Bitwarden Logs
Panther supports pulling logs directly from Bitwarden
Overview
This feature is currently in open beta, and is available to all customers. Please share any bug reports and feature requests with your Panther support team.
Panther can query the Bitwarden Events API for new audit events every 60 seconds.
How to onboard Bitwarden logs to Panther
Prerequisite
To read events from your Bitwarden account, you must have a Bitwarden organization account with API access.
Step 1: Create a new Bitwarden source in Panther
In the left-hand navigation bar of your Panther Console, click Configure > Log Sources.
Click Create New.
Search for “Bitwarden,” then click its tile.
In the slide-out panel, click Start Setup.
Enter a descriptive name for the source, e.g., "My Bitwarden logs".
Click Setup.
Step 2: Fetch API credentials in Bitwarden
In a separate browser tab, open the Bitwarden web console.
Navigate to the Settings tab.
In the lefthand navigation bar, select Organization info.
Copy the Client ID and Client Secret and store them in a secure location, as you will need them in the next step.
Step 3: Finalize Bitwarden onboarding in Panther
Navigate to the Panther Console, on the Credentials page where you left off in the earlier steps.
Click Setup. You will be directed to a success screen:
You can optionally enable one or more Detection Packs.
The Trigger an alert when no events are processed setting defaults to YES. We recommend leaving this enabled, as you will be alerted if data stops flowing from the log source after a certain period of time. The timeframe is configurable, with a default of 24 hours.
Supported log types
Bitwarden.Events
These logs represent events for the entire organization. For more information, see Bitwarden's API documentation.
Last updated