HELP FILE

How do I integrate Splunk with my LastPass Business account?

All available events that take place in the LastPass Business Admin Console (e.g., login activity, Master Password changes, form fill attempts, etc.) can be passed to a Splunk Cloud instance, where you can then create custom reports using that data. This allows you to use the advanced functionality of Splunk Cloud to access and report on your LastPass Business activity. To take advantage of this integration, you need a running Splunk Cloud instance with a configured Data Input as HTTP Event Collector.

Notice: All new setups for the Splunk integration for LastPass are not supported on and after May 1, 2020. All existing instances of the Splunk integration (set up before May 1, 2020) will continue to function.

Required for setup (before May 1, 2021):

  • Splunk account (Splunk Lite or Splunk Cloud only)
  • LastPass Business account

Step #1: Configure your Splunk Cloud instance

  1. Follow the instructions to Enable HTTP Event Collector for your Splunk Cloud instance.
  2. Copy the following values and save them to a text editor:
    • Splunk Instance Token
    • Splunk Instance URL (e.g., prd-my-instance.cloud.splunk.com:8080)
    Important: Port 8080 or 8088 are the only ports that can be used in this configuration.

Step #2: Set up the Splunk integration in LastPass Business

  1. Log in and access the Admin Console at https://lastpass.com/company/#!/dashboard.
  2. Go to Advanced Options > Business Options > Splunk Integration.
  3. Enter your Splunk Instance Token and Splunk Instance URL that you copied from Step #1 above.
    Note:  Do not add the "input-" prefix to the URL of the instance and use the port number.
  4. Click Update when finished.

Configure Splunk Integration