diff --git a/docs/assets/operation_center/integration_catalog/cloud_and_saas/ubika_cloud_protector/api_access.png b/docs/assets/operation_center/integration_catalog/cloud_and_saas/ubika_cloud_protector/api_access.png new file mode 100644 index 0000000000..5f5dbc6530 Binary files /dev/null and b/docs/assets/operation_center/integration_catalog/cloud_and_saas/ubika_cloud_protector/api_access.png differ diff --git a/docs/assets/operation_center/integration_catalog/cloud_and_saas/ubika_cloud_protector/api_keys_info.png b/docs/assets/operation_center/integration_catalog/cloud_and_saas/ubika_cloud_protector/api_keys_info.png new file mode 100644 index 0000000000..b4166b6ca1 Binary files /dev/null and b/docs/assets/operation_center/integration_catalog/cloud_and_saas/ubika_cloud_protector/api_keys_info.png differ diff --git a/docs/assets/operation_center/integration_catalog/cloud_and_saas/ubika_cloud_protector/create_api_token.png b/docs/assets/operation_center/integration_catalog/cloud_and_saas/ubika_cloud_protector/create_api_token.png new file mode 100644 index 0000000000..ce30b464d8 Binary files /dev/null and b/docs/assets/operation_center/integration_catalog/cloud_and_saas/ubika_cloud_protector/create_api_token.png differ diff --git a/docs/assets/operation_center/integration_catalog/cloud_and_saas/ubika_cloud_protector/switch.png b/docs/assets/operation_center/integration_catalog/cloud_and_saas/ubika_cloud_protector/switch.png new file mode 100644 index 0000000000..33a9852959 Binary files /dev/null and b/docs/assets/operation_center/integration_catalog/cloud_and_saas/ubika_cloud_protector/switch.png differ diff --git a/docs/xdr/features/collect/integrations/cloud_and_saas/ubika_cloud_protector.md b/docs/xdr/features/collect/integrations/cloud_and_saas/ubika_cloud_protector.md new file mode 100644 index 0000000000..c562e5eac7 --- /dev/null +++ b/docs/xdr/features/collect/integrations/cloud_and_saas/ubika_cloud_protector.md @@ -0,0 +1,67 @@ +uuid: d0383e87-e054-4a21-8a2c-6a89635d8615 +name: Ubika Cloud Protector +type: intake + +## Overview + +Ubika Cloud Protector is a cloud-native security solution, providing advanced threat detection and data protection to secure cloud environments, enabling real-time monitoring and mitigation of risks in cloud-based infrastructures. + +!!! warning + Important note - This format is currently in beta. We highly value your feedback to improve its performance. + +{!_shared_content/operations_center/detection/generated/suggested_rules_d0383e87-e054-4a21-8a2c-6a89635d8615_do_not_edit_manually.md!} + +{!_shared_content/operations_center/integrations/generated/d0383e87-e054-4a21-8a2c-6a89635d8615.md!} + +## Configure + +### How to create an API token + +!!! warning + The following instructions are based on the old interface of Ubika Cloud Protector. Please, switch to the old interface if you use the new one. + ![choose old interfaces](/assets/operation_center/integration_catalog/cloud_and_saas/ubika_cloud_protector/switch.png){: style="max-width:100%"} + +To create an API token: + + +1. Log in the Ubika Cloud protector +2. Go to `Account` > `API Access` + + ![api access](/assets/operation_center/integration_catalog/cloud_and_saas/ubika_cloud_protector/api_access.png){: style="max-width:100%"} + +3. In the `API KEYS INFO` section, please note the `provider name` and the `tenant name` + + ![api info](/assets/operation_center/integration_catalog/cloud_and_saas/ubika_cloud_protector/api_keys_info.png){: style="max-width:100%"} + +4. In the `CREATE API KEYS` section + 1. Type a description to identify the API token + 2. Select the `AUTHZ_ROLE_TENANT` role + 3. Select the `AUTHZ_ACT_LIST_LOGS` action + 4. Click `CREATE` + + ![create_token](/assets/operation_center/integration_catalog/cloud_and_saas/ubika_cloud_protector/create_api_token.png){: style="max-width:100%"} + + +### Create your intake + +1. Go to the [intake page](https://app.sekoia.io/operations/intakes) and create a new intake from the `Ubika Cloud Protector`. +2. Copy the associated Intake key + +### Pull the logs to collect them on Sekoia.io + +Go to the Sekoia.io [playbook page](https://app.sekoia.io/operations/playbooks), and follow these steps: + +- Click on **+ PLAYBOOK** button to create a new one +- Select **Create a playbook from scratch** +- Give it a name in the field **Name** +- Open the left panel, click **Ubika** then select the trigger `Fetch new alerts from Ubika Cloud Protector` +- Click on **Create** +- Create a **Trigger configuration** using: + + * Type the `Intake key` created on the previous step + * Type the `provider`, `tenant` and `token` from the `How to create an API token` step + +- Click on the **Save** button +- **Activate the playbook** with the toggle button on the top right corner of the page + +### Enjoy your events on the [Events page](https://app.sekoia.io/operations/events) diff --git a/mkdocs.yml b/mkdocs.yml index e42e25d34a..d41a3356b8 100644 --- a/mkdocs.yml +++ b/mkdocs.yml @@ -157,6 +157,7 @@ nav: - Salesforce: xdr/features/collect/integrations/cloud_and_saas/salesforce.md - SecurityScorecard's Vulnerability Assessment Scanner: xdr/features/collect/integrations/cloud_and_saas/securityscorecard_vas.md - Sophos Threat Analysis Center: xdr/features/collect/integrations/cloud_and_saas/sophos_threat_analysis_center.md + - Ubika Cloud Protector: xdr/features/collect/integrations/cloud_and_saas/ubika_cloud_protector.md - Ubika WAAP Gateway: xdr/features/collect/integrations/cloud_and_saas/ubika_waap.md - Zscaler ZIA: xdr/features/collect/integrations/cloud_and_saas/zscaler_zia.md - Email: