{
  "name": "bitwarden",
  "title": "Bitwarden",
  "version": "1.21.1",
  "release": "ga",
  "source": {
    "license": "Elastic-2.0"
  },
  "description": "Collect logs from Bitwarden with Elastic Agent.",
  "type": "integration",
  "download": "/epr/bitwarden/bitwarden-1.21.1.zip",
  "path": "/package/bitwarden/1.21.1",
  "icons": [
    {
      "src": "/img/bitwarden-logo.svg",
      "path": "/package/bitwarden/1.21.1/img/bitwarden-logo.svg",
      "title": "Bitwarden logo",
      "size": "32x32",
      "type": "image/svg+xml"
    }
  ],
  "conditions": {
    "kibana": {
      "version": "^8.19.4 || ~9.0.7 || ^9.1.4"
    },
    "elastic": {
      "subscription": "basic"
    }
  },
  "owner": {
    "type": "elastic",
    "github": "elastic/security-service-integrations"
  },
  "categories": [
    "security",
    "credential_management"
  ],
  "signature_path": "/epr/bitwarden/bitwarden-1.21.1.zip.sig",
  "format_version": "3.3.2",
  "readme": "/package/bitwarden/1.21.1/docs/README.md",
  "license": "basic",
  "screenshots": [
    {
      "src": "/img/bitwarden-event-dashboard.png",
      "path": "/package/bitwarden/1.21.1/img/bitwarden-event-dashboard.png",
      "title": "Event dashboard",
      "size": "600x600",
      "type": "image/png"
    },
    {
      "src": "/img/bitwarden-group-and-collection-dashboard.png",
      "path": "/package/bitwarden/1.21.1/img/bitwarden-group-and-collection-dashboard.png",
      "title": "Group and Collection dashboard",
      "size": "600x600",
      "type": "image/png"
    },
    {
      "src": "/img/bitwarden-member-dashboard.png",
      "path": "/package/bitwarden/1.21.1/img/bitwarden-member-dashboard.png",
      "title": "Member dashboard",
      "size": "600x600",
      "type": "image/png"
    },
    {
      "src": "/img/bitwarden-policy-dashboard.png",
      "path": "/package/bitwarden/1.21.1/img/bitwarden-policy-dashboard.png",
      "title": "Policy dashboard",
      "size": "600x600",
      "type": "image/png"
    }
  ],
  "assets": [
    "/package/bitwarden/1.21.1/LICENSE.txt",
    "/package/bitwarden/1.21.1/changelog.yml",
    "/package/bitwarden/1.21.1/manifest.yml",
    "/package/bitwarden/1.21.1/validation.yml",
    "/package/bitwarden/1.21.1/docs/README.md",
    "/package/bitwarden/1.21.1/img/bitwarden-event-dashboard.png",
    "/package/bitwarden/1.21.1/img/bitwarden-group-and-collection-dashboard.png",
    "/package/bitwarden/1.21.1/img/bitwarden-logo.svg",
    "/package/bitwarden/1.21.1/img/bitwarden-member-dashboard.png",
    "/package/bitwarden/1.21.1/img/bitwarden-policy-dashboard.png",
    "/package/bitwarden/1.21.1/kibana/tags.yml",
    "/package/bitwarden/1.21.1/data_stream/collection/manifest.yml",
    "/package/bitwarden/1.21.1/data_stream/collection/sample_event.json",
    "/package/bitwarden/1.21.1/data_stream/event/manifest.yml",
    "/package/bitwarden/1.21.1/data_stream/event/sample_event.json",
    "/package/bitwarden/1.21.1/data_stream/group/manifest.yml",
    "/package/bitwarden/1.21.1/data_stream/group/sample_event.json",
    "/package/bitwarden/1.21.1/data_stream/member/manifest.yml",
    "/package/bitwarden/1.21.1/data_stream/member/sample_event.json",
    "/package/bitwarden/1.21.1/data_stream/policy/manifest.yml",
    "/package/bitwarden/1.21.1/data_stream/policy/sample_event.json",
