Skip to content

Commit 037dcb0

Browse files
amee-sumoJV0812ankitgoelcmu
authored
Bitwarden (#5368)
* Bitwarden (Apps) * Delete 2025-05-12-apps.md * Update bitwarden.md * minor fix * minor fix * Update bitwarden.md --------- Co-authored-by: Jagadisha V <[email protected]> Co-authored-by: Ankit Goel <[email protected]>
1 parent fd82162 commit 037dcb0

File tree

6 files changed

+147
-1
lines changed

6 files changed

+147
-1
lines changed

blog-service/2025-05-13-apps.md

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
---
2+
title: Bitwarden (Apps)
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
keywords:
5+
- apps
6+
- bitwarden
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
We're excited to introduce the new Bitwarden app for Sumo Logic. This app enables threat detection and identification of high-risk events such as vault exports or SSO deactivation, supporting continuous monitoring and accelerating incident response for credential and secret management workflows. [Learn more](/docs/integrations/saas-cloud/bitwarden).

cid-redirects.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1637,6 +1637,7 @@
16371637
"/cid/6025": "/docs/integrations/saas-cloud/cisco-vulnerability-management",
16381638
"/cid/6026": "/docs/integrations/saas-cloud/sumo-collection",
16391639
"/cid/6027": "/docs/integrations/saas-cloud/sysdig-secure",
1640+
"/cid/6028": "/docs/integrations/saas-cloud/bitwarden",
16401641
"/cid/10112": "/docs/integrations/app-development/jfrog-xray",
16411642
"/cid/10113": "/docs/observability/root-cause-explorer",
16421643
"/cid/10116": "/docs/manage/fields",

