Skip to main content

AirLock Digital

Visualize your AirLock Digital application control deployment in JupiterOne — enforcement agents, policy groups and their exceptions, allowlisted applications, application categories, and blocklists — map agents to the hosts they protect, and monitor changes through queries and alerts.

Installation​

This integration connects to your self-hosted AirLock Digital server using the AirLock Digital REST API and ingests enforcement agents, policy groups, allowlisted applications, application categories, and blocklists. The server is usually on your own network, so the integration normally runs on a JupiterOne Collector that can reach the server's REST API over HTTPS (default port 3129).

Configuration in AirLock Digital​

Before you configure the integration in JupiterOne, prepare the following in the AirLock Digital console:

  • The server URL of your AirLock Digital server, including the REST API port, in the format https://server.name:3129. The JupiterOne Collector must be able to reach it.

  • A user whose user group grants the REST API roles the integration needs. In the console, go to Settings, open the Users tab, and under User Group Management select the user's group. In the REST API Roles section, add the roles for the endpoints below, then click Save.

    EndpointNeeded for
    /v1/blocklistCredential validation (always required) and the Blocklists data source
    /v1/agent/findEnforcement Agents
    /v1/group and /v1/group/policiesPolicy Groups
    /v1/applicationAllowlist Applications
    /v1/application/categoriesApplication Categories

    The integration only calls these read endpoints. It never uses write, delete, or settings endpoints.

  • An API key for that user. Log in to the console as the user, open the drop-down menu with the user's name, go to My profile, and click Generate API Key. The user must have the generate_apikey permission. The key is displayed only once, so copy it now.

  • If the server presents a self-signed or internal-CA TLS certificate, get the CA certificate in PEM format so the collector can verify the connection.

Once you have obtained the information above, proceed to JupiterOne to finalize the integration.

Configuration in JupiterOne​

To install the AirLock Digital integration in JupiterOne, navigate to the Integrations tab in JupiterOne and select AirLock Digital. Click New Instance to begin configuring your integration.

Creating an instance requires the following:

  • The Account Name used to identify the AirLock Digital account in JupiterOne. Ingested entities will have this value stored in tag.AccountName when the AccountName toggle is enabled.

  • Description to assist in identifying the integration instance, if desired.

  • Polling Interval that you feel is sufficient for your monitoring needs. You may leave this as DISABLED and manually execute the integration.

  • The Server URL of your AirLock Digital server, for example https://airlock.example.com:3129.

  • The API Key generated above. It is sent in the X-ApiKey request header.

  • Optionally, a CA Certificate to trust a self-signed or internal-CA certificate, or enable Disable TLS Verification to skip certificate validation (not recommended).

  • Optionally, set Agent Statuses to a comma-separated list of the numeric agent status codes reported by /v1/agent/find to ingest only agents in those statuses. Leave it empty to ingest all agents.

  • Optionally, enable Include Hidden Policy Groups to also ingest policy groups marked as hidden. By default, hidden groups are skipped.

Data Sources​

Each data source can be enabled or disabled on its own. All data sources are disabled by default, so enable the ones you want to ingest.

Data SourceDescriptionEntities Created
Enforcement AgentsAirLock Digital agents deployed on devices, with hostname, domain, OS, IP addresses, agent version, and policy versionairlock_agent
Policy GroupsPolicy groups with their mode (audit or enforcement) and their path, publisher, parent-process, and global-process exceptionsairlock_policy
Allowlist ApplicationsAllowlisted application packagesairlock_application
Application CategoriesAllowlist categories and their subcategoriesairlock_application_category
BlocklistsBlocklist packagesairlock_blocklist

The relationships between data sources are built only when both sides are enabled:

  • Agent to policy group (ASSIGNED) requires Enforcement Agents and Policy Groups.
  • Policy group to application (HAS) requires Policy Groups and Allowlist Applications.
  • Policy group to blocklist (HAS) requires Policy Groups and Blocklists.

Each enforcement agent is also mapped to an existing Host entity in JupiterOne with the same hostname, such as a host from your CMDB or another endpoint tool, through a PROTECTS relationship. No new Host entities are created.

Click Create once all values are provided to finalize the integration.

Next steps​

Now that your integration instance has been configured, it will begin running on the polling interval you provided, populating data within JupiterOne. Continue on to our Instance management guide to learn more about working with and editing integration instances.

Additional resources​