    "/package/bitwarden/1.21.1/kibana/dashboard/bitwarden-63396370-b37e-11ed-9607-677b4c473c8b.json",
    "/package/bitwarden/1.21.1/kibana/dashboard/bitwarden-89884710-b362-11ed-9607-677b4c473c8b.json",
    "/package/bitwarden/1.21.1/kibana/dashboard/bitwarden-9602fa40-b370-11ed-9607-677b4c473c8b.json",
    "/package/bitwarden/1.21.1/kibana/dashboard/bitwarden-a9819650-b36e-11ed-9607-677b4c473c8b.json",
    "/package/bitwarden/1.21.1/kibana/search/bitwarden-0879a470-b362-11ed-9607-677b4c473c8b.json",
    "/package/bitwarden/1.21.1/kibana/search/bitwarden-2eb31230-b370-11ed-9607-677b4c473c8b.json",
    "/package/bitwarden/1.21.1/kibana/search/bitwarden-41c871e0-b37e-11ed-9607-677b4c473c8b.json",
    "/package/bitwarden/1.21.1/data_stream/collection/fields/base-fields.yml",
    "/package/bitwarden/1.21.1/data_stream/collection/fields/beats.yml",
    "/package/bitwarden/1.21.1/data_stream/collection/fields/fields.yml",
    "/package/bitwarden/1.21.1/data_stream/event/fields/base-fields.yml",
    "/package/bitwarden/1.21.1/data_stream/event/fields/beats.yml",
    "/package/bitwarden/1.21.1/data_stream/event/fields/fields.yml",
    "/package/bitwarden/1.21.1/data_stream/group/fields/base-fields.yml",
    "/package/bitwarden/1.21.1/data_stream/group/fields/beats.yml",
    "/package/bitwarden/1.21.1/data_stream/group/fields/fields.yml",
    "/package/bitwarden/1.21.1/data_stream/member/fields/base-fields.yml",
    "/package/bitwarden/1.21.1/data_stream/member/fields/beats.yml",
    "/package/bitwarden/1.21.1/data_stream/member/fields/fields.yml",
    "/package/bitwarden/1.21.1/data_stream/policy/fields/base-fields.yml",
    "/package/bitwarden/1.21.1/data_stream/policy/fields/beats.yml",
    "/package/bitwarden/1.21.1/data_stream/policy/fields/fields.yml",
    "/package/bitwarden/1.21.1/data_stream/collection/agent/stream/httpjson.yml.hbs",
    "/package/bitwarden/1.21.1/data_stream/collection/elasticsearch/ingest_pipeline/default.yml",
    "/package/bitwarden/1.21.1/data_stream/event/agent/stream/httpjson.yml.hbs",
    "/package/bitwarden/1.21.1/data_stream/event/elasticsearch/ingest_pipeline/default.yml",
    "/package/bitwarden/1.21.1/data_stream/group/agent/stream/httpjson.yml.hbs",
    "/package/bitwarden/1.21.1/data_stream/group/elasticsearch/ingest_pipeline/default.yml",
    "/package/bitwarden/1.21.1/data_stream/member/agent/stream/httpjson.yml.hbs",
    "/package/bitwarden/1.21.1/data_stream/member/elasticsearch/ingest_pipeline/default.yml",
    "/package/bitwarden/1.21.1/data_stream/policy/agent/stream/httpjson.yml.hbs",
    "/package/bitwarden/1.21.1/data_stream/policy/elasticsearch/ingest_pipeline/default.yml"
  ],
  "policy_templates": [
    {
      "name": "bitwarden",
      "title": "Bitwarden logs",
      "description": "Collect Bitwarden logs.",
      "inputs": [
        {
          "type": "httpjson",
          "vars": [
            {
              "name": "url",
              "type": "text",
              "title": "URL",
              "description": "Base URL of the Bitwarden API.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "https://api.bitwarden.com"
            },
            {
              "name": "client_id",
              "type": "text",
              "title": "Client ID",
