How It Works
All available log messages in the Enterprise dashboard, such as login activity, password changes, and form fill attempts, will be passed to a Splunk Cloud instance, where you can then create custom reports using that data. This allows you to use the advanced functionality of Splunk Cloud to access and report on your LastPass Enterprise activity. To take advantage of this integration, you need a running Splunk Cloud instance with a configured Data Input as HTTP Event Collector. 1) Create Splunk instance - If your company isn’t currently using Splunk, you can simply start a trial. Be sure to select one of their cloud-based services (Splunk Light. or Splunk Cloud)Once you have an account or are logged in to your existing Splunk account, you’ll want to create a Splunk instance for the data you’ll be sending over from LastPass Enterprise. You can create a new instance from your customer portal, as well as give users access to that instance and more. 2) Set up HTTP event collector - Within that instance, you can now set up the data inputs that will be sent from LastPass. For example, you’ll be able to send to Splunk all types of event logs, including user event, shared folder, admin and notification event logs. To do so, you’ll need to configure an HTTP Event Collector which authenticates the access using tokens. Within your LastPass instance in Splunk, follow the steps to create the HTTP event collector and generate the token and destination URL. 3) Bind Splunk to LastPass - Once you have the token and URL, go back to your admin dashboard in LastPass. From the left-hand menu, click Advanced Options and select Enterprise Options. Then click “Splunk Integration” on the next screen, and add the token and URL in the designated fields. Click Update and the data integration will begin; it will take no more than 24 hours to complete, and it’s likely it will take much less time.
4) Receive Raw Data - When the raw data is received into your Splunk instance from LastPass, you’ll see the event logs loaded into the LastPass instance in Splunk. Using that data, you can create and define new reports using the complete functionality of Splunk that you’re already using for your corporate data.




