Description
This connector provides insight into activity of your Bitwarden organization such as user's activity (logged in, changed password, 2fa, etc.), cipher activity (created, updated, deleted, shared, etc.), collection activity, organization activity, and more.
- Declared author / publisher
- Bitwarden Inc
Declared sources
Metadata from the source file. No dependencies inferred from KQL.
Data types
Declared permissions
Read and Write permissions are required.
Workspace
Workspace
Read permissions to shared keys for the workspace are required. [See the documentation to learn more about workspace keys](https://docs.microsoft.com/azure/azure-monitor/platform/agent-windows#obtain-workspace-id-and-key)
Keys
Workspace
Bitwarden Client Id and Client Secret
Your API key can be found in the Bitwarden organization admin console. Please see [Bitwarden documentation](https://bitwarden.com/help/public-api/#authentication) for more information.
Connector instructions
Content published in the repository. Refer to the original file for all parameters.
Your API key can be found in the Bitwarden organization admin console.
Please see [Bitwarden documentation](https://bitwarden.com/help/public-api/#authentication) for more information.
Self-hosted Bitwarden servers may need to reconfigure their installation's URL.
Bitwarden Identity Url
Bitwarden Api Url
Connect Bitwarden Event Logs to Microsoft Sentinel
Related content
Links established from declared identifiers and solution manifests.
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
9800e51↗- Source identifier
BitwardenEventLogs
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC