Keeper Security Password Manager

SamurAI [Local] CollectorSamurAI [Cloud] Collector
Picture1.svg

This integration ingests security event data from Keeper Security Password Manager using Keeper’s built-in SIEM push capability, delivered to the SamurAI platform via Splunk HTTP Event Collection (HEC).

Prerequisites

Ensure that a Samurai Cloud Collector of type Splunk HTTP Event Collector (HEC) has been deployed via the SamurAI Portal. 

If you are planning to reuse an already deployed Samurai HEC Cloud Collector you will need (displayed only upon creation):

  • API URL
  • Token

Activate the Integration in Keeper

For additional information you can refer to the Keeper documentation on Splunk integration.

To configure Keeper to push events to the SamurAI HEC Cloud Collector, follow the steps below:

  1. Log in to the Keeper Admin Console

  2. Navigate to Reporting & Alerts in the left menu

  3. Click Setup next to the external logging option

  4. Select Splunk as the integration type

  5. Perform the following steps using the values recorded from the SamurAI HEC Cloud Collector:

    5.1 In the Host field, enter the API URL of the SamurAI HEC Cloud Collector

    5.2 In the Port field, enter 443

    5.3 In the Token field, enter the SamurAI HEC Cloud Collector Token

  6. Click Test Connection to verify that Keeper can reach the SamurAI HEC Cloud Collector

  7. Once the test is successful, click Save to activate the integration

Once activated, security event data will begin appearing in the SamurAI platform within 15 minutes.

Our Integration guide was accurate at the time of writing but vendors change things frequently! If you find errors or anything is outdated, let us know by raising a request in the SamurAI MDR Portal and we shall get it updated.