Set up Nozomi Vantage for Integration
Focus
Focus
Device Security

Set up Nozomi Vantage for Integration

Table of Contents

Set up Nozomi Vantage for Integration

Generate the API token that Cortex XSOAR needs to query your Nozomi Vantage tenant.
Where Can I Use This?What Do I Need?
  • Device Security (Managed by Strata Cloud Manager)
  • (Legacy) IoT Security (Standalone portal)
One of the following subscriptions:
  • Device Security subscription
  • Precision AI bundle subscription
  • Device Security X subscription
One of the following Cortex XSOAR setups:
  • A free, cohosted, limited-featured Cortex XSOAR instance
    AND
    A free Cortex XSOAR Engine (on-premises integration)
  • A full-featured Cortex XSOAR server
Before Device Security can collect device data from Nozomi Vantage, generate an API token in the Vantage Portal that Cortex XSOAR can use to query the Vantage API. Cortex XSOAR uses the API token for read-only queries and does not write data back to Vantage.
To generate the token, you need a Nozomi Vantage user account with permission to create API keys and access to the organization whose asset and vulnerability data you want Device Security to collect. You also need the list of IP addresses or CIDR ranges that your Cortex XSOAR instance uses to reach Vantage.
For the most up-to-date instructions on how to generate an API token for Nozomi Vantage, refer to the Nozomi Networks documentation for API keys in Vantage.
  1. Log in to the Nozomi Vantage Portal.
  2. Navigate to ProfileSettingsAPI Keys.
  3. Click Add to create a new API token.
  4. Configure the API token.
    • Description: Enter a description that identifies the purpose of the token, for example, XSOAR integration access.
    • Allowed IPs: Enter the IP addresses or CIDR ranges that are permitted to use this token, for example, 192.168.1.0/24. Use the IP addresses or ranges that your Cortex XSOAR instance uses to reach Vantage.
    • Organization: Select the Vantage organization whose data you want Device Security to collect.
    • Permissions: Select Restricted privileges and grant the following read privileges to the token:
      • Assets: Read
      • Vulnerabilities: Read
  5. Click Generate.
  6. Copy the token and store it in a secure location.
    You need the token to configure your Cortex XSOAR integration instance. The token is shown only once at generation. If you lose the token, you must generate a new one.