For the complete documentation index, see llms.txt. This page is also available as Markdown.

CrowdStrike Falcon Next-Gen SIEM

Integrating Keeper SIEM push to Crowdstrike Falcon Next-Gen SIEM

Overview

Keeper supports event streaming into CrowdStrike Next-Gen SIEM. External logging is real-time, and new events will appear within a few minutes. Setup instructions are below.

1

Add the Data Connector

  • From the CrowdStrike dashboard, visit the Data Onboarding > Data Connectors screen.

  • Select "+ Add connection" and search for Keeper.

  • Click "Configure", assign a name, and then "Create connection".

Data connectors
2

Create the API Key

  • From the Data Connector screen, in the Keeper row click the overflow menu and then "Generate API Key".

  • Save the API Key and API URL for the next step.

Create API Key
Copy the API Key and API URL
3

Activate the Integration

  • From the Keeper Admin Console, go to Reporting & Alerts > External Logging.

  • Select CrowdStrike Falcon Next-Gen SIEM.

  • Provide the API Key and API URL from Step 2.

  • Click Test and then Save.

Setup Complete!

When audit events are sent from Keeper to CrowdStrike, the data will begin to populate in the "Third Party" source within minutes.

Event Logs in CrowdStrike

Last updated

Was this helpful?