TEAM: Huntress Managed Security Information and Event Management (SIEM)
PRODUCT: HTTP Event Collector (HEC) Syslog
ENVIRONMENT: LastPass
SUMMARY: Configuration Guide for LastPass
Vendor Information
Vendor |
LastPass |
---|---|
Supported Model Name/Number |
N/A |
Supported Software Version(s) |
LastPass Business (or higher) |
Collection Method |
HTTP Event Collector |
Provider Name |
LastPass |
Additional Information |
You must be an Account Administrator in Huntress in order to follow the steps below.
If the options don't appear available to you, please confirm you have the appropriate LastPass licensing.
Configuration Checklist
-
Create Token
-
Open Huntress Portal
- Click SIEM on the left navigation menu
- Click Source Management
- Click Add Source
- Click LastPass
- Click Add
- Provide a name for the Integration and an optional description.
- Click Save
- Copy the HTTP Event Collector Token value
-
- Configure Integration in LastPass
-
-
- Log into LastPass Admin Console
- Click More
- Click Advanced
- Click Integrations
- Click SIEM Integrations
- Click Splunk
- In the Splunk Instance URL field, enter https://hec.huntress.io
- In the Token, paste the value from step 9 in the previous step.
- No Instance name is required
- Select Enabled
- Click "Save Changes"
-
-