PDF Version: ThinkstCanaryConfigurationGuide.pdf
Step by Step Instructions
Authorization type: API Key Auth
API doc reference: Introduction | Canary API Docs
API Endpoint:
/api/v1/incidents/all
1. App Information
App Info:
App Name: Thinkst Canary
App Description(Optional): NA
AlienApp Category: Database
Vendor (Optional): Thinkst Canary
Device Type (Optional): Honeypot
Complete the dialogues as shown above. These details don’t impact the function of the app and can be set up as you see fit.
2. API Credentials
Use the details above to populate the dialogues. Include the username and password from your Thinkst Canary configuration.
3. API Configuration
In Params : we need to add limit 100
Use the details above to complete the dialogues.
4. Mapping
Raw Log Data:
Fields Mapping:
Use the table above as a guide - the left hand side is the new log data, and the right hand side represents which USM key to drag it onto. Use the search bars above both sides to find the exact matches. Once finished, click “next”.
5. Summary Fields:
Select which fields you would like in the summary. See above as an example. This step is completely at your discretion and doesn’t impact app operations. All log details will be available in “Event Details”.
6. API Response:
7. Preview
“Save and Close” to finalize app.