docs/integrations/product-list/product-list-a-l.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -129,7 +129,7 @@ For descriptions of the different types of integrations Sumo Logic offers, see [
129129
| <img src={useBaseUrl('img/integrations/security-threat-detection/barracuda.png')} alt="Thumbnail icon" width="100"/> | [Barracuda WAF](https://www.barracuda.com/products/application-protection/web-application-firewall) | App: [Barracuda WAF](/docs/integrations/security-threat-detection/barracuda-waf/) <br/>Partner integration: [Barracuda CloudGen Firewall](https://campus.barracuda.com/product/cloudgenfirewall/doc/91132156/sumo-logic-integration/) |
130130
| <img src={useBaseUrl('img/integrations/misc/bettercloud-logo.png')} alt="Thumbnail icon" width="75"/> | [BetterCloud](https://www.bettercloud.com/) | Partner integration: [BetterCloud](https://support.bettercloud.com/s/article/Integrating-Sumo-Logic-with-BetterCloud-bc45575) |
131131
| <img src={useBaseUrl('img/integrations/app-development/bitbucket.png')} alt="Thumbnail icon" width="50"/> | [Bitbucket](https://bitbucket.org/product) | App: [Bitbucket](/docs/integrations/app-development/bitbucket/) |
132-
| <img src={useBaseUrl('img/integrations/security-threat-detection/bitwarden.png')} alt="Thumbnail icon" width="100"/> | [Bitwarden](https://bitwarden.com/) | Collector: [Bitwarden Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/bitwarden-source) |
132+
| <img src={useBaseUrl('img/integrations/security-threat-detection/bitwarden.png')} alt="Thumbnail icon" width="100"/> | [Bitwarden](https://bitwarden.com/) | App: [Bitwarden](/docs/integrations/saas-cloud/bitwarden/) <br/>Collector: [Bitwarden Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/bitwarden-source) |
133133
| <img src={useBaseUrl('img/integrations/misc/bitdefender-logo.png')} alt="Thumbnail icon" width="75"/> | [Bitdefender](https://www.bitdefender.com/) | Automation integration: [Bitdefender GravityZone](/docs/platform-services/automation-service/app-central/integrations/bitdefender-gravityzone/) <br/>Cloud SIEM integration: [Bitdefender](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/04de471f-70b0-4ffb-89a9-f094ef242248.md) <br/>Partner integration: [Bitdefender](https://www.bitdefender.com/business/support/en/77209-158570-sumo-logic.html) |
134134
| <img src={useBaseUrl('img/platform-services/automation-service/app-central/logos/bitsight-security-performance-management.png')} alt="Thumbnail icon" width="75"/> | [BitSight](https://www.bitsight.com/) | Automation integration: [BitSight Security Performance Management](/docs/platform-services/automation-service/app-central/integrations/bitsight-security-performance-management/) |
135135
| <img src={useBaseUrl('img/integrations/misc/blackberry-logo.png')} alt="Thumbnail icon" width="100"/> | [Blackberry](https://www.blackberry.com/us/en) | App: [Cylance](/docs/integrations/security-threat-detection/cylance/) <br/>Automation integration: [Cylance Protect](/docs/platform-services/automation-service/app-central/integrations/cylanceprotect/) <br/>Cloud SIEM integrations: <br/>- [Blackberry](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/ac6a961b-590c-4dd4-8402-56f4a4cddd98.md) <br/>- [Cylance](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/c57feda1-8da4-464d-b6cf-2c9982b71e57.md) |
Lines changed: 126 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,126 @@
1+
---
2+
id: bitwarden
3+
title: Bitwarden
4+
sidebar_label: Bitwarden
5+
description: The Bitwarden app for Sumo Logic helps monitor and accelerate incident response in credential and secret management workflows.
6+
---
7+
8+
import useBaseUrl from '@docusaurus/useBaseUrl';
9+
10+
<img src={useBaseUrl('img/integrations/security-threat-detection/bitwarden.png')} alt="thumbnail icon" width="125"/>
11+
12+
The Sumo Logic app for Bitwarden provides comprehensive visibility into user activity, security events, and administrative changes within your Bitwarden environment. It enables security analysts to track key actions such as user logins, failed two-step verifications, master password resets, and decryption key migrations. The app includes contextual data—like IP addresses, device types, and geolocation—to help detect suspicious behavior and potential threats. Visualizations such as event trends and geo heatmaps reveal usage patterns and regional access anomalies.
13+
14+
A major strength of the app is its ability to highlight high-risk activities through event summaries and filtered views of critical actions, such as vault exports or SSO deactivation. It also includes preconfigured alerts to proactively detect security threats like data exfiltration, account compromise, or policy violations.
15+
16+
:::info
17+
This app includes [built-in monitors](#bitwarden-monitors). For details on creating custom monitors, refer to the [Create monitors for Bitwarden app](#create-monitors-for-bitwarden-app).
18+
:::
19+
20+
## Log types
21+
22+
This app uses Sumo Logic’s [Bitwarden Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/bitwarden-source/) to collect the [event logs](https://bitwarden.com/help/event-logs/) from the Bitwarden platform.
23+
24+
### Sample log messages
25+
26+
```json title="Event Log"
27+
{
28+
"actingUserEmail": "[email protected]",
29+
"actingUserId": "9aaa2aeb-6cf1-48a0-8e2e-b28e015b71d6",
30+
"actingUserName": "frank",
31+
"date": "2025-04-23T22:42:44-0700226Z",
32+
"device": 9,
33+
"deviceName": "ChromeBrowser",
34+
"groupId": null,
35+
"groupName": "",
36+
"installationId": null,
37+
"ipAddress": "103.149.48.189",
38+
"itemId": null,
39+
"memberId": null,
40+
"object": "event",
41+
"policyId": null,
42+
"secretId": null,
43+
"serviceAccountId": null,
44+
"type": 1009,
45+
"typeName": "Created_item_item-identifier"
46+
}
47+
```
48+
49+
### Sample queries
50+
51+
```sql title="Event Breakdown"
52+
_sourceCategory=Labs/bitwarden
53+
| json "actingUserName", "date", "object", "type", "typeName", "ipAddress","deviceName","actingUserEmail" as user_name, date, object, event_code, event_name, ip, device_name, user_email
54+
| lookup event_name from https://sumologic-app-data.s3.us-east-1.amazonaws.com/bitwarden_events.csv on event_code=event_code
55+
| lookup latitude, longitude,country_name, country_code from geo://location on ip = ip
56+
57+
58+
| count by event_name
59+
| sort by _count
60+
```
61+
62+
## Collection configuration and app installation
63+
64+
import CollectionConfiguration from '../../reuse/apps/collection-configuration.md';
65+
66+
<CollectionConfiguration/>
67+
68+
:::important
69+
Use the [Cloud-to-Cloud Integration for Bitwarden](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/bitwarden-source/) to create the source and use the same source category while installing the app. By following these steps, you can ensure that your Bitwarden app is properly integrated and configured to collect and analyze your Bitwarden data.
70+
:::
71+
72+
### Create a new collector and install the app
73+
74+
import AppCollectionOPtion1 from '../../reuse/apps/app-collection-option-1.md';
75+
76+
<AppCollectionOPtion1/>
77+
78+
### Use an existing collector and install the app
79+
80+
import AppCollectionOPtion2 from '../../reuse/apps/app-collection-option-2.md';
81+
82+
<AppCollectionOPtion2/>
83+
84+
### Use an existing source and install the app
85+
86+
import AppCollectionOPtion3 from '../../reuse/apps/app-collection-option-3.md';
87+
88+
<AppCollectionOPtion3/>
89+
90+
## Viewing the Bitwarden dashboards​​
91+
92+
import ViewDashboards from '../../reuse/apps/view-dashboards.md';
93+
94+
<ViewDashboards/>
95+
96+
### Security
97+
98+
The **Bitwarden - Security** dashboard offers security analysts a centralized view of critical user and system activity. It highlights high-risk events such as SSO disablement, master password resets, failed two-step verifications, and decryption key migrations. Visual tools like event timelines and geographic heatmaps help quickly identify anomalies. The dashboard also enforces security policies by flagging access from embargoed regions and tracking users who disable two-step login.
99+
100+
Detailed login and invitation data supports monitoring of access patterns and potential insider threats. Each panel is optimized for real-time investigation and auditing, enhancing the ability to detect and respond to suspicious behavior. The dashboard improves visibility, accountability, and response time for security incidents in the Bitwarden.<br/><img src='https://sumologic-app-data-v2.s3.us-east-1.amazonaws.com/dashboards/Bitwarden/Bitwarden+-+Security.png' alt="Bitwarden-Security" />
101+
102+
## Create monitors for Bitwarden app
103+
104+
import CreateMonitors from '../../reuse/apps/create-monitors.md';
105+
106+
<CreateMonitors/>
107+
108+
### Bitwarden monitors
109+
110+
| Name | Description | Trigger Type (Critical / Warning / MissingData) | Alert Condition |
111+
|:--|:--|:--|:--|
112+
| `Events from Embargoed Geo Location` | This alert is triggered when a Bitwarden event is detected originating from a geo-location that is on an embargo list. This alert helps security teams detect potential violations of compliance policies or identify suspicious access attempts from high-risk regions. | Critical | Count > 0 |
113+
| `Exported Organization Vault` | This alert is triggered when a user exports the entire organization's vault data. This is a high-risk activity that could indicate potential data exfiltration or insider threat behavior and should be reviewed immediately by security personnel. | Critical | Count > 0 |
114+
| `Organization Disabled SSO` | This alert is triggered when the Single Sign-On (SSO) is disabled for the organization, which could reduce the security posture and increase the risk of unauthorized access. This alert ensures that administrators are immediately aware of any change that affects the organization’s authentication method. | Critical | Count > 0 |
115+
116+
## Upgrading the Bitwarden app (Optional)
117+
118+
import AppUpdate from '../../reuse/apps/app-update.md';
119+
120+
<AppUpdate/>
121+
122+
## Uninstalling the Bitwarden app (Optional)
123+
124+
import AppUninstall from '../../reuse/apps/app-uninstall.md';
125+
126+
<AppUninstall/>

