Panther is a security information and event management (SIEM) platform that can be used with Bitwarden organizations. Organization users can monitor event activity with the Bitwarden app on their Panther monitoring system.
To start you will need a Panther account and dashboard. Create a Panther account on their website.
Access the Panther dashboard.
On the menu, open the Configure dropdown and select Log Sources.
Select Onboard your logs.
Search Bitwarden in the catalogue.
Click on the Bitwarden integration and select Start Setup.
After you select Start Setup you will be brought to the configuration screen.
Panther SIEM services are only available for Bitwarden cloud hosted organizations.
Enter a name for the integration and then select Setup.
Next, you will have to access to your Bitwarden organization's Client ID and Client Secret. Keep this screen open, on another tab, access your Bitwarden web vault. Open your organization and navigate to Settings, Organization info, and View API key. You will be asked to re-enter your master password in order to access your API key information.
Copy and paste the
client_secretvalues into their respective locations on the Bitwarden App setup page. Once you have entered the information, continue by selecting Setup again.
Panther will run a test on the integration. Once a successful test has been completed, You will be given to option to adjust preferences. Complete the setup by pressing View Log Source.
Panther may take up to 10 minutes to ingest data following the Bitwarden App setup.
To begin monitoring data, head over to the primary dashboard and selectInvestigate and Data Explorer.
On the Data Explorer page, select the
panther_logs.publicdatabase from the drop down menu. Make sure that
bitwarden_eventsis being viewed as well.
Once you have made all of your required selections, select Run Query.
You may also Save as to use the query at another time.
A list of Bitwarden events will be produced at the bottom of the screen.
Events can be expanded and viewed in JSON by selecting View JSON..