HarfangLab is an Endpoint Detection and Response (EDR) solution certified by ANSSI (the French national cybersecurity agency). It detects and blocks known and unknown threats on endpoints using behavioral analysis, machine learning, and event correlation, and can propagate blocking information to other endpoints across the fleet.
This connector queries the HarfangLab API to produce indicators (numerical values tracked over time on a perimeter) for a single module, dedicated to EDR.
This article is for Tenacy Admins in charge of configuring connectors.
This connector collects the following information:
Agents: antivirus coverage, scan coverage, number of agents, online agents, agents in error.
Alerts: critical alerts, breakdown by alert severity, number of alerts.
Jobs: number and success rate of jobs.
Add and configure the connector
To add this connector, go to Catalog > Connectors > HarfangLab > Add connector.
After adding it, you must configure:
Operating perimeter: the perimeter that operates and dictates EDR rules. Indicators will be attached here by default.
Frequency: how often the HarfangLab API is queried and indicators are updated (daily, weekly, monthly, half-yearly, or yearly).
Once the connector is created, configuration continues with the HarfangLab connection credentials:
HarfangLab connection URL: the URL used to access the HarfangLab console, including the port at the end of the URL.
HarfangLab API key: the key generated by a HarfangLab user to authenticate the connector.
History period: the period over which data is analyzed and retrieved on each connector run. It's recommended to match this to the connector's frequency for consistent comparisons since the last run.
⚠️ The API key grants access to all the information that the user who generated it can themselves view in HarfangLab, no filtering is possible. Make sure to use an account whose visibility scope matches what you want to bring into Tenacy.
💡 To generate an API key, sign in to the HarfangLab console, click the avatar in the bottom left, then "Personal Settings", and either copy the existing token or click "Generate Token".
What metrics are collected?
This connector feeds a large number of metrics, grouped below by theme.
Alerts
Alerts: alerts detected within the history period
New alerts: alerts with "New" status during the history period
Low alerts: low-severity alerts detected within the history period
Medium alerts: medium-severity alerts detected within the history period
High alerts: high-severity alerts detected within the history period
Critical alerts: critical alerts detected within the history period
Suspicious behaviors: number of security events identified as suspicious behavior
Potential malware: number of security events identified as potential malware
Agents
Agents: number of agents recorded
Online agents: agents detected as online by HarfangLab
Agents with active antivirus: agents with an antivirus profile (avprofile) defined
Agents without antivirus: agents without an antivirus profile defined
Agents with antivirus not enabled: agents whose antivirus profile isn't applied
Jobs
Jobs: number of jobs
Cancelled jobs
Jobs in error
Completed jobs
Policies
Policies in error: agents with a log-level policy in error
Policies in alert: agents with a log-level policy in warning
Run your first test
Once the connector is properly configured, test the integration by running an initial execution.
Go to ⚙️ > Connectors > click on the HarfangLab connector > Run now:
💡 Feel free to contact Tenacy support if you have any questions regarding this.
Expected result
Once the test runs successfully, the connector automatically queries the HarfangLab API according to the chosen frequency. Indicators on alerts, agents, jobs, and policies start updating on the configured operating perimeter.
FAQ
Can I restrict the data accessible via the API key?
No, no filtering is possible: the key grants access to all the information that the user who generated it can themselves view in HarfangLab.
What happens if I choose a history period different from the connector's frequency?
The connector will still work, but comparing data between two successive runs may be less meaningful. It's recommended to match the two values.
How do I generate a HarfangLab API key?
Sign in to the HarfangLab console, click the avatar in the bottom left, then "Personal Settings", and either copy the existing token or click "Generate Token".
Does this connector let me sync gaps in Tenacy?
No, this connector only feeds indicators for the EDR module. It doesn't offer gap synchronization.




