Before you can receive and view PCAPs on Helix, you must create an API key that you will provide to the network sensor operations team. Use the following procedure to generate the key.
Note
Your account privileges determine the entitlements visible to you during this procedure. If you have problems or questions, see your account administrator.
Note
For further information, see the Trellix System Security Guide topic "Creating an API key."
Important
There are two versions of IAM. If the URL you use to access the IAM UI ends with
fireeye.com, this document pertains to you. If the URL you use to access the IAM UI ends withtrellix.com, see the Trellix IAM Guide for information regarding IAM.
To create the API key:
From the main menu, select your avatar and then select Identity Access Management.
In your Cloud IAM Web UI, select API Keys.
Select Create API Key in the upper right corner of the Manage API Keys page. You can also use this page to manage other API keys you have created.
Provide a name and expiration period for the API key. Set the product to Threat Analytics Platform.
Click Next.
In the Available Entitlements for TAP list on the left side of the page, click Grant for all entitlements beginning with
tap.pcap*to move each to the Selected Entitlements list on the right.Verify that you have all
tap.pcap*entitlements selected, and click Create API Key.At the bottom of the page, click
to copy your API to the clipboard or click
to download it.Provide your API key to the Network Sensor Operations team so they can complete the process that allows PCAPs to be sent from your network sensors to your Helix Enterprise instance.