Skip to main content

Stream Keeper Security Events

Follow this step by step guide to allow SlashID to monitor and protect your Keeper Security environment.

Step 1: Configure External Logging

  1. Log in to the Keeper Admin Console, and navigate to 'Reporting and Alerts' > 'External Logging'.

Navigate to 'External Logging'

  1. Select 'Sumo Logic' from the list of available SIEM integrations.
info

SlashID functions as a Sumo Logic-compatible endpoint. You do not need a separate Sumo Logic account.

Configure the target

  1. In the configuration window:
    1. Enter https://api.slashid.com/nhi/events/v2/keeper_account in the 'HTTP Source Address' field.
    2. Add your SlashID Data Source Event Streaming Token as a query parameter: ?token=<YOUR_TOKEN>.
    3. Click on the 'Test' button to verify the connection.
    4. Once the test succeeds, click on the 'Save' button.

Configure external logging


Verify Configuration

  • Execute a connection test; success enables the Save button.
  • Allow several minutes for logs to begin flowing after configuration.
  • Keeper logs contain details of user activity such as logins, password changes, vault access, shared item interactions, and administrative actions.