SIEM
Overview
Britive generates a rich audit trail for every access request, checkout, checkin, approval, and policy change. Forwarding these events to your SIEM gives your security team a single pane of glass for monitoring privileged access activity, building detection rules, and satisfying compliance requirements.
The guides in this section cover integrating Britive with common SIEM platforms.
Britive supports log forwarding via webhooks, syslog, and direct API polling. The approach varies by SIEM — each guide covers the recommended method for that platform.
How the Britive data connector for Microsoft Sentinel works — Sentinel polls the Britive Audit Log API every five minutes and stores each event in a queryable table, with parsers, analytic rules, hunting queries and a workbook included.
A catalog of detections to build in your SIEM from Britive audit events — authentication, privileged access, secrets, policy changes, and identity lifecycle — with the event types that drive each rule.
Last updated on