cscli parsers install MariuszKociubinski/bitwarden-logsParser for Bitwarden Logs.
1---2filenames:3 - /etc/bitwarden/logs/identity.log4labels:5 type: bitwarden
1onsuccess: next_stage2#debug: false3name: MariuszKociubinski/bitwarden-logs4description: "Parse bitwarden logs"5filter: "evt.Parsed.program == 'bitwarden'"6nodes:7 - grok:8 pattern: '^%{EXIM_DATE:timestamp}.*Failed login attempt\. %{IP:source_ip}.*$'9 apply_on: message10 statics:11 - meta: log_type12 value: bitwarden_failed_auth13 - grok:14 pattern: '^%{EXIM_DATE:timestamp}.*Failed login attempt\, 2FA invalid\. %{IP:source_ip}.*$'15 apply_on: message16 statics:17 - meta: log_type18 value: bitwarden_failed_auth1920statics:21 - meta: service22 value: bitwarden23 - meta: source_ip24 expression: "evt.Parsed.source_ip"25 - target: evt.StrTime26 expression: evt.Parsed.timestamp27