1Password
Last updated
Was this helpful?
If you’ve previously created an 1Password connection, select it from the list.
Otherwise, select New 1Password Connection and fill in the required fields:
Connection Name: Give the connection a recognizable name.
Base URL: eg. https://events.1password.com/
Token: Generate this from your 1Password admin console.
For help finding these values:
With the Collect Rule created, Scanner will poll the 1Password Events API every 5 minutes. New events will be written to your S3 bucket, under the specified prefix.
Create an Index Rule to have Scanner index the logs for fast search and detections.
When you create the Index Rule from the Collect Rule, the following defaults are pre-populated:
Transformations: Add Metadata, Parse JSON Columns
Timestamp Field: .timestamp
Last updated
Was this helpful?
Was this helpful?