How do I integrate Splunk with my LastPass Business account?
All available events that take place in the LastPass Business Admin Console (e.g., login activity, Master Password changes, form fill attempts, etc.) can be passed to a Splunk Cloud instance, where you can then create custom reports using that data. This allows you to use the advanced functionality of Splunk Cloud to access and report on your LastPass Business activity. To take advantage of this integration, you need a running Splunk Cloud instance with a configured Data Input as HTTP Event Collector.
Required for setup (before May 1, 2021):
- Splunk account (Splunk Lite or Splunk Cloud only)
- LastPass Business account
Step #1: Configure your Splunk Cloud instance
- Follow the instructions to Enable HTTP Event Collector for your Splunk Cloud instance.
- Copy the following values and save them to a text editor:
Important: Port 8080 or 8088 are the only ports that can be used in this configuration.
- Splunk Instance Token
- Splunk Instance URL (e.g., prd-my-instance.cloud.splunk.com:8080)
Step #2: Set up the Splunk integration in LastPass Business
- Log in and access the Admin Console at https://lastpass.com/company/#!/dashboard.
- Go to .
- Enter your Splunk Instance Token and Splunk Instance URL that you copied from Step #1 above.
Note: Do not add the "input-" prefix to the URL of the instance and use the port number.
- Click Update when finished.