For the complete documentation index, see llms.txt. This page is also available as Markdown.

Alerts and SIEM Integration

Monitoring Gateway events and integrating with your SIEM

Overview

KeeperPAM supports integration with your SIEM provider to provide real-time event logging and monitoring of all privileged access management activity. In the Keeper Admin Console, alerts can also be configured based on any event.

For more information on activating SIEM integration from the Keeper Enterprise guide:

Features

  • Push over 300 different event types to any connected SIEM provider

  • Send alerts to email, SMS, Webhook, Slack or Microsoft Teams on any event trigger

  • Integrate with ITSM products like ServiceNow and Jira

  • Run custom reports from the Keeper Admin Console or Keeper Commander CLI

KeeperPAM Events

Events related to KeeperPAM include:

  • Starting and stopping sessions, tunnels, remote browser isolation

  • Just-in-time (JIT) access requests, access approvals and access denies

  • Gateway lifecycle (online, offline, added/removed)

  • Connection lifecycle (creation, editing and deleting PAM resources)

  • Endpoint Privilege Manager elevation requests, file access executions, AI agent access

KeeperPAM Events
Just-In-Time Access Requests

Dashboards, metrics and audit reporting

KeeperPAM includes built-in dashboards and reporting to measure JIT activity and policy effectiveness.

  • Centralized dashboard - The Keeper Admin Console provides a default dashboard that shows recent privileged access activity, including JIT requests and privilege elevation events.

  • Advanced Reporting & Alerts - The dashboard helps you monitor approval requests, approvals, session starts, session terminations, and elevation activity.

  • Session auditing - All privileged sessions, including JIT sessions, are logged for review and analysis.

  • SIEM streaming - Access events can stream directly to external SIEM platforms for centralized monitoring and correlation.

Useful metrics include:

  • Frequency of privilege elevation

  • Number of active privileged accounts, including ephemeral accounts

  • Discretionary access events

  • Number of users who requested or received discretionary access

Audit and compliance

Every JIT access event, privilege elevation event, and account creation or deletion is logged for audit and compliance purposes.

Use these logs to generate reports, demonstrate compliance, and analyze privileged access trends over time.

Policy tuning

Use dashboard data to evaluate approval rules, time limits, and elevation policies.

This helps enforce least privilege and zero standing privilege more consistently.

As a KeeperPAM administrator, it is useful to receive alerts related to Gateway actions, such as when a Gateway goes offline (in case of server outage or system restart).

From the Admin Console, go to Reporting & Alerts > Alerts > select Event Types and set the recipient information.

Set Alert for Gateway Offline

Event alert details will include the name and UID of the affected Keeper gateway.

Gateway Offline Alert

Email alerts contain event information

Email Alert for Gateway Offline

Integrations

Keeper integrates with ITSM platforms for realtime ticket creation, alerting and incident response.

Last updated

Was this helpful?