Hello Devolutions Support Team,
We are currently configuring a webhook integration with Splunk to forward security-relevant events from Devolutions.
In the current webhook configuration screen, only a limited set of triggers appears to be available
[image]
For security monitoring and SIEM ( Splunk ) integration purposes, we would like to request that additional security audit events be made available as webhook triggers.
The goal is to send these events in near real time to Splunk for alerting, investigation, and compliance monitoring.
Could you please add support for the following security-related events as webhook triggers?
AttachmentPasswordRevealed
EntryPasswordRevealed
EntrySensitiveRevealed
EntryPasswordUsed
EntrySensitiveUsed
EntryCredentialsViewed
EntryPasswordCopied
EntrySensitiveCopied
EntryPasswordReset
EntrySendPasswordCopyInApp
EntryExported
EntriesExported
VaultPasswordsAnalyzed
VaultUsedOffline
VaultUsedAutofill
VaultEntriesWithStatesUsed
LoginSuccess
Logout
UserDeleted
UserEdited
UserCreated
GroupDeleted
GroupEdited
GroupCreated
SystemSettingsEdited
ChangeOwner
InvitationCreated
InvitationRevoked
EntryCheckout
EntryCheckin
EntryCheckoutApprovalRequestCreated
EntryCheckoutApprovalRequestApproved
EntryCheckoutApprovalRequestDenied
EntryCheckoutApprovalRequestGranted
EntryCheckoutApprovalRequestRejected
EntryCheckoutApprovalRequestCancelled
EntryCheckoutApprovalRequestCompleted
EntryCheckoutApprovalRequestUpdated
EntryCheckoutApprovalRequestRevoked
EntryTemporaryAccessRequestCreated
EntryTemporaryAccessRequestApproved
EntryTemporaryAccessRequestDenied
EntryTemporaryAccessRequestRevoked
EntryTemporaryAccessRequestGranted
EntryTemporaryAccessRequestRejected
EntryTemporaryAccessRequestCancelled
EntryTemporaryAccessRequestRevokedByApprover
EntryTemporaryAccessRequestRevokedForUser
EntryTemporaryAccessHasExpired
EntryTemporaryAccessRequestGrantedWithDependencies
EntryTemporaryAccessRequestApprovedWithDependencies
VaultAccessRequestCreated
VaultAccessRequestApproved
VaultAccessRequestCancelled
VaultAccessRequestDenied
LucidSyncUserAdded
LucidSyncUserEdited
LucidSyncUserDeleted
LucidSyncUserDisabled
LucidSyncGroupAdded
LucidSyncGroupEdited
LucidSyncGroupDeleted
GatewayDeleted
GatewayAdded
GatewayEdited
GatewaySessionTerminated
GatewaySessionOpen
GatewaySessionFailed
GatewaySessionClosed
PAMProviderDeleted
PAMProviderAdded
PAMProviderEdited
PAMAnyIdentityTemplateDeleted
PAMAnyIdentityTemplateCreated
PAMAnyIdentityTemplateUpdated
PAMScriptTemplateDeleted
PAMScriptTemplateCreated
PAMScriptTemplateUpdated
PAMCheckoutPolicyDeleted
PAMCheckoutPolicyCreated
PAMCheckoutPolicyUpdated
PAMAccountLifecyclePolicyDeleted
PAMAccountLifecyclePolicyCreated
PAMAccountLifecyclePolicyUpdated
PAMSshJitTemplateDeleted
PAMSshJitTemplateCreated
PAMSshJitTemplateUpdated
PAMSecurityGroupRiskDeleted
PAMSecurityGroupRiskCreated
PAMSecurityGroupRiskUpdated
RegenerateAppIdentitySecrets
GenerateEmergencyKey
GenerateRecoveryKey
SharedPasswordWithDevolutionsSendEmail
SharedPasswordWithDevolutionsSendLink
SendEmail
SendLink
These events are important for detecting and investigating actions such as:
Credential or sensitive data access
Password reveal, copy, reset, or sharing
Entry and vault exports
Temporary access requests and approvals
Checkout and check-in activity
PAM configuration changes
User, group, and permission changes
Emergency or recovery key generation
Application identity secret regeneration
This enhancement would significantly improve our ability to integrate Devolutions with Splunk and strengthen our security monitoring posture.
For context, before recommending the use of Azure Log Analytics or PowerShell commands to extract these logs, we would like to clarify that we have already evaluated both approaches.
Unfortunately, neither option provided satisfactory results for our security monitoring requirements. In the case of Azure Log Analytics, we also submitted a feature request, but it appears that implementing the requested functionality may not be straightforward. Azure Log Analytics Integration – Log Content Enrichment & Structured Fields for SIEM - Devolutions Forum
Because of these limitations, we explored the webhook option. This approach produced much better results and appears to be a more suitable solution for forwarding security events to Splunk in near real time.
However, the current webhook implementation is significantly limited by the small number of available triggers. To support effective SIEM integration and security monitoring, we would need additional security-related audit events to be exposed as webhook triggers.