              "description": "Client ID of Bitwarden.",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "client_secret",
              "type": "password",
              "title": "Client Secret",
              "description": "Client secret of Bitwarden.",
              "multi": false,
              "required": true,
              "show_user": true
            },
            {
              "name": "token_url",
              "type": "text",
              "title": "Token URL",
              "description": "Token URL of Bitwarden.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "https://identity.bitwarden.com/connect/token"
            },
            {
              "name": "proxy_url",
              "type": "text",
              "title": "Proxy URL",
              "description": "URL to proxy connections in the form of http\\[s\\]://<user>:<password>@<server name/ip>:<port>. Please ensure your username and password are in URL encoded format.",
              "multi": false,
              "required": false,
              "show_user": false
            },
            {
              "name": "ssl",
              "type": "yaml",
              "title": "SSL Configuration",
              "description": "SSL configuration options. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-ssl.html#ssl-common-config) for details.",
              "multi": false,
              "required": false,
              "show_user": false,
              "default": "#certificate_authorities:\n#  - |\n#    -----BEGIN CERTIFICATE-----\n#    MIIDCjCCAfKgAwIBAgITJ706Mu2wJlKckpIvkWxEHvEyijANBgkqhkiG9w0BAQsF\n#    ADAUMRIwEAYDVQQDDAlsb2NhbGhvc3QwIBcNMTkwNzIyMTkyOTA0WhgPMjExOTA2\n#    MjgxOTI5MDRaMBQxEjAQBgNVBAMMCWxvY2FsaG9zdDCCASIwDQYJKoZIhvcNAQEB\n#    BQADggEPADCCAQoCggEBANce58Y/JykI58iyOXpxGfw0/gMvF0hUQAcUrSMxEO6n\n#    fZRA49b4OV4SwWmA3395uL2eB2NB8y8qdQ9muXUdPBWE4l9rMZ6gmfu90N5B5uEl\n#    94NcfBfYOKi1fJQ9i7WKhTjlRkMCgBkWPkUokvBZFRt8RtF7zI77BSEorHGQCk9t\n#    /D7BS0GJyfVEhftbWcFEAG3VRcoMhF7kUzYwp+qESoriFRYLeDWv68ZOvG7eoWnP\n#    PsvZStEVEimjvK5NSESEQa9xWyJOmlOKXhkdymtcUd/nXnx6UTCFgnkgzSdTWV41\n#    CI6B6aJ9svCTI2QuoIq2HxX/ix7OvW1huVmcyHVxyUECAwEAAaNTMFEwHQYDVR0O\n#    BBYEFPwN1OceFGm9v6ux8G+DZ3TUDYxqMB8GA1UdIwQYMBaAFPwN1OceFGm9v6ux\n#    8G+DZ3TUDYxqMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBAG5D\n#    874A4YI7YUwOVsVAdbWtgp1d0zKcPRR+r2OdSbTAV5/gcS3jgBJ3i1BN34JuDVFw\n#    3DeJSYT3nxy2Y56lLnxDeF8CUTUtVQx3CuGkRg1ouGAHpO/6OqOhwLLorEmxi7tA\n#    H2O8mtT0poX5AnOAhzVy7QW0D/k4WaoLyckM5hUa6RtvgvLxOwA0U+VGurCDoctu\n#    8F4QOgTAWyh8EZIwaKCliFRSynDpv3JTUwtfZkxo6K6nce1RhCWFAsMvDZL8Dgc0\n#    yvgJ38BRsFOtkRuAGSf6ZUwTO8JJRRIFnpUzXflAnGivK9M13D5GEQMmIl6U9Pvk\n#    sxSmbIUfc2SGJGCJD4I=\n#    -----END CERTIFICATE-----\n"
            },
            {
              "name": "enable_request_tracer",
              "type": "bool",
              "title": "Enable request tracing",
              "description": "The request tracer logs requests and responses to the agent's local file-system for debugging configurations. Enabling this request tracing compromises security and should only be used for debugging. See [documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-httpjson.html#_request_tracer_filename) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "title": "Collect Bitwarden logs via API",
          "description": "Collecting Bitwarden via API."
