This is the multi-page printable view of this section. Click here to print.

Return to the regular view of this page.

Keeper Security Password Manager

    SamurAI [Local] CollectorSamurAI [Cloud] Collector
    Picture1.svg

    This integration ingests security event data from Keeper Security Password Manager using Keeper’s built-in SIEM push capability, delivered to the SamurAI platform via Splunk HTTP Event Collection (HEC).

    Prerequisites

    Ensure that a Samurai Cloud Collector of type Splunk HTTP Event Collector (HEC) has been deployed via the SamurAI Portal. 

    If you are planning to reuse an already deployed Samurai HEC Cloud Collector you will need (displayed only upon creation):

    • API URL
    • Token

    Activate the Integration in Keeper

    For additional information you can refer to the Keeper documentation on Splunk integration.

    To configure Keeper to push events to the SamurAI HEC Cloud Collector, follow the steps below:

    1. Log in to the Keeper Admin Console

    2. Navigate to Reporting & Alerts in the left menu

    3. Click Setup next to the external logging option

    4. Select Splunk as the integration type

    5. Perform the following steps using the values recorded from the SamurAI HEC Cloud Collector:

      5.1 In the Host field, enter the API URL of the SamurAI HEC Cloud Collector

      5.2 In the Port field, enter 443

      5.3 In the Token field, enter the SamurAI HEC Cloud Collector Token

    6. Click Test Connection to verify that Keeper can reach the SamurAI HEC Cloud Collector

    7. Once the test is successful, click Save to activate the integration

    Once activated, security event data will begin appearing in the SamurAI platform within 15 minutes.

    Our Integration guide was accurate at the time of writing but vendors change things frequently! If you find errors or anything is outdated, let us know by raising a request in the SamurAI MDR Portal and we shall get it updated.