# AQUILA - Digital Guardian Integration

##### Integrating **Digital Guardian (DG)** with **AQUILA** for security log ingestion typically involves exporting logs from DG and then parsing and ingesting them into **AQUILA.**

##### **Digital Guardian** is a Data Loss Prevention **(DLP)** and endpoint protection tool. It logs:

- ##### Data access
- ##### File operations (copy, move, print, etc.)
- ##### Application usage
- ##### User behavior analytics

##### **Goal:** Extract these logs and ingest them into **AQUILA** to enable searching, visualization, and alerting.

##### **<span class="TextRun SCXW54660973 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW54660973 BCX8">Digital Guardian</span></span>**<span class="TextRun SCXW54660973 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW54660973 BCX8">'s native integration with </span></span>**<span class="TextRun SCXW54660973 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW54660973 BCX8">Aquila Agent</span></span>**<span class="TextRun SCXW54660973 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW54660973 BCX8"> requires:</span></span><span class="EOP SCXW54660973 BCX8" data-ccp-props="{}"> </span>

- ##### <span class="TextRun SCXW54660973 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW54660973 BCX8">ARC Server URL</span></span><span class="EOP SCXW54660973 BCX8" data-ccp-props="{}"> </span>
- ##### <span class="TextRun SCXW54660973 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW54660973 BCX8">Authorization Server URL</span></span><span class="EOP SCXW54660973 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"> </span>
- ##### <span class="TextRun SCXW54660973 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW54660973 BCX8">ARC Export Profile ID</span></span><span class="EOP SCXW54660973 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"> </span>
- ##### <span class="TextRun SCXW54660973 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW54660973 BCX8">Client ID</span></span><span class="EOP SCXW54660973 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"> </span>
- ##### <span class="TextRun SCXW54660973 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW54660973 BCX8">Client Secret</span></span>

##### <span class="EOP SCXW54660973 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW48505150 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW48505150 BCX8">W</span><span class="NormalTextRun SCXW48505150 BCX8">orking</span><span class="NormalTextRun SCXW48505150 BCX8"> with the </span></span>**<span class="TextRun SCXW48505150 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW48505150 BCX8">Digital Guardian ARC Cloud API</span></span>**<span class="TextRun SCXW48505150 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW48505150 BCX8"> (Advanced Reporting &amp; Correlation), which is used to export events via a secure API.</span></span></span>

##### <span style="color: rgb(53, 152, 219);">**<span class="EOP SCXW54660973 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW48505150 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW48505150 BCX8">Steps on getting the required information before integrating it to AQUILA</span></span></span>**</span>

##### <span style="color: rgb(53, 152, 219);">**<span class="EOP SCXW54660973 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW48505150 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW48505150 BCX8">1. ARC Server URL</span></span></span>**</span>

- ##### <span class="EOP SCXW54660973 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW48505150 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW48505150 BCX8">This is the base URL for the **Digital Guardian ARC cloud instance**.</span></span></span>
- ##### <span class="EOP SCXW54660973 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW48505150 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW48505150 BCX8">It looks like:</span></span></span>
    
    
    - ##### <span class="EOP SCXW54660973 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW48505150 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW48505150 BCX8">**<span class="TextRun SCXW229902446 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW229902446 BCX8">https://arc.digitalguardian.com</span></span>**</span></span></span>
- ##### <span class="EOP SCXW54660973 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW48505150 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW48505150 BCX8"><span class="EOP SCXW229902446 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW108183864 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW108183864 BCX8">Sometimes </span><span class="NormalTextRun SCXW108183864 BCX8">it's</span><span class="NormalTextRun SCXW108183864 BCX8"> region-specific (e.g., EU or US </span><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW108183864 BCX8">ARC</span><span class="NormalTextRun SCXW108183864 BCX8"> instance).</span></span></span></span></span></span>

##### <span style="color: rgb(53, 152, 219);">**<span class="EOP SCXW54660973 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW48505150 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW48505150 BCX8"><span class="EOP SCXW229902446 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW108183864 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW108183864 BCX8">2. Authorization Server URL</span></span></span></span></span></span>**</span>

- ##### <span class="EOP SCXW54660973 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW48505150 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW48505150 BCX8"><span class="EOP SCXW229902446 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW108183864 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW108183864 BCX8">This is the OAuth2 token server used for authenticating API calls.</span></span></span></span></span></span>
- ##### <span class="EOP SCXW54660973 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW48505150 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW48505150 BCX8"><span class="EOP SCXW229902446 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW108183864 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW108183864 BCX8">It may look like:</span></span></span></span></span></span>
    
    
    - ##### **<span class="EOP SCXW54660973 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW48505150 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW48505150 BCX8"><span class="EOP SCXW229902446 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW108183864 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW108183864 BCX8">https://auth.digitalguardian.com</span></span></span></span></span></span>**
- ##### <span class="EOP SCXW54660973 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW48505150 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW48505150 BCX8"><span class="EOP SCXW229902446 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW108183864 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW108183864 BCX8">Or it may be included in your API documentation.</span></span></span></span></span></span>

