Onboarding
Onboarding Overview
Step-by-step guide to onboarding with ThreatSabre, from Agent Token creation and API user setup to device inventory and dashboard access.
Onboarding steps
The recommended way to onboard is to use the Onboarding wizard, which guides you through these steps in the platform.
- In the ThreatSabre platform, under your organization, define a new ThreatSabre Agent (Agent for short) to generate an Agent Token. See Obtaining Your Agent Token.
- Create read-only API admins in FortiManager, FortiManager Cloud, or FortiGate. It is strongly recommended to configure these users with trusted hosts to only allow the IP address of the Agent to use these tokens. Use Obtaining API credentials to pick the right guide for your environment.
- Create your FortiManager(s), FortiManager Cloud instance(s), and/or FortiGate(s) as Agent Devices under the Agent configured in step 1.
- Install the ThreatSabre Agent with your Agent Token.
- Wait a few minutes, then go to Inventory to see the discovered devices and select the devices you wish to add to ThreatSabre.
- After a few minutes these devices will appear in the ThreatSabre dashboard and other views.
Limitations
- Adding the same device via FMG Agent Device type and FGT Agent Device type is not supported.
Security and networking
- The Agent Token provides authentication to the ThreatSabre platform—keep it secure
- The configuration file (/etc/threatsabre-agent/agent.conf) contains sensitive credentials and should be protected (600 permissions)
- The Agent only requires outbound network access—no inbound ports need to be opened