        }
      ],
      "multiple": true,
      "deployment_modes": {
        "default": {
          "enabled": true
        },
        "agentless": {
          "enabled": true,
          "release": "ga"
        }
      }
    }
  ],
  "data_streams": [
    {
      "type": "logs",
      "dataset": "bitwarden.collection",
      "title": "Collect Collection logs from Bitwarden",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "httpjson",
          "vars": [
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Duration between requests to the Bitwarden. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "1h"
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP client timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Valid time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "30s"
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "bitwarden-collection"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "preserve_duplicate_custom_fields",
              "type": "bool",
              "title": "Preserve duplicate custom fields",
              "description": "Preserve bitwarden.collection fields that were copied to Elastic Common Schema (ECS) fields.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "httpjson.yml.hbs",
          "title": "Collection logs",
          "description": "Collect Collection logs via API.",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "bitwarden",
      "path": "collection"
    },
    {
      "type": "logs",
      "dataset": "bitwarden.event",
      "title": "Collect Event logs from Bitwarden",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "httpjson",
          "vars": [
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Duration between requests to the Bitwarden. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "5m"
            },
            {
              "name": "initial_interval",
              "type": "text",
              "title": "Initial Interval",
              "description": "How far back to pull the events from Bitwarden. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "24h"
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP client timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Valid time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "30s"
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "bitwarden-event"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "preserve_duplicate_custom_fields",
              "type": "bool",
              "title": "Preserve duplicate custom fields",
              "description": "Preserve bitwarden.event fields that were copied to Elastic Common Schema (ECS) fields.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "httpjson.yml.hbs",
          "title": "Event logs",
          "description": "Collect Event logs via API.",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "bitwarden",
      "path": "event"
    },
    {
      "type": "logs",
      "dataset": "bitwarden.group",
      "title": "Collect Group logs from Bitwarden",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "httpjson",
          "vars": [
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Duration between requests to the Bitwarden. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "1h"
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP client timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Valid time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "30s"
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "bitwarden-group"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "preserve_duplicate_custom_fields",
              "type": "bool",
              "title": "Preserve duplicate custom fields",
              "description": "Preserve bitwarden.group fields that were copied to Elastic Common Schema (ECS) fields.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "httpjson.yml.hbs",
          "title": "Group logs",
          "description": "Collect Group logs via API.",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "bitwarden",
      "path": "group"
    },
    {
      "type": "logs",
      "dataset": "bitwarden.member",
      "title": "Collect Member logs from Bitwarden",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "httpjson",
          "vars": [
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Duration between requests to the Bitwarden. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "1h"
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP client timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Valid time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "30s"
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "bitwarden-member"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "preserve_duplicate_custom_fields",
              "type": "bool",
              "title": "Preserve duplicate custom fields",
              "description": "Preserve bitwarden.member fields that were copied to Elastic Common Schema (ECS) fields.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "httpjson.yml.hbs",
          "title": "Member logs",
          "description": "Collect Member logs via API.",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "bitwarden",
      "path": "member"
    },
    {
      "type": "logs",
      "dataset": "bitwarden.policy",
      "title": "Collect Policy logs from Bitwarden",
      "release": "ga",
      "ingest_pipeline": "default",
      "streams": [
        {
          "input": "httpjson",
          "vars": [
            {
              "name": "interval",
              "type": "text",
              "title": "Interval",
              "description": "Duration between requests to the Bitwarden. Supported units for this parameter are h/m/s.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": "1h"
            },
            {
              "name": "http_client_timeout",
              "type": "text",
              "title": "HTTP client timeout",
              "description": "Duration before declaring that the HTTP client connection has timed out. Valid time units are ns, us, ms, s, m, h.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": "30s"
            },
            {
              "name": "tags",
              "type": "text",
              "title": "Tags",
              "multi": true,
              "required": true,
              "show_user": false,
              "default": [
                "forwarded",
                "bitwarden-policy"
              ]
            },
            {
              "name": "preserve_original_event",
              "type": "bool",
              "title": "Preserve original event",
              "description": "Preserves a raw copy of the original event, added to the field `event.original`.",
              "multi": false,
              "required": true,
              "show_user": true,
              "default": false
            },
            {
              "name": "preserve_duplicate_custom_fields",
              "type": "bool",
              "title": "Preserve duplicate custom fields",
              "description": "Preserve bitwarden.policy fields that were copied to Elastic Common Schema (ECS) fields.",
              "multi": false,
              "required": true,
              "show_user": false,
              "default": false
            },
            {
              "name": "processors",
              "type": "yaml",
              "title": "Processors",
              "description": "Processors are used to reduce the number of fields in the exported event or to enhance the event with metadata. This executes in the agent before the logs are parsed. See [Processors](https://www.elastic.co/guide/en/beats/filebeat/current/filtering-and-enhancing-data.html) for details.",
              "multi": false,
              "required": false,
              "show_user": false
            }
          ],
          "template_path": "httpjson.yml.hbs",
          "title": "Policy logs",
          "description": "Collect Policy logs via API.",
          "enabled": true,
          "ingestion_method": "API"
        }
      ],
      "package": "bitwarden",
      "path": "policy"
    }
  ]
}