##### <span style="color: rgb(53, 152, 219);">**<span class="EOP SCXW54660973 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW48505150 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW48505150 BCX8"><span class="EOP SCXW229902446 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW108183864 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW108183864 BCX8">3. ARC Export Profile ID</span></span></span></span></span></span>**</span>

- ##### <span class="EOP SCXW54660973 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW48505150 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW48505150 BCX8"><span class="EOP SCXW229902446 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW108183864 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW108183864 BCX8">This is a **profile ID** that determines which logs (event types, time windows, etc.) are exported via the API.</span></span></span></span></span></span>
- ##### <span class="EOP SCXW54660973 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW48505150 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW48505150 BCX8"><span class="EOP SCXW229902446 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW108183864 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW108183864 BCX8">It is **configured by a DG admin** inside the **DG Management Console** under the **ARC export profiles** section.</span></span></span></span></span></span>
- ##### <span class="EOP SCXW54660973 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW48505150 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW48505150 BCX8"><span class="EOP SCXW229902446 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW108183864 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW108183864 BCX8">Steps for the DG Admin:</span></span></span></span></span></span>
    
    
    - ##### <span class="EOP SCXW54660973 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW48505150 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW48505150 BCX8"><span class="EOP SCXW229902446 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW108183864 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW108183864 BCX8">Log in to the **Digital Guardian Console**.</span></span></span></span></span></span>
    - ##### <span class="EOP SCXW54660973 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW48505150 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW48505150 BCX8"><span class="EOP SCXW229902446 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW108183864 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW108183864 BCX8">Go to **ARC &gt; Export Profiles**.</span></span></span></span></span></span>
    - ##### <span class="EOP SCXW54660973 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW48505150 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW48505150 BCX8"><span class="EOP SCXW229902446 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW108183864 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW108183864 BCX8">Create or view an export profile with appropriate filters.</span></span></span></span></span></span>
    - ##### <span class="EOP SCXW54660973 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW48505150 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW48505150 BCX8"><span class="EOP SCXW229902446 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW108183864 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW108183864 BCX8">Copy the **Export Profile ID** from the profile details.</span></span></span></span></span></span>

##### <span style="color: rgb(53, 152, 219);">**<span class="EOP SCXW54660973 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW48505150 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW48505150 BCX8"><span class="EOP SCXW229902446 BCX8" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"><span class="TextRun SCXW108183864 BCX8" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW108183864 BCX8">4. Client ID &amp; Client Secret</span></span></span></span></span></span>**</span>

- ##### These are **OAuth2 credentials** used to authenticate your API access.
- ##### Generated via the **API client registration** feature in the DG admin interface.
- ##### Steps for the DG Admin:
    
    
    - ##### Log into the **Digital Guardian ARC Console**.
    - ##### Navigate to **ARC &gt; API Clients / Applications**.
    - ##### Register a new application.
        
        
        - ##### Assign the **Export Profile ID**.
        - ##### Set appropriate scopes (usually “read:events”).
    - ##### A **Client ID** and **Client Secret** will be generated.
- ##### <span style="color: rgb(224, 62, 45);">**IMPORTANT:**</span> The **Client Secret** is shown **only once**, so it must be secure.

##### <span style="color: rgb(53, 152, 219);">**Sample Information needed from DG Admin**</span>

![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-07/scaled-1680-/aIg9wT1ZxDHHmqsO-image.png)

##### **<span style="color: rgb(53, 152, 219);">Integration to AQUILA</span>**

##### 1. Log in to **CyTech - AQUILA.** Choose **Cyber Monitoring -&gt; Cyber Incident Management -&gt; Settings.**

![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-07/scaled-1680-/N7sU1IleMKmImW9I-image.png)

##### 2. Click **Log Source.** In the text box type **Digital Guardian,** the log source will show up and click the **Add to Agent.**

![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-07/scaled-1680-/tsyvf6xOZ77kmluq-image.png)

##### 3. Choose the **Log Collector** name you installed. Click the **+** sign.

![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-07/scaled-1680-/J7zI6S464bkgog6F-image.png)

##### 4. Enable the **Collect Digital Guardian logs via API.**

![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-07/scaled-1680-/pubk5K9SwdzGLx61-image.png)

##### 5. Paste the information you gather on each text box. **ARC Server URL, Authorization Server URL, ARC Export Profile ID** and **Client ID.** Then scroll down.

![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-07/scaled-1680-/aQ8o3ErKxKE3R8D4-image.png)

##### 6. Paste the information you gather on each text box. **Client Secret,** then click the **Tags** text box, it will show 2 tags you will need to add.

![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-07/scaled-1680-/FirlaPXX87KYroNI-image.png)

![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-07/scaled-1680-/Z9wdqStiTA5QwCEz-image.png)

##### 7. Then click **Next** so that the integration will process the information you inputted.

![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-07/scaled-1680-/beYymD1SrgPo7Get-image.png)

##### 8. Wait for the **Successful** window to display, this will confirm the successful integration.

![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-07/scaled-1680-/m7vXAsPPI420XzRI-image.png)

*If you need further assistance, kindly contact our support at **support@cytechint.com** for prompt assistance and guidance.*