Overview
You can use HTTP Ingestion to integrate Blumira with KnowBe4 PhishER and bypass the need for an on-premises Ubuntu sensor or traditional API-polling Cloud Connector. This method uses Blumira’s Cloud Ingest API, which provides a unique HTTPS endpoint where your organization can transfer structured logs.
Most Blumira editions have no limit to the number of HTTP integrations you can add. However, the following restrictions apply:
- Detect Lite, Respond Core, and SIEM Core editions have a limit of one ingestion source
- M365 Edition accounts do not include access to any HTTP logging
Reference: See additional available HTTP integrations in Blumira HTTP Ingestion.
Before you begin
Before configuring any log source for outbound HTTP log streaming, you must generate your unique ingestion credentials by doing the following:
- In the Blumira app, navigate to Ingestion > HTTP Ingestion.
- Click Add Ingestion Instance.
- In the window that appears, do the following:
- In Vendor, select the vendor you would like to integrate with.
- (Optional) In Ingestion Instance Name, edit the pre-populated name.
- (Optional) In Description, type a description that provides context for this instance being created.
- Click Save.
- In the Credentials window, do at least one of the following:
- Copy and save each credential to use later when configuring your vendor integration.
-
Keep the Credentials window open to copy and paste the values directly from Blumira into the vendor's site in a different browser tab.
Important: You must copy the token before you close the window. You will not be able to see the token again after you close the Credentials window.
Configuring KnowBe4 PhishER
To integrate with KnowBe4 PhishER and start receiving logs, do the following:
- In PhishER, navigate to Settings > Integrations > Webhook.
- Click New Webhook.
- Under Name, type a name to identify your webhook by.
- In the URL box, paste the URL value you copied from the Credentials for KnowBe4 PhishER window in Blumira.
- In the Authorization dropdown, select Bearer Token.
- In the Token box, paste the Token value you copied from the Credentials for KnowBe4 PhishER window in Blumira.
- Under Available Data, select the check boxes next to each data type you want to transfer.
- Click Create.
- Navigate to Actions > Actions List.
- Click New Action in the top-right corner.
- In the Action Details page that appears, do the following:
- In Name, type a name to identify the action by.
- In Description, type a description that defines the purpose of the action.
- Under Choose how this action should be triggered, select the trigger you want to initiate the action.
- Under Choose the action to be taken on matched messages, do the following:
- Click the check box next to each action you want to set.
- In the respective dropdown menu, select the desired status, priority, or category.
- Under Choose how you would like to report this action, do the following:
- Select Send to Webhook.
- In the Select a Webhook dropdown menu, select the webhook you created in previous steps.
- (Optional) Under Choose whether or not to halt further actions, click the check box next to Stop executing further actions if you want to prevent actions ordered below this action from running.
- (Optional) Under Choose QuickActions settings, click the check box next to the setting you want to implement.
-
(Optional) Under Choose whether or not to permanently delete matching messages, click the check box next to Delete matching messages from PhishER Inbox if you want to delete messages with the tags you specified in Step 3.
Note: If you chose to trigger this action for every message, this section will be grayed out. -
(Optional) Under Find Similar Messages, select the check boxes next to two or more criteria and the action you want PhishER to take if a message matches that criteria.
Note: To change the timeframe for finding similar messages, click the dropdown menu labeled with the current timeframe, and select a different option. - Click Save Action.
- (Optional) Click and drag your actions to reorder them if you chose to halt further actions, and then click Save Action Order.
For information about managing this HTTP integration and its tokens, see Using Blumira HTTP Ingestion.