↳ GitHub sourceConnector
BitSight Security Events (via Codeless Connector Framework)
Description
The [BitSight](https://www.bitsight.com/) data connector provides the capability to ingest security alerts, breaches, and findings from your BitSight portfolio into Microsoft Sentinel through the BitSight REST API. The connector monitors portfolio companies for rating changes, news alerts, data breaches, and detailed security findings across Diligence, Compromised Systems, and User Behavior risk categories. Refer to the [BitSight API documentation](https://help.bitsighttech.com/hc/en-us/articles/115014888388-API-Token-Management) for more information.
- Declared status
- 1
- Declared author / publisher
- Microsoft
Declared sources
Metadata from the source file. No dependencies inferred from KQL.
Data types
Declared permissions
Read and Write permissions are required.
Workspace
Workspace
BitSight API Token
A BitSight API Token is required to authenticate requests to the BitSight REST API. [See the documentation](https://help.bitsighttech.com/hc/en-us/articles/115014888388-API-Token-Management) to learn more about API Token management.
Connector instructions
Content published in the repository. Refer to the original file for all parameters.
1. Connection Management
Manage your BitSight data stream connections
Add Connection
Add BitSight Connection
Data Stream
Alerts - Rating changes and news events (BitSightAlerts)
Breaches - Data breach events for portfolio companies (BitSightBreaches)
Diligence Findings - Web, app, and network risk factors (BitSightFindings)
Compromised Systems Findings - Botnet and malware activity (BitSightFindings)
User Behavior Findings - Credential and employee risk activity (BitSightFindings)
BitSight API Base URL
BitSight API Token (Username)
BitSight API Token (Password)
Both fields must contain the **same API token value**. Entering different values will cause authentication to fail.
Obtain your API Token from **Settings > Account > User Preferences > API Token** in the BitSight portal.
Connection Name
The connection name is stored in the `ConnectorName` column of every ingested record, enabling you to trace data back to this specific connection.
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
9800e51↗- Source identifier
BitSightEventsConnector
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC