BridgeLink plugin

SIEM Event Logging

Forward BridgeLink security and event logs to your SIEM in real time.

v1.0.0 BridgeLink 26.6.0 or later

Why it matters

Real-time security monitoring and compliance reporting.

Healthcare environments have to monitor access and configuration changes and keep an audit trail for compliance. The SIEM plugin forwards BridgeLink's error and event logs to one or more external SIEM platforms in real time, so authentication, configuration, user management, data access, and system events land in the same place your security team already watches, without anyone leaving WebAdmin.

Capabilities

What it does:

Multiple destinations

Configure and manage several SIEM endpoints at once, each with its own protocol, address, and format, enabled or disabled independently.

Flexible protocols

Send events over an HTTP/HTTPS REST API, Syslog (UDP or TCP, with optional TLS), or write them to a local log file.

Flexible formats

Emit CEF, JSON, or LEEF so events arrive in the shape your SIEM platform expects.

Delivery monitoring and alerts

Track uptime, queue depth, latency, and per-destination status, with email alerts when the success rate drops or the queue backs up.

Release highlights

What's new.

Event forwarding

  • Multiple destinations: configure and manage several SIEM endpoints at once, each with its own protocol, address, and format.
  • Flexible protocols: HTTP/HTTPS REST API, Syslog (UDP or TCP with optional TLS), or a local log file.
  • Flexible formats: CEF, JSON, or LEEF, so events arrive in the shape your SIEM expects.

Platform presets

  • Ready-made presets for Elastic Stack, Splunk (HEC), IBM QRadar, and Wazuh fill in the recommended protocol and format automatically.
  • Other / Custom connects any platform that accepts HTTP/HTTPS, Syslog, or a log file, such as ArcSight.
  • A five-step Add Destination wizard, no SIEM expertise required.

Control and monitoring

  • Master switch to enable or disable all SIEM forwarding at once.
  • Per-destination toggle to disable individual destinations without deleting their configuration.
  • Delivery health monitoring from the Statistics tab.
  • Backup and restore the SIEM configuration as a file.

How it works

Get started in minutes.

  1. 1

    License and enable the plugin

    Innovar Healthcare installs the SIEM Plugin extension and a license. Once licensed, a SIEM tab appears under Settings in WebAdmin.

  2. 2

    Add your SIEM destinations

    A five-step wizard walks you through each destination, with ready-made presets for Elastic Stack, Splunk, IBM QRadar, and Wazuh, or an Other / Custom option for anything else.

  3. 3

    Choose protocol, format, and filters

    Pick HTTP/HTTPS, Syslog, or a log file, an event format of CEF, JSON, or LEEF, and optionally filter by event type, severity, or user to control volume and cost.

  4. 4

    Monitor delivery health

    The Statistics tab shows uptime, queue depth, latency, and per-destination status, with email alerts when delivery falls behind.

Requirements

What you'll need:

  • BridgeLink 26.6.0 or later
  • A SIEM Plugin license and the License Manager plugin
  • At least one reachable SIEM destination (Elastic Stack, Splunk, IBM QRadar, Wazuh, or a custom HTTP, Syslog, or log-file endpoint)
  • Outbound network access from BridgeLink to each destination (for example, port 514 for Syslog)

FAQ

Frequently asked questions.

Which SIEM platforms are supported?

The plugin ships presets for Elastic Stack, Splunk, IBM QRadar, and Wazuh. Any platform that accepts an HTTP/HTTPS REST API, Syslog, or a local log file, such as ArcSight, connects through the Other / Custom option.

What event formats can it send?

CEF, JSON, or LEEF, chosen per destination so events arrive in the shape your SIEM expects.

Can I control which events are forwarded?

Yes. Each destination can filter by event type (authentication, configuration, user management, system, data access, and errors), severity, and user, which also helps lower ingestion costs.

Can I send to more than one SIEM at once?

Yes. You can configure multiple destinations and enable or disable each one independently, with a master switch to stop all forwarding at once.

How do I know events are being delivered?

The Statistics tab reports uptime, queue depth, latency, dropped events, and a connected or disconnected status per destination, refreshed automatically, plus optional email alerts.

Availability

Requires BridgeLink 26.6.0 or later and a SIEM Plugin license. Installed by Innovar Healthcare or your professional services contact.

Add SIEM Event Logging to BridgeLink.

Talk to us about your deployment, or read the full user guide to get started.