Before you can use the Endpoint Security (HX) API, perform the following actions:
Ensure the Endpoint Security (HX) server is running software version 2.5 or higher.
Create one or more Endpoint Security (HX) API user accounts on the Endpoint Security (HX) server.
Creating an API user account on the Endpoint Security (HX) server
To submit API requests to the Endpoint Security (HX) server from a remote system, you need a valid user account on the Endpoint Security (HX) server associated with the api_admin or api_analyst role. For more information about setting up user accounts on the Endpoint Security (HX) server, see the Endpoint Security (HX) System Administration Guide.
The following table lists the remote access privileges on the Endpoint Security (HX) server for each role.
User profile access privileges
Privilege | api_admin | api_analyst | admin |
|---|---|---|---|
API access | Yes | Yes | Yes |
View acquisitions | Yes | Yes | Yes |
View cloned agents | Yes | Yes | Yes |
Configure agents | Yes | No | Yes |
Manage and view alerts | Yes | Yes | Yes |
Approve and cancel containment | Yes | No | Yes |
View audits | Yes | Yes | Yes |
Create data acquisitions | Yes | Yes | Yes |
Run enterprise searches | Yes | Yes | Yes |
Create file acquisitions | Yes | Yes | Yes |
Create host lists | Yes | Yes | Yes |
View host lists | Yes | Yes | Yes |
Create, update, and delete host sets | Yes | No | Yes |
View host sets | Yes | Yes | Yes |
Create and view indicators | Yes | Yes | Yes |
api_analyst
Users assigned the api_analyst role have only API access to Endpoint Security (HX) features and cannot log into the CLI or the Web UI. This role must be assigned from the Web UI or CLI.
Users assigned the api_analyst role only have basic API authorization for Endpoint Security (HX) features. They cannot change their password. An Endpoint Security (HX) administrator (user role Admin) must change their passwords, if necessary.
api_admin
Users assigned this role have only API access to Endpoint Security (HX) features and cannot log into the CLI or the Web UI. This role must be assigned from the Web UI or CLI.
Users assigned the api_admin role can perform all of the functions of an api_analyst but can also maintain API custom policy channels and can contain hosts using the API. (Custom policy channels are used to distribute custom configuration files to agents running on hosts in specified host sets.) They cannot change their password. An Endpoint Security (HX) administrator (user role Admin) must change their passwords, if necessary.
admin
Users assigned this role have API access to Endpoint Security (HX) features and can also log into the CLI and the Web UI. They can perform all the functions of an api_admin. The admin role must be assigned from the Web UI or CLI.