VaultOne: Integrate with a SIEM

Integrating your VaultOne platform with a SIEM (Security Information and Event Management) system allows you to centralize security information and streamline your alert monitoring. The process begins with generating an API token to securely connect VaultOne to your SIEM.

Generating an API Token

  1. Log in to your VaultOne platform.
  2. Go to Administration > API Tokens.
  3. Click on Create API Token.

Warning:

The Client ID and Secret (token) may only be shown once. Copy them to a secure location, like the JumpCloud Password Manager, for future reference.

Calling the GetAlertsLog API

To retrieve alerts from VaultOne, you will need to call the GetAlertsLog API.

  1. Authentication: Select 'API KEY' as the authentication type and enter the access key you generated in Step 1
  2. Required Fields: The API call requires two essential fields: StartDate and EndDate
  3. Sending Interval: The system is configured to send alerts at a one-day interval
  4. Format: All alerts are sent in the CEF (Common Event Format), which is a standardized log format recognized by most SIEMs

Default Alerts

VaultOne is pre-configured to send the following alerts by default to your SIEM:

  • More than 5 credentials seen in a short time frame (1, 2, or 3 minutes)
  • Login from outside the country
  • Excessive login attempts
  • User login outside of business hours
Back to Top

List IconIn this Article

Still Have Questions?

If you cannot find an answer to your question in our FAQ, you can always contact us.

Submit a Case