AlienVault OTX
Integrate AlienVault Open Threat Exchange (OTX) with Cloudaware to stream threat intelligence logs to Cloudaware Log Management (Conflux) for security analysis and investigation.
info
- Audience: Cloudaware administrators, security operations teams, threat intelligence teams, and incident response teams
- Outcome: The AlienVault OTX API key is added, and logs are streamed to Conflux (Log Management)
Capabilities
The integration supports:
- AlienVault OTX API key registration in Cloudaware
- Threat intelligence log streaming to Cloudaware Log Management (Conflux)
Prerequisites
Before you begin, make sure you have:
- Access to a Cloudaware account.
- A user with access to the Admin Console and permissions to manage cloud accounts, organizations, and integrations (Cloudaware Administrator).
- AlienVault OTX account.
- AlienVault OTX API key with read access to the required threat intelligence data.
Add an AlienVault OTX API Key to Cloudaware
To connect your AlienVault OTX API key to Cloudaware:
- In Cloudaware, go to Admin.
- Find AlienVault OTX, then click + ADD.
- Enter the following values:
- Name: A display name for this connection
- API Key: The AlienVault OTX API key
- Click SAVE.
- Confirm that the integration status indicator is green.
tip
Allow the initial discovery cycle to complete after enabling the integration.
View AlienVault OTX Data in Cloudaware Log Management
- Open the Cloudaware Control Hub (Launcher).
- Open the Conflux app.
- Review AlienVault OTX logs in the Log Management workspace.
Troubleshooting
note
Initial data collection may take time to complete.
Authentication Failed or Integration Shows Red Status
- Confirm that the AlienVault OTX API key is active.
- Verify that the API key was copied without extra spaces or line breaks.
- Confirm that the AlienVault OTX account is active and can access the required threat intelligence data.
- Re-enter the API key by editing the integration in Cloudaware.
No Data Appears Several Hours After a Successful Save
- Allow the initial discovery cycle to complete.
- Confirm that the AlienVault OTX account has access to pulses or indicators.
Still stuck? Contact Cloudaware Support at support@cloudaware.com with the integration name and a brief description of the issue.
Reconfigure or Remove the Integration
warning
To rotate credentials, edit the existing integration instead of deleting and re-creating it.
Update the Integration Details
- Go to Admin.
- Select AlienVault OTX.
- Select the specific integration.
- Open the three-dot menu (⋮), then click Edit.
- Update the required fields.
- Click Save.
Remove the Integration from Cloudaware
- Go to Admin.
- Select AlienVault OTX.
- Select the specific integration.
- Open the three-dot menu (⋮), then click Delete.
- Confirm the deletion if prompted.
Security Notes
- Use a dedicated AlienVault OTX API key with the minimum required read access.
- Rotate the API key according to your organization's credential-rotation policy.
- Update the Cloudaware AlienVault OTX integration immediately if the API key is revoked or regenerated in AlienVault OTX.
- Credentials are stored securely and are only visible to Cloudaware collector.