Welcome to the new Splunkbase! To return to the old Splunkbase, click here.
CCX Add-on for Keeper Security Products app icon

CCX Add-on for Keeper Security Products

About Us: CyberCX is Australia’s greatest force of cyber security experts. Our highly skilled professional services team operates a 24x7 on-shore security operations centre (SOC) servicing corporate and public sector organisations across Australia and New Zealand, specialising in Security Operations services leveraging Splunk. Description: The CCX Splunk Add-on for Keeper Security Products looks to provide a single field extraction bundle for Keeper Security logs ingested via HTTP Event Collector (HEC). To configure Keeper Security to logpush to Splunk follow the link: https://docs.keeper.io/enterprise-guide/event-reporting/splunk Currently this add-on provides extraction and CIM compliance for Keeper Security products: - Keeper Password Manager - "ccx:keeper:password_manager" Fully compatible with Splunk Enterprise and Splunk Cloud, built by an Ops team for Ops teams. Features: - This TA currently supports logtypes tagged under the following CIM datamodels: Alert, Authentication, Change.

Built by Matthew Orme
splunk product badge

Latest Version 1.0.2
February 22, 2024
Compatibility
Not Available
Platform Version: 9.4, 9.3, 9.2, 9.1, 9.0, 8.2, 8.1
CIM Version: 5.x, 4.x
Rating

5

(2)

Log in to rate this app
Support
CCX Add-on for Keeper Security Products support icon
Developer Supported addon
Learn more
About Us: CyberCX is Australia’s greatest force of cyber security experts. Our highly skilled professional services team operates a 24x7 on-shore security operations centre (SOC) servicing corporate and public sector organisations across Australia and New Zealand, specialising in Security Operations services leveraging Splunk. Description: The CCX Splunk Add-on for Keeper Security Products looks to provide a single field extraction bundle for Keeper Security logs ingested via HTTP Event Collector (HEC). To configure Keeper Security to logpush to Splunk follow the link: https://docs.keeper.io/enterprise-guide/event-reporting/splunk Currently this add-on provides extraction and CIM compliance for Keeper Security products: - Keeper Password Manager - "ccx:keeper:password_manager" Fully compatible with Splunk Enterprise and Splunk Cloud, built by an Ops team for Ops teams. Features: - This TA currently supports logtypes tagged under the following CIM datamodels: Alert, Authentication, Change.

Categories

Created By

Matthew Orme

Type

addon

Downloads

478

Resources

Login to report this app listing