Lacework provides cloud security automation for AWS, Azure, and GCP with a comprehensive view of risks across cloud workloads and containers. The Balbix integration with Lacework ingests assets, software and associated vulnerabilities information discovered by Lacework.
Balbix leverages AI to aggregate, normalize, and deduplicate ingested data, along with information integrated from your existing IT and cybersecurity tools. This creates a unified view of your entire asset inventory, including vulnerabilities and their business and operational context. Balbix’s AI models then analyze this data to provide insights such as deployment gap analysis, risk-based vulnerability prioritization (with detailed ranking and scoring), and risk quantification. This process delivers a comprehensive assessment of risk, whether for a single asset, groups of assets, or your entire enterprise, enabling more informed and effective security decisions.
Integration Summary
This table provides a summary of the Balbix integration for the Lacework connector.
Integration Type | Fetch: An inbound API integration used to fetch cloud workloads, containers, software and vulnerabilities. |
Types of Assets Fetched | Host devices including servers, virtual machines, containers. |
Types of Data Fetched | Asset names, hardware information, interface information (MAC address, IP address), OS information, software information, vulnerabilities information. |
Prerequisites
To configure the Balbix connector, you must first create Lacework API credentials with the appropriate permissions. These credentials are required for completing the configuration process. Here are the steps you need to complete:
Create an API Key
To generate an API key from Lacework:
Go to Settings > Configuration > API keys.
Select the User API Keys tab to add a key for a human user, or the Service User API Keys tab for programmatic API users, such as scripts or integrations.
Click + Add New.
Enter a name for the key and an optional description.
Toggle on Assign this to a service user to have the API key emulate a service user, then select the assigned service user from the drop-down menu.
Click Save.
Download the generated API key file, then open it in an editor to access the key ID and secret for your API requests.
Caution: If an API key is created by an administrator who is later downgraded to a user role, the API key will no longer work for generating tokens or accessing the Lacework API.
Create and Configure the Connector
After you have completed the prerequisites, follow these steps to create and configure your Balbix connector for Lacework.
API Reference Documentation
To learn more about the Lacework API, see the references listed below: