If you use Arctic Wolf for security monitoring, you can connect JumpCloud Directory Insights® so Arctic Wolf can monitor authentication, access, and directory activity from your organization. Gather an API key and your Organization ID in the Admin Portal, then add JumpCloud Directory Insights in the Arctic Wolf Unified Portal.
Prerequisites
- An administrator account with the Administrator with Billing role in the JumpCloud Admin Portal.
- Directory Insights enabled for your organization. See Get Started: Directory Insights to learn more. If Directory Insights is not enabled, contact your account manager or JumpCloud support at directoryinsights@jumpcloud.com.
Considerations
- Complete these steps for each organization you want Arctic Wolf to monitor.
- Arctic Wolf polls time-based events with a short delay so data is available. For new deployments, Arctic Wolf begins polling and reviewing activity from approximately one hour before configuration succeeds.
- If your API credentials fail (for example, because they expired), Arctic Wolf notifies you and asks for a new set. After you provide refreshed credentials, Arctic Wolf can only retrieve data from the previous 12 hours. Provide refreshed credentials within 12 hours of expiry so polling stays complete.
Configuring JumpCloud
Collect an API key, confirm Directory Insights is enabled, and copy your Organization ID before you configure Arctic Wolf.
To generate an API key
If you do not already have a JumpCloud API key, generate one. Arctic Wolf expects a Custom expiration of 365 days and the credential expiration date. See JumpCloud APIs to learn more.
- Log in to the JumpCloud Admin Portal.
If your data is stored outside of the US, check which login URL you should be using depending on your region. If your organization uses LDAP, RADIUS, or requires firewall allow list configuration, the Fully Qualified Domain Names (FQDNs) will also be region specific. See JumpCloud Data Centers for the URLs, FQDNs, and IP addresses.
- Click your profile icon, and then click My API Key.
- In the API Key window, in the Expiration Date section, select Custom, and then in the Days field, enter 365.
- Copy the expiration date. You enter this value in Arctic Wolf later.
- Click Generate New API Key.
- Copy the API key, and then save it in a safe, encrypted location.
The API key begins with the prefix jca_. You enter this value in Arctic Wolf later.
Directory Insights and Organization ID
Arctic Wolf requires Directory Insights to be enabled and uses your Organization ID as the Org ID when you add the cloud sensor.
- Under Settings > Features, confirm that Directory Insights is enabled. See Settings in the Admin Portal to learn more.
- Under Settings > Organization Profile, copy your Organization ID. See Settings in the Admin Portal to learn more.
- Save the Organization ID in a safe, encrypted location. You enter it in Arctic Wolf later.
Configuring Arctic Wolf
- Log in to the Arctic Wolf Unified Portal.
- Go to Data Collection > Cloud Sensors.
- Click Add Account +.
- On the Add Account page, click JumpCloud Directory Insights.
- Configure these settings:
- Account Name — Enter a unique and descriptive name for the account.
- API Key — Enter the API key you generated in JumpCloud.
- Org ID — Enter the Organization ID you copied from JumpCloud.
- API URL — Select the URL that matches the region of your dashboard. If you do not know the region of your dashboard, select https://api.jumpcloud.com.
- Credential Expiry — Enter the credential expiration date, if applicable.
- Click Test and submit credentials.
After the credentials succeed, Arctic Wolf begins polling Directory Insights for security monitoring. See Configure JumpCloud Directory Insights for Arctic Wolf monitoring to learn more.