Configure 1Password for Arctic Wolf monitoring

You can configure 1Password® to send the necessary logs to Arctic Wolf® for security monitoring.

These resources are required:

  • Administrator or Owner permissions for 1Password Business
  • A 1Password Business account

Set up an Events Reporting integration

  1. Sign in to 1Password.
  2. Click Integrations. If you have other integrations set up, click Directory.
  3. In the Events Reporting section, select your SIEM from the list. If your SIEM is not listed, select Other.
  4. Enter a name for the integration, and then click Add Integration.
  5. Click Add Token and configure the bearer token:
    • Token Name — Enter a name for the token.
    • Expires After — (Optional) Choose when the token will expire. The default setting is Never.
    • Events to Report — Select Sign-in attempts, Item usages, and Audit events.
  6. Click Issue Token, and then copy the token and save it in a safe, encrypted location.
    You will provide this value to Arctic Wolf later.
  7. Click View Integration Details, and then copy the account domain and save it in a safe, encrypted location.
    You will provide this value to Arctic Wolf later.

Provide 1Password credentials to Arctic Wolf

  1. Sign in to the Arctic Wolf Unified Portal.
  2. In the navigation menu, click Data Collection > Cloud Sensors.
  3. Click Add Account +.
  4. On the Add Account page, click 1Password.
  5. Configure these settings:
  6. Click Test and submit credentials.