GitHub Team and Free organizations should use the
GitHub integration, which collects the security
events available through GitHub App webhooks.
Before you connect
- Confirm the organization uses GitHub Enterprise Cloud, which is required for organization audit-log access.
- Have a GitHub organization owner available to complete or approve the Wirespeed GitHub App installation.
- Review and accept the App’s read-only Organization administration permission. The App cannot modify repositories, organization settings, members, or code.
- For IP-based investigations and detections, enable source IP disclosure under Organization Settings → