Skip to main content

Cloud ConnectorsExabeam Cloud Connectors Configuration Guide

Ping Identity Cloud Connector

Prerequisites to Configure the Ping Identity Cloud Connector

Before you configure the Ping Identity connector you must complete the following prerequisites:

  • Create a new Ping Identity administrator user for the Exabeam cloud connector configuration

  • Assign Audit and Report administrator role to the administrator

  • Note the username, account ID, and password of the administrator that you created

  • Obtain subscription IDs for the required endpoints

Create an Administrator

To create an administrator:

  1. Log in to the PingOne administrator portal as an administrator.

  2. Navigate to Account > Administrators.

  3. Click Add Administrator.

  4. Enter the required information such as name and email address, then select Audit & Report Administrator in the Role list.

  5. Click Save. PingOne sends an email with a link to set a password to the user. After the user sets a password as prompted, and logs in for the first time via SSO, the user is added to the list of administrators.

Assign Audit and Report Administrator Role

Administrators with the Audit and Report role can manage subscription for audit events, run reports, and access PingOne Dashboard and the Reporting and Subscription pages. Additionally, the administrator can access the API for polling audit events.

If you have created an administrator user with a role other than Audit & Report Administrator, to assign the Audit and Report Administrator role:

  1. Log in to the PingOne administrator portal as an administrator.

  2. Navigate to Account > Administrators.

  3. In the Search box, enter the administrator’s user name for whom you want to assign the role.

  4. Click the administrator’s name whose role you want to change to expand details, then click the edit icon.

  5. In the Role list containing PingOne administrative roles, select Audit & Report Administrator.

  6. Click Save. The role is assigned. For more information see Assign Administrative Roles.

Obtain Subscription IDs

To manage subscriptions for the audit events, you must create poll subscriptions for the administrator. For poll subscriptions, the audit events of a specific type are accumulated and provided to a client pulling those events.

To get the audit events for a Poll subscription and obtain subscription ID:

  1. Log in to the PingOne administrator portal as an administrator.

  2. On the PingOne dashboard, navigate to Reporting > Subscriptions.

  3. Click Add Subscription.

  4. Specify a name for the subscription.

  5. Select the type of event that you want to poll for this subscription.

  6. In Subscription Type area, select Poll, then select a batch size to indicate maximum number of audit events for the polling subscription to retrieve.

  7. Click Done. The Subscriptions page displays the new Poll subscription listed.

  8. On the Subscriptions page, select the Poll subscription that you created, then click the expand icon to view details.

  9. Copy the Poll URL. This URL contains account ID and the poll subscription ID. The poll URL has the following syntax: https://admin-api.pingone.com/v3/reports/<account-Id>/poll-subscriptions/<subscriptionID>/events

    Note the account ID and the subscription ID represented by a string of letters and numbers. For example, in the URL https://admin-api.pingone.com/v3/reports/5733a0b1-ff99-4e59-95e6-58c14831xxxx/poll-subscriptions/8ae7c229-5198-40ae-bb68-b67bb46exxxx/events, the account ID is 5733a0b1-ff99-4e59-95e6-58c14831xxxx and the subscription ID is 8ae7c229-5198-40ae-bb68-b67bb46exxxx.   Use the account ID and the subscription ID to configure the Ping Identity cloud connector.

Configure the Ping Identity Cloud Connector

Ping Identity is a unified platform that provides identity services including multi-factor authentication (MFA), single sign-on (SSO), identity data management, access security, directory, data governance, and intelligent API cyber security. Ping Identity offers its customers intelligent and real-time access to resources to enable them to connect securely to cloud, mobile, devices, SaaS, and APIs. Ping Identity products help to manage sensitive data, prevent security breaches, and improve user engagement. For more information see the Ping Identity documentation.

The following table lists the audit source API and security events supported by the connector.

Audit Source: API

Service or Module Covered

Administrator login

Provide admin login success and login failed events

Administrator activity

  • Provide admin events such as admin created, deleted, invitation mail sent and property updated

  • Provide application events such as app created, deleted, updated, added to group, removed from group

  • Provide group events such as group created or deleted

  • Provide updates in the authentication policy

Ping ID administrative activity

Provide events such as updates in general settings updated, changes in authentication properties and account updates

Directory

Provide user updates events such as delete, create, password changed, and password policy updates

Provisioning

Provide group updates events and user updates events

SSO

Provide SSO events such as init connection with SSO, successful connection, and failure of connection

Ping ID

Provide device events such as device paired or unpaired, and device wipe success or time out

Table 23. Audit source API and security events supported by the connector


To configure the Ping Identity connector to import data into the Exabeam Cloud Connector platform:

  1. Complete the Prerequisites to Configure the Ping Identity Cloud Connector.

  2. Log in to the Exabeam Cloud Connectors platform with your registered credentials.

  3. Navigate to Settings > Accounts > Add Account.

  4. Click Select Service to Add, then select Ping Identity from the list.

  5. Enter the required information. Required fields are indicated with a red bar.

    1. Tenant – Select a tenant to attach to the connector if you are using a multi-tenant edition of Exabeam. Otherwise, select default.

    2. Account Name – Specify a name for the Ping Identity connector. For example, Ping_Identity_MFA_SSO.

    3. Description – Describe the Ping Identity connector (optional). For example, Ping access security through MFA and SSO.

    4. Username – Enter the user name of Ping Identity administrator.

    5. Account ID – Enter the account ID that you obtained while completing prerequisites.

    6. Password – Enter the password for the Ping Identity administrator.

    7. Subscription ID – Enter the appropriate subscription IDs for the endpoints that you want to use. You obtained the subscription IDs while completing prerequisites.

  6. To confirm that the Exabeam Cloud Connector platform communicates with the service, click Test Connection.

  7. Click Done to save your changes. The cloud connector is now set up on the Exabeam Cloud Connector platform.

  8. To ensure that the connector is ready to send and collect data, Start the connector and check that the status shows OK.