Elastic
Elastic Security for Endpoint stops ransomware and malware, detects advanced threats, collects host data, and streamlines investigation and response — all with one agent.
Authenticating
Elastic uses API Key based auth, a developer-friendly delegated access protocol. Quolum has already connected the necessary wires with Elastic. Using a sequence of click-throughs, your organization's administrator allows Quolum to make API calls to Elastic without getting access to passwords.
Step 1: Initiate a connection to Elastic
Click the Connect button from the Connections card. If you are not an admin, you can invite your organization's Elastic admin to make a connection to your Elastic organization account. When you click on the Connect button, the web browser will navigate to the Elastic login page.

Quolum Catalog: Elastic App
Step 2: Log in to Elastic
Log in to Elastic using your organization's credentials. The exact login mechanism may depend on your Elastic plan, and the sign-in mechanism used. You may have corporate SSO such as Azure AD, GSuite, or Okta along with multi-factor authentication. Once you have successfully logged-in you can find the API Key and API Secret as mentioned below in Step 3.

Elastic Authentication
Step 3: Back to Quolum
Once you have granted access to Quolum, Elastic is going to send you back to Quolum's page in Step 1, where you started. The Connect button on the Connections card would now say Reconnect. Reconnect is used to reauthenticate under circumstances where the access has expired.
Under the hood
Using the OAuth protocol, Quolum now has delegated access to your Elastic Workspace. The Quolum server, running on Amazon AWS VPC, will be able to make API calls and retrieve feature-level utilization. Later, this data is crunched and available for visualization on the Quolum dashboard.
Updated 2 months ago