Integrate Thinkst Canary
You can integrate Thinkst Canary with Sophos XDR so that it sends data to Sophos for analysis.
Key steps
The key steps in a Thinkst Canary integration are as follows:
- Generate an API token in Thinkst Canary.
- Get details of your Thinkst Canary service.
- Configure the integration in Sophos XDR.
Requirements
The following is required for Thinkst Canary configuration:
- Access to the Thinkst Canary console.
Add a Thinkst Canary integration
To integrate Thinkst Canary, you must first gather certain details from Thinkst, then provide them in Sophos XDR.
Get API details from Thinkst Canary
To get the Thinkst Canary API details you need for integration, do as follows:
- Sign in to your Thinkst Canary console.
- Click the Gear icon and choose Global Settings.
- Click API and Enable API.
-
An Authentication Token and Domain Hash are created for you.
Copy these to use later in Sophos XDR.
Next, you configure an integration in Sophos XDR.
Configure the integration in Sophos XDR
To integrate Thinkst Canary with Sophos XDR, do as follows:
- In Sophos Fusion, go to Security Operations > Integrations > Marketplace.
-
Click Thinkst Canary.
The Thinkst Canary page opens. You can configure integrations here and see a list of any you've already configured.
-
In Configured integrations, click Add new.
-
In Add an integration, do as follows:
- Enter a name for the integration.
-
Enter the Base URL in the form
https://<domain-hash>.canary.tools, where<domain-hash>is the Domain Hash you got from Thinkst Canary.For example if your Domain Hash in the Canary Console is
375hd8af, your base URL ishttps://375hd8af.canary.tools. -
Enter the Authentication Token you got from Thinkst Canary.
-
Click Done.
The new integration appears under Configured integrations. If its status icon is a green tick, your data should appear in the Sophos Data Lake after validation.
Additional resources
For more information on configuring Thinkst Canary, see the following documents: