NordPass activity log integration setup with Splunk

Introduction

This article explains how to install the NordPass app in Splunk and set up activity log integration. Once configured, NordPass activity logs are automatically sent to Splunk, where they can be searched, visualized, and analyzed.

 

Here's what to do

  1. Generate a Splunk token in the NordPass Admin Panel by following the Token Management guide.
  2. Log in to your Splunk account.
  3. Go to “Apps” and click "Find More Apps".
  4. Search for NordPass.
  5. Click "Install" to install the NordPass Activity Logs app.
    For Splunk on‑premise deployments, download the app from Splunkbase and upload it via Manage Apps.
     
  6. Once installed, go to “Apps” and select "NordPass Activity Logs".
  7. Open the “Setup” tab and select the data center that your organization uses.
  8. Paste the token generated in the NordPass Admin Panel.
  9. Select the Index where NordPass activity logs will be stored.
  10. Click "Confirm" to complete the setup.

 

Additional tips

  • You can use a custom index to control access permissions and retention policies.
  • Only one active token is required per Splunk integration.
  • Make sure the selected index exists before completing setup.

Was this article helpful?