Signal Sciences

March 16, 2023 ยท View on GitHub

Signal Sciences + JupiterOne Integration Benefits

  • Visualize Signal Sciences corps, users and cloudwaf instances in the JupiterOne graph.
  • Monitor changes to Signal Sciences users, corps and cloudwaf instances using JupiterOne alerts.

How it Works

  • JupiterOne periodically fetches users, corps and cloudwaf instances from Signal Sciences to update the graph.
  • Write JupiterOne queries to review and monitor updates to the graph, or leverage existing queries.
  • Configure alerts to take action when JupiterOne graph changes, or leverage existing alerts.

Requirements

  • JupiterOne requires an API access token. You need access to a user in Signal Sciences that has permissions to create an access token.
  • You must have permission in JupiterOne to install new integrations.

Support

If you need help with this integration, please contact JupiterOne Support.

Integration Walkthrough

In Signal Sciences

  1. Add API access token. The access token generated will have the same role as the logged in user. The role of Observer is sufficient for the ingestion of corps and users.
  2. Save the provided token in a secure location. You will need it to configure Signal Sciences in JupiterOne.

In JupiterOne

  1. From the top navigation of the J1 Search homepage, select Integrations.
  2. Scroll to the Signal Sciences integration tile and click it.
  3. Click the Add Configuration button and configure the following settings:
  • Enter the Account Name by which you'd like to identify this Signal Sciences account in JupiterOne. Ingested entities will have this value stored in tag.AccountName when Tag with Account Name is checked.
  • Enter a Description that will further assist your team when identifying the integration instance.
  • Select a Polling Interval that you feel is sufficient for your monitoring needs. You may leave this as DISABLED and manually execute the integration.
  • Enter the Signal Sciences user to be used by JupiterOne. This is most like the email associated with the account that was used to generate the API access token.
  • Enter the Signal Sciences API access token generated for use by JupiterOne. This was created within the Signal Sciences web app in a previous step (see above).
  1. Click Create Configuration once all values are provided.

How to Uninstall

  1. From the top navigation of the J1 Search homepage, select Integrations.
  2. Scroll to the Signal Sciences integration tile and click it.
  3. Identify and click the integration to delete.
  4. Click the trash can icon.
  5. Click the Remove button to delete the integration.

Data Model

Entities

The following entities are created:

ResourcesEntity _typeEntity _class
CloudWAFsigsci_cloudwafFirewall
Organizationsigsci_corpOrganization
Usersigsci_userUser

Relationships

The following relationships are created:

Source Entity _typeRelationship _classTarget Entity _type
sigsci_corpHASsigsci_cloudwaf
sigsci_corpHASsigsci_user