FreshService ITSM
Secure ingestion of security and incidents alerts into FreshService

Overview
The Keeper Security ITSM application provides a secure and streamlined integration between Keeper Security Alerts and FreshService incident tickets. It enables enterprise customers to centrally manage and respond to Keeper-generated security alerts by automating their intake, transformation, and creation as FreshService Incident tickets.
This integration helps security teams maintain visibility, improve response times, and ensure that Keeper Security alerts are managed consistently within existing FreshService workflows.
Features
Receive Keeper Security alerts and incidents through a protected webhook endpoint, ensuring that only authorized sources can submit data to the platform.
Guided Setup to configure webhooks and alert severity mappings.
Transform incoming alerts into a FreshService Incident ticket
Provides custom priority mapping for Keeper Security alert types enabling FreshService administrators to work on incidents on priority basis.
Example Use Cases
Below are some example UseCases.
Password BreachWatch In Keeper Vault
Trigger: BreachWatch has detected a record in the Keeper vault with a vulnerable password.
Action: An alert will be sent to FreshService webhook that contains the BreachWatch incident.
FreshService Keeper Security ITSM app will receive the alerts, checks for priority mapping and creates a Incident Ticket.
Result: FreshService admins can audit, and work on the incident reported.
Privileged User Behavior Monitoring
Trigger: An admin user created a new Team or new policy in Keeper Administrative account.
Action: An alert will be sent to FreshService webhook that contains the incident information and an incident ticket will be created.
Result: SIR admins can audit, and work on the incident reported.
Prerequisites
Alerts configurations in Keeper Admin Console
FreshService subscription
Configuration Instructions
To configure the Keeper Security ITSM App in FreshService perform below steps:
Login as a admin in FreshService portal and click on the Market place icon, Search for Keeper Security ITSM and Download the app.

Once downloaded, head over to Manage Apps > Keeper Security ITSM > Click on Install. you will see below app configuration page

Getting Webhook Token
To get a webhook authentication token, Login to Keeper Security admin console click on Reporting & Alerts and create a new alert.

Click on Add Recipient then click on Add webhook.

Generate the token by click on generate button.

Once, the token is generated, copy the same token in app configuration page in FreshService ITSM application.
Once, the app is successfully install. Copy the webhook URL back to above alert configuration and save the alert configurations in Keeper admin console.
Receiving Alerts
Once, the application is configured, You will receive alerts in tickets section


Keeper Security Event Types Mapping
In the app configuration, users can set the priority, urgency, and impact for each event type. These values determine how alerts are classified when they create tickets. Configure them to match your team's incident-management process.

Troubleshooting
Use the application logs section to review relevant logs during troubleshooting.


Last updated

