Anomali ThreatStream
Introduction
This guide explains how to authenticate the Anomali ThreatStream connector in Swimlane using API Key Authentication.
You will generate an API key in Anomali ThreatStream, collect the required authentication details, and configure the connector in Swimlane.
Prerequisites
Anomali ThreatStream Access Requirements
You must have permissions to:
- Access the Anomali ThreatStream platform
- Generate and manage API credentials
- Access ThreatStream Intelligence APIs
- Retrieve observables and threat intelligence data
Required Credentials
During setup, you will collect:
- API URL
- API Key
- API User
Authentication Method Overview
The Anomali ThreatStream connector supports:
- API Key Authentication
Anomali ThreatStream Setup
Take the following steps to generate an API Key:
- Log in to your Anomali ThreatStream instance.
- Navigate to Settings or User Profile.
- Locate the API Access or API Credentials section.
- Generate a new API Key if one does not already exist.
- Copy and securely store:
- API Key
- API User
Take the following steps to identify the API URL:
The API URL is typically your ThreatStream tenant URL.
Example:
https://<your-instance>.anomali.com
Example API endpoint:
https://<your-instance>.anomali.com/api/v2/intelligence
Connector configuration in Swimlane
- Log in to Turbine.
- From the left-hand navigation pane, click ORCHESTRATION and click Assets. Asset homepage opens.
- Click the plus icon to open the Configure your Connector Asset window.
- Select Anomali ThreatStream from the Asset type list.
- Fill in the Asset Settings and Asset Input as shown:
Configuration β API Key Authentication
Field | Description | Required |
|---|---|---|
url | Anomali ThreatStream API URL | Yes |
x-apikey | API Key generated in ThreatStream | Yes |
api_user | API username associated with the API key | Yes |
verify_ssl | Enable or disable SSL verification | No |
http_proxy | Proxy configuration | No |

Troubleshooting
Authentication issues may occur due to:
- Invalid API Key
- Incorrect API User
- Incorrect ThreatStream URL
- Expired or revoked credentials
- SSL verification failures
Fix:
- Regenerate the API Key
- Verify the API User associated with the key
- Confirm the correct tenant URL
- Ensure API access is enabled for the account
- Disable SSL verification temporarily for testing if required
Result
You have successfully authenticated the Anomali ThreatStream connector in Swimlane.
Sources
- Anomali ThreatStream API Documentation: https://docs.anomali.com/platform/docs/rest-apiο»Ώ
- Anomali ThreatStream Main Documentation: https://docs.anomali.com/ο»Ώ