Microsoft Sentinel SIEM

Microsoft Sentinel is a security information and event management (SIEM) platform that can be used to monitor Bitwarden organizations. Organizations can monitor event activity with the Bitwarden Event Logs app on the Microsoft Dashboard.

Setup

To setup the Bitwarden integration, an active Azure account with access to Microsoft Sentinel is required, as well as a Bitwarden organization in which you have the required access permissions.

Install the Bitwarden app to your Microsoft Sentinel dashboard

  1. Navigate to your Microsoft Sentinel dashboard. Select your workspace or select New to add Microsoft Sentinel to a new workspace.

    Sentinel New Workspace
    Sentinel New Workspace
  2. Navigate to apps catalogue

  3. third step if required

Connect your Bitwarden organization

Once the Bitwarden Event Logs app has been installed to your Microsoft Sentinel dashboard, you can connect your Bitwarden organization using your Bitwarden API key.

  1. Go to the dashboard home and select the Bitwarden Event Logs app.

  2. Select Data connectors from the navigation menu. Then, select the menu for your workspace and Open connector page.

    Open connector page
    Open connector page
  3. Keep this screen open, on another tab, log in to the Bitwarden web app and open the Admin Console using the product switcher ():

    製品-スイッチャー
    製品-スイッチャー
  4. Navigate to your organization's SettingsOrganization info screen and select the View API key button. You will be asked to re-enter your master password in order to access your API key information.

    組織API情報
    組織API情報
  5. Return to the Microsoft Sentinel tab. On the Configuration page, complete the following fields:

Field

Value

Bitwarden Identity Url

For Bitwarden cloud users, the default URL will be https://identity.bitwarden.com.

For self-hosted Bitwarden users, input your self-hosted URL. Be sure that the URL does not include and trailing forward slashes at the end of the URL "/".

Bitwarden Api Url

For Bitwarden cloud users, the default URL will be https://api.bitwarden.com.

For self-hosted Bitwarden users, input your self-hosted URL. Be sure that the URL does not include and trailing forward slashes at the end of the URL "/".

Client ID

Input the value for client_id from the Bitwarden organization API key window.

Client Secret

Input the value for client_secret from the Bitwarden organization API key window.

Select Connect once the required fields have been completed.

注意

あなたの組甔のAPIキーは、あなたの組織への完全なアクセスを可能にします。あなたのAPIキーを秘密に保ってください。あなたのAPIキーが侵害されたと思われる場合、この画面で設定>組織情報> APIキーをロテートボタンを選択してください。あなたの現在のAPIキーのアクティブな実装は、使用する前に新しいキーで再設定する必要があります。

Start monitoring event logs

備考

Historic event data is not available for the Bitwarden Event Logs app on Microsoft Sentinel at this time.

To start monitoring data in the Microsoft Sentinel directory, and select Workbooks and them Templates from the navigation menu.

Workbook Templates
Workbook Templates

The Bitwarden Event Logs app will have three templates included by default. Select one of the templates and choose View Template.

Included Templates
Included Templates

Select one of the templates to begin monitoring data. The dashboard include graphs and reported data:

Microsoft Sentinel Overview
Microsoft Sentinel Overview

Continue scrolling the overview page for additional event log data:

BitwardenEventLogsAuthenticationWhite2
BitwardenEventLogsAuthenticationWhite2

Customize reports

Customize the data displayed by reports

このページに提案する

サポートチームへのお問い合わせ

For technical, billing, product, and Family/Premium questions.

お名前*
ビットワルデン*
アカウントのメールアドレスを確認してください*
製品*
あなたは自己ホスト型ですか?*
件名*
お問い合わせ内容を入力してください...*

クラウドのステータス

ステータスを確認する

© 2024 Bitwarden, Inc. 利用規約 プライバシー クッキーの設定 サイトマップ

このサイトは日本語でご利用いただけます。
Go to EnglishStay Here