Integration: Kaseya SIEM and VSA 9

The Kaseya SIEM and VSA 9 integration enables organizations to connect a VSA 9 instance to Kaseya SIEM using OAuth authentication. Once connected, VSA 9 becomes available as an application within the organization and can be used with supported Kaseya SIEM workflows. If Unify functionality is configured, VSA 9 asset data can also support Unify-related correlation workflows.

Prerequisites

Before configuring the integration, make sure the following requirements are met:

  • The VSA 9 domain or URL for the instance

  • Credentials for a VSA 9 user with permissions to create OAuth clients

  • An OAuth Client ID and Client Secret generated in VSA 9

  • Administrative access to Kaseya SIEM

If IP restrictions are configured in your firewall or in VSA 9, allow the following IP addresses:

  • 35.192.223.4

  • 35.224.156.102

Required API permissions

The OAuth client must have access to the following endpoints:

  • api/v1.0/system/orgs

  • api/v1.0/assetmgmt/agents

  • api/v1.0/assetmgmt/assets/{{agentId}}/customfields

  • api/v1.0/system/users

  • api/v1.0/environment

  • api/v1.0/system/logs

  • api/v1.0/assetmgmt/logs/{{agentId}}/*

How to...

Troubleshooting

The Allow Access window opens and immediately closes

This behavior may be caused by a password manager automatically populating credentials. Try connecting using an Incognito browser session with password manager autofill disabled.

Unable to connect VSA 9

Verify that:

  • The VSA 9 domain was entered correctly.

  • The OAuth Client ID is correct.

  • The OAuth Client Secret is correct.

  • The OAuth client was configured using the correct redirect URL.

  • Any firewall or product-level IP restrictions allow the required IP addresses.

Duplicate events or alerts appear

Verify that the same VSA 9 instance is not connected to multiple organizations. Connecting the same VSA 9 instance to multiple organizations can result in duplicate event and alert generation

Microsoft Entra ID is not required for the basic integration. However, it may be used to support enhanced Unify functionality if configured.