SIEM API keys
Your SIEM authenticates to Kolleno's event feed using an API key. You manage keys under Settings > Security > API keys. You can have up to two keys at a time, which is enough to rotate a key without any downtime.
Creating a key
Go to Settings > SIEM and select Create key.
Give the key a name so you can recognise it later, for example the name of your SIEM (such as
microsoft-defender).Select Create.
Copy the secret straight away
After the key is created, Kolleno shows you the secret once, in a dialog titled Your SIEM API key. Copy it immediately and store it securely in your SIEM's configuration.
For security reasons the secret is never shown again. If you lose it, delete the key and create a new one.
Managing existing keys
Each key is shown as a card with its name, the date it was created, when it was last used (or Never), and its current status:
Activate or deactivate: use the toggle on the key. A deactivated key immediately stops working but is kept so you can re-enable it.
Delete: select Delete and confirm. Any SIEM using that key will immediately lose access. Deleting a key also frees up a slot so you can create another.
Rotating a key
To rotate without downtime: create a second key, update your SIEM to use it, confirm events are still flowing, then delete the old key.




