceOPTICS integrations page at any time.
Next, you configure an integration in Sophos XDR.
Configure the integration in Sophos XDR
To integrate BlackBerry CylanceOPTICS with Sophos XDR, do as follows:
- In Sophos Fusion, go to Security Operations > Integrations > Marketplace.
-
Click BlackBerry CylanceOPTICS.
The BlackBerry CylanceOPTICS page opens. You can configure integrations here and see a list of any you've already configured.
-
In Configured integrations, click Add new.
-
In Add an integration, do as follows:
- Enter a name for the integration.
-
Enter the following details you copied from the BlackBerry CylanceOPTICS console:
- Base URL
- Tenant ID
- Application ID
- Application Secret
-
Click Done.
The new integration appears under Configured integrations. If its status icon is a green tick, your data should appear in the Sophos Data Lake after validation.
Additional resources
For more information on configuring BlackBerry CylanceOPTICS, see the following documents: