Skip to main content
Question

Integrating Bindplane OP console Audit logs with Secops

  • January 21, 2026
  • 3 replies
  • 39 views

Forum|alt.badge.img+1

Hi All,

In our environment, we are using the Bindplane OP Console. As part of our logging and monitoring requirements, we need to forward the Bindplane OP Console Audit logs to the SecOps console for centralized visibility and analysis. Could someone please guide us on the recommended approach to send or integrate Bindplane OP Console logs into SecOps? 

Currently I am referring the link https://docs.bindplane.com/integrations/sources/bindplane-audit-logs  and performed the below changes. 

I created an API key at the Bindplane project level and configured a source using Bindplane Audit Logs, with the destination set to our SecOps console. However, I’m not seeing any logs in SecOps. In other configurations, we usually need to attach agents to a configuration for logs to flow. In this case, since it’s SaaS-based, how are these changes supposed to be applied or pushed from the Bindplane OP console? 

Any documentation, configuration steps, or best practices would be greatly appreciated

Thanks in advance for your support.

 

Regards,

Karthik

3 replies

Eoved
Forum|alt.badge.img+8
  • Bronze 2
  • January 21, 2026

Hello, you need to attach this configuration to one of your existing or new agents.
The OP itself is not sending the logs, they need to be sent from an agent.

  1. Go to  New Configuration and under Source, choose BindPlane Audit.
  2. Choose your SecOps as the destination.
  3. Add BINDPLANE as the Ingestion Label.
  4. Add Agent to the Configuration and apply 

Forum|alt.badge.img+1
  • Author
  • New Member
  • January 21, 2026

Hi ​@Eoved  : Thanks for the response.

Based on my understanding, the log flow will be as follows:

Bindplane OP SAAS Console → Bindplane Agent (within our corporate network) → SecOps

If this flow is correct, could you please advise which network ports need to be opened on the corporate firewall for communication between the OP Console and the Agent? Since the data is received by the agent from the internet and then forwarded to SecOps, we need to ensure the appropriate connectivity is in place.

 


Forum|alt.badge.img+1
  • Author
  • New Member
  • January 22, 2026

Hi ​@Eoved ,

I followed the suggested approach and I’m now able to see the Bindplane audit logs in the SecOps console. However, I’m noticing a new issue with the event content.

In SecOps, only the Description field is being populated, while the rest of the fields that are visible in the Bindplane console for the same audit event are not present.

Is this the expected behavior of this integration, or is there a way to forward the complete audit log payload (all fields) into a single event in SecOps for better visibility and correlation?