Thinkst Canary Logs
Connecting Thinkst Canary logs in your Panther Console
Overview
Panther ingests Thinkst Canary alert logs by configuring a webhook to post events to a Panther HTTP source.
Thinkst Canary honeypots and honeytokens can be deployed in minutes and piped into Panther with just a few clicks. In Panther, you can correlate Canary alerts with other security events to enable centralized threat detection, streamlined incident response, and enhanced visibility across your network security posture.
How to onboard Thinkst Canary logs to Panther
Step 1: Create a new Thinkst Canary source in Panther
To connect these logs into Panther:
In the left-hand navigation bar of your Panther Console, click Configure > Log Sources.
Click Create New.
Search for “Thinkst Canary,” then click its tile.
In upper-right corner of the slide-out panel, click Start Setup.
Follow Panther's instructions for configuring an HTTP Source, beginning at Step 5.
For the Auth method, select shared secret authentication. This is the only method of authentication Thinkst Canary supports.
Payloads sent to this source are subject to the payload requirements for all HTTP sources.
Do not proceed to the next step until the creation of your HTTP endpoint has completed.
Step 2: Configure a webhook in Thinkst Canary
In the upper-right corner of your Thinkst Canary console, click the gear icon > Global Settings.
In the left-hand navigation bar, click Webhooks.
Click Add New Webhook.
Under Global Webhooks Feed, click the plus sign icon (+).
In the Add New Webhook pop-up modal, click Add Generic.
In the Add new Generic Webhook pop-up modal, configure the webhook fields:
Webhook URL: Paste the HTTP Source URL you generated in Panther in Step 1.
Add custom request headers: Toggle this field on.
The header name and value should only be shared between your Thinkst Canary console and Panther.
Enter header name: Enter the Header Name you entered in Panther in Step 1.
Enter header value: Enter the Shared Secret Value you entered or generated in Panther in Step 1.
Click Save.
Panther-managed detections
See Panther-managed rules for Thinkst Canary in the panther-analysis GitHub repository.
Supported log types
ThinkstCanary.Alert
Last updated
Was this helpful?