Set up Nozomi CMC for Integration
Focus
Focus
Device Security

Set up Nozomi CMC for Integration

Table of Contents

Set up Nozomi CMC for Integration

Generate the API token that Cortex XSOAR needs to query your Nozomi Central Management Console (CMC) appliance.
Where Can I Use This?What Do I Need?
  • Device Security (Managed by Strata Cloud Manager)
  • (Legacy) IoT Security (Standalone portal)
One of the following subscriptions:
  • Device Security subscription
  • Precision AI bundle subscription
  • Device Security X subscription
One of the following Cortex XSOAR setups:
  • A free, cohosted, limited-featured Cortex XSOAR instance
    AND
    A free Cortex XSOAR Engine (on-premises integration)
  • A full-featured Cortex XSOAR server
Before Device Security can collect device data from Nozomi CMC, generate an OpenAPI key on Nozomi CMC that Cortex XSOAR can use to query the Nozomi CMC API. Because Nozomi CMC aggregates data from all of the Nozomi Guardian appliances it manages, a single API key generated on CMC gives Cortex XSOAR access to the asset and vulnerability data from every Guardian behind it — you do not need to generate a separate API key on each Guardian. Cortex XSOAR uses the API key for read-only queries and does not write data back to Nozomi CMC or to the Guardian appliances behind it.
To generate the key, you need a Nozomi CMC user account with permission to create OpenAPI keys and access to the organization whose asset and vulnerability data you want Device Security to collect. You also need the list of IP addresses or CIDR ranges that your Cortex XSOAR instance should query for data.
For the most up-to-date instructions on how to generate an OpenAPI key and token for Nozomi CMC, refer to the Nozomi Networks OpenAPI documentation.
  1. Log in to the Nozomi CMC Portal.
  2. Select your profile in the top navigation bar.
  3. Select Other actions.
  4. Select Edit OpenAPI keys.
  5. In the top right, select + Generate to create a new OpenAPI key.
  6. Configure the OpenAPI key.
    • Description: Enter a description that identifies the purpose of the OpenAPI key, for example, XSOAR integration access.
    • Allowed IPs: Enter the IP addresses or CIDR ranges that are permitted to use this key, for example, 192.168.1.0/24. Use the IP addresses or ranges that your Cortex XSOAR instance uses to reach CMC.
    • Organization: Select the organization whose data you want Device Security to collect.
    • Permissions: Select Restricted privileges and grant the following read privileges to the key:
      • Assets: Read
      • Vulnerabilities: Read
  7. Select Generate.
  8. Copy the OpenAPI key and store it in a secure location.
    You need the OpenAPI key to configure your Cortex XSOAR integration instance. The key is shown only once at generation. If you lose the key, you must generate a new one.