How do I integrate Splunk with my LastPass Enterprise account?

All available events that take place in the LastPass Enterprise Admin Console (e.g., login activity, Master Password changes, form fill attempts, etc.) can be passed to a Splunk Cloud instance, where you can then create custom reports using that data. This allows you to use the advanced functionality of Splunk Cloud to access and report on your LastPass Enterprise activity. To take advantage of this integration, you need a running Splunk Cloud instance with a configured Data Input as HTTP Event Collector.

Required for setup:

  • Splunk account (Splunk Lite or Splunk Cloud only)
  • LastPass Enterprise account

Step #1: Configure your Splunk Cloud instance

  1. Follow the instructions to Enable HTTP Event Collector for your Splunk Cloud instance.
  2. Copy the following values and save them to a text editor:
    • Splunk Instance Token
    • Splunk Instance URL (e.g.,

Step #2: Set up the Splunk integration in LastPass Enterprise

  1. Log in and access the Admin Console at!/dashboard.
  2. Go to Advanced OptionsEnterprise OptionsSplunk Integration.
  3. Enter your Splunk Instance Token and Splunk Instance URL that you copied from Step #1 above.

    Note: Do not add the "input-" prefix to the URL of the instance and use the port number.

  4. Click Update when finished.

Configure Splunk Integration


Advanced LastPass Admin Options