docs/integrations/saas-cloud/index.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -69,6 +69,12 @@ Learn about the Sumo Logic apps for SaaS and Cloud applications.
6969
<p>Gain insights into Automox events and audit data to enhance security monitoring, streamline endpoint management, and boost operational resilience.</p>
7070
</div>
7171
</div>
72+
<div className="box smallbox card">
73+
<div className="container">
74+
<a href="/docs/integrations/saas-cloud/bitwarden"><img src={useBaseUrl('img/integrations/security-threat-detection/bitwarden.png')} alt="bitwarden-icon.png" width="100" /><h4>Bitwarden</h4></a>
75+
<p>Gain insights into user activity, security events, and administrative changes within your Bitwarden environment.</p>
76+
</div>
77+
</div>
7278
<div className="box smallbox card">
7379
<div className="container">
7480
<a href="/docs/integrations/saas-cloud/box"><img src={useBaseUrl('img/integrations/saas-cloud/box.png')} alt="icon" width="80"/><h4>Box</h4></a>

sidebars.ts

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2526,6 +2526,7 @@ integrations: [
25262526
'integrations/saas-cloud/asana',
25272527
'integrations/saas-cloud/atlassian',
25282528
'integrations/saas-cloud/automox',
2529+
'integrations/saas-cloud/bitwarden',
25292530
'integrations/saas-cloud/box',
25302531
'integrations/saas-cloud/cato-networks',
25312532
'integrations/saas-cloud/cisco-amp',

0 commit comments

Comments
 (0)