Skip to content

Rubrik Integration Guide🔗

Rubrik's backup and recovery cybersecurity tool is a cloud-based solution that secures and automates data protection across hybrid and multi-cloud environments. It integrates with various security frameworks, providing a centralized platform for backup, data recovery, ransomware detection, and compliance, ensuring resilient data management and fast data recovery in the event of attacks.

The following instructions are for configuring Rubrik to facilitate log ingestion into Secureworks® Taegis™ XDR.

Data Provided from Integration🔗

Normalized Data Out-of-the-Box Detections Vendor-Specific Detections
Rubrik     Thirdparty

Note

XDR detectors are not guaranteed to be triggered, even if a data source's logs are normalized to a schema associated with a given detector. However, you can create Custom Detection Rules to generate detections based on normalized data from a data source.

Key Steps🔗

The key steps in a Rubrik integration are as follows:

  • Get details of your Rubrik Security Cloud service.
  • Create an API application and a service user.
  • Configure the integration in XDR.

Requirements🔗

The following is required for Rubrik configuration:

  • Access to the Rubrik Security Cloud console.

Add a Rubrik Integration🔗

To integrate Rubrik, you must first gather certain details from Rubrik, then provide them in XDR.

Get the API Details from Rubrik🔗

To get the Rubrik API details you need for integration, do as follows:

  1. Log in to Rubrik Security Cloud.
  2. Click the Square grid icon and select Settings.
  3. In Settings, go to Users and Access > Service Accounts.
  4. In Service Accounts, click Add Service Account.

    The Service Account Details assistant starts.

  5. Enter a Name and Description for the service account.

  6. Click Next.

    The Roles assistant starts.

  7. Select the roles to be assigned to the service account.

  8. Click Add.

    Rubrik Security Cloud creates the service account, then displays the client credentials and Access Token URI.

  9. Copy the Client ID and Client Secret. You'll need to use them later in XDR.

  10. Pull the Base URL from the Access Token URI, in the following form: https://<account>.my.rubrik.com. You'll need to use it later in XDR.

Configure the Integration in XDR🔗

To integrate Rubrik with XDR, do as follows:

  1. From the Taegis Menu, go to Integrations > Cloud APIs.
  2. Click Add an Integration.
  3. From the Optimized tab, select Rubrik.
  4. Enter a name for the integration.
  5. Enter the following details you got from Rubrik:

    • Base URL
    • Client ID

      Note

      Make sure you enter the Client ID in the format client|<UUID>. For example, client|a5cc86be-5f95-42c3-9f3e-540b8e79dcdc.

    • Client Secret

  6. Click Done.

Once the above steps are completed, Rubrik integration details are available under Integrations > Cloud APIs.

Additional Resources🔗

For more information on configuring Rubrik, see the following documents: