Tracebit Logs

Connecting Tracebit logs in your Panther Console

Overview

Panther ingests Tracebit alert logs by configuring Tracebit to send alerts to an HTTP endpoint in Panther.

Tracebit maintains canary resources across your organization's cloud infrastructure to detect potential intrusions. Alert logs from Tracebit contain information about activity on canary resources, as well as use of canary credentials.

How to onboard Tracebit logs to Panther

Step 1: Create a new Tracebit source in Panther

  1. In the left-side navigation bar of your Panther Console, click Configure > Log Sources.

  2. Click Create New.

  3. Search for "Tracebit," then click its tile.

  4. In the slide-out panel, click Start Setup.

    An arrow is drawn to a "Tracebit" tile to a "Start Setup" button.
  5. Follow Panther's instructions for configuring an HTTP Source, beginning at Step 5.

    • During setup, on the Configure page, you will be required to use HMAC authentication; this is the only method of authentication Tracebit supports.

      • The Header Name associated with your Secret Key Value will be locked with a value of X-Tracebit-Signature-256, and the Hashing Algorithm will be locked with a value of SHA 256.

      • Generate a Secret Key Value and store it in a secure location, as you will need it in the next step.

    • Payloads sent to this source are subject to the payload requirements for all HTTP sources.

    • Do not proceed to the next step until the creation of your HTTP endpoint has completed.

Step 2: Create a Panther integration in Tracebit

  1. In the Tracebit console, navigate to the Integrations page.

  2. Click Panther.

  3. In the HTTP Log Source URL field, paste the HTTP Source URL you generated in Panther in the previous step.

  4. In the HMAC SHA256 Shared Secret field, paste the Secret Key Value you generated in Panther in the previous step.

  5. Click Save.

Supported log types

Tracebit.Alert

Tracebit.HealthCheck

Last updated

Was this helpful?