BeheerconsoleRapportageSIEM Integrations

Generic HEC Integration

Bitwarden provides comprehensive event logging capabilities for security information and event management (SIEM) solutions, enabling organizations to monitor credential management events alongside other activities. In addition to official integrations for popular SIEM solutions, the generic HEC integration works with any HTTP ingestion compatible SIEM platform. This article provides guidance for integrating Bitwarden with HEC solutions, similar to platforms such as Huntress, and Splunk.

Requirements

To setup HTTP ingestion, you must:

  • Have a Bitwarden Teams or Enterprise organization.

  • Have an account with an HTTP ingestion-compliant platform set up.

  • Have administrative access to Bitwarden and your chosen event log monitoring platform.

Setup

Integrating Bitwarden with HTTP ingestion will require setup procedures in both platforms.

Set up HEC in your SIEM platform

Before connecting from the Bitwarden app, generate the credentials that Bitwarden will use to send events to your SIEM monitoring platform. Review your chosen platform's documentation to locate the HTTP Event Collector URL and HTTP Event Collector Token.

Connect from Bitwarden

Once you have your HTTP Event Collector URL and HTTP Event Collector Token, provide that information in your Bitwarden organization to complete setup:

  1. Log in to the Bitwarden web app and open the Admin Console.

  2. In the Admin Console, go to Integrations → Event management.

  3. Find the Generic HEC card and select Connect. The following table describes these credential values:

    Generic HEC connection
    Generic HEC connection
  4. Enter your HTTP Event Collector URL and HTTP Event Collector Token.

    Set up HEC
    Set up HEC

Additional resources