The Trigger an alert when no events are processed setting defaults to YES. We recommend leaving this enabled, as you will be alerted if data stops flowing from the log source after a certain period of time. The timeframe is configurable, with a default of 24 hours.\
schema: Bitwarden.Events
parser:
native:
name: Bitwarden.Events
description: Event logs from the Bitwarden Event Logs API
referenceURL: https://bitwarden.com/help/event-logs/#events
fields:
- name: object
required: true
description: String representing the object's type.
type: string
- name: type
required: true
description: Event type
type: bigint
- name: itemId
description: Unique identifier of the related item that the event describes.
type: string
- name: collectionId
description: Unique identifier of the related collection that the event describes.
type: string
- name: groupId
description: Unique identifier of the related group that the event describes.
type: string
- name: policyId
description: Unique identifier of the related policy that the event describes.
type: string
- name: memberId
description: Unique identifier of the related member that the event describes.
type: string
- name: actingUserId
description: Unique identifier of the user that performed the event.
type: string
- name: installationId
description: Unique identifier of the installation that the event describes.
type: string
- name: date
required: true
description: date/timestamp when the event occurred.
type: timestamp
timeFormats:
- rfc3339
isEventTime: true
- name: device
description: Device type
type: bigint
- name: ipAddress
description: IP address of the acting user
type: string
indicators:
- ip