↳ GitHub sourceConnector

Bitwarden Event Logs

Description

This connector provides insight into activity of your Bitwarden organization such as user's activity (logged in, changed password, 2fa, etc.), cipher activity (created, updated, deleted, shared, etc.), collection activity, organization activity, and more.
Declared author / publisher
Bitwarden Inc

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Declared permissions

Read and Write permissions are required.
Workspace
Workspace
Read permissions to shared keys for the workspace are required. [See the documentation to learn more about workspace keys](https://docs.microsoft.com/azure/azure-monitor/platform/agent-windows#obtain-workspace-id-and-key)
Keys
Workspace
Bitwarden Client Id and Client Secret
Your API key can be found in the Bitwarden organization admin console. Please see [Bitwarden documentation](https://bitwarden.com/help/public-api/#authentication) for more information.

Connector instructions

Content published in the repository. Refer to the original file for all parameters.

Your API key can be found in the Bitwarden organization admin console. Please see [Bitwarden documentation](https://bitwarden.com/help/public-api/#authentication) for more information. Self-hosted Bitwarden servers may need to reconfigure their installation's URL.
Bitwarden Identity Url
Bitwarden Api Url
Connect Bitwarden Event Logs to Microsoft Sentinel

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
BitwardenEventLogs
Additional source files 2Solutions/Bitwarden/Data Connectors/BitwardenEventLogs/definitions.jsonsource ↗Solutions/Bitwarden/Data/Solution_Bitwarden.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.