You can configure the ExtraHop integration to post data to Moogsoft AIOps when an alert occurs in ExtraHop.
Refer to the REST LAM Reference to see the integration's default properties. When you use the integrations UI, you can only configure the visible properties.
If you want to implement a more complex ExtraHop LAM with custom settings, see Configure the ExtraHop LAM.
See the ExtraHop documentation for details on ExtraHop components.
Before You Begin
The ExtraHop integration has been validated with ExtraHop 7.4. Before you start to set up your ExtraHop integration, ensure you have met the following requirements:
- You have an active ExtraHop account.
- You have the necessary permissions to access system configuration and add data stream targets in ExtraHop.
- ExtraHop can make requests to external endpoints over port 443.
Configure the ExtraHop Integration
Configure the ExtraHop integration in Moogsoft AIOps as follows:
- Navigate to the Integrations tab.
- Click ExtraHop in the Monitoring section.
Provide the connection details to create the integration.
Log in to ExtraHop to configure a data stream target and trigger to send alert data to your system. For more help, see the ExtraHop docs.
Create a new data stream target connection in ExtraHop with the following details:
Field Value Name Moogsoft AIOps Host
<your ExtraHop integration URL>
Copy the URL and paste into ExtraHop withoutfor example:
Port 443 Type HTTPS Authentication Basic Username
<Username that Moogsoft AIOps generates in the UI>
<Password that Moogsoft AIOps generates in the UI>
Test the target configuration with the following details:
Field Value Method GET Options
Ensure new configuration has been saved and is running.
Create an ExtraHop trigger with the following details:
Field Value Name Moogsoft AIOps Events ALERT_RECORD_COMMIT
Add the following trigger script. The value of REST_DEST must match the name of your data stream target.
Once you complete the configuration, ExtraHop sends new alerts to Moogsoft AIOps.