Abnormal Security


Abnormal Security is a behavioral AI-based email security platform that learns the behavior of every identity in a cloud email environment and analyzes the risk of every event to block the most sophisticated attacks. DNIF can collect, normalize, and monitor Abnormal Security threat logs to help you identify suspicious activity within your workspace in real time.

Pre-requisites
  • Access Token
Steps to derive prerequisites:
  1. Sign in to the Abnormal Security platform.
  2. In the Manage section, click on the Settings option.

In the Settings section, click on the Integrations option.

image 1-Nov-29-2023-09-02-30-9339-AM

4. Scroll down to the Additional Integrations section and click + Connect on the Abnormal REST API card to display an integration page for your organization.

image 2-4


5. In the IP Safelist field, enter the IP addresses for your deployment.

image 3-3

6. Copy and save the Access token.

Configurations

The following are the configurations to forward Abnormal Security Connector logs to DNIF.‌

image 4-3

Field Name Description
 Connector Name Enter a name for the connector
 API Key Enter the Access Token for Abnormal Security.
  • Click Save after entering all the required details and click Test Connection, to test the configuration.
  • Connection successful message will be displayed on screen along with the time stamp.

Once the connector is configured, validate if the connector is listed under Collection Status screen with status as Active. This signifies the connector is configured successfully and data is ready to ingest.