Getting started

Prev Next

Before you can use the Endpoint Security (HX) API, perform the following actions:

  • Ensure the Endpoint Security (HX) server is running software version 2.5 or higher.

  • Create one or more Endpoint Security (HX) API user accounts on the Endpoint Security (HX) server.

Creating an API user account on the Endpoint Security (HX) server

To submit API requests to the Endpoint Security (HX) server from a remote system, you need a valid user account on the Endpoint Security (HX) server associated with the api_admin or api_analyst role. For more information about setting up user accounts on the Endpoint Security (HX) server, see the Endpoint Security (HX) System Administration Guide.

The following table lists the remote access privileges on the Endpoint Security (HX) server for each role.

User profile access privileges

Privilege

api_admin

api_analyst

admin

API access

Yes

Yes

Yes

View acquisitions

Yes

Yes

Yes

View cloned agents

Yes

Yes

Yes

Configure agents

Yes

No

Yes

Manage and view alerts

Yes

Yes

Yes

Approve and cancel containment

Yes

No

Yes

View audits

Yes

Yes

Yes

Create data acquisitions

Yes

Yes

Yes

Run enterprise searches

Yes

Yes

Yes

Create file acquisitions

Yes

Yes

Yes

Create host lists

Yes

Yes

Yes

View host lists

Yes

Yes

Yes

Create, update, and delete host sets

Yes

No

Yes

View host sets

Yes

Yes

Yes

Create and view indicators

Yes

Yes

Yes

api_analyst

Users assigned the api_analyst role have only API access to Endpoint Security (HX) features and cannot log into the CLI or the Web UI. This role must be assigned from the Web UI or CLI.

Users assigned the api_analyst role only have basic API authorization for Endpoint Security (HX) features. They cannot change their password. An Endpoint Security (HX) administrator (user role Admin) must change their passwords, if necessary.

api_admin

Users assigned this role have only API access to Endpoint Security (HX) features and cannot log into the CLI or the Web UI. This role must be assigned from the Web UI or CLI.

Users assigned the api_admin role can perform all of the functions of an api_analyst but can also maintain API custom policy channels and can contain hosts using the API. (Custom policy channels are used to distribute custom configuration files to agents running on hosts in specified host sets.) They cannot change their password. An Endpoint Security (HX) administrator (user role Admin) must change their passwords, if necessary.

admin

Users assigned this role have API access to Endpoint Security (HX) features and can also log into the CLI and the Web UI. They can perform all the functions of an api_admin. The admin role must be assigned from the Web UI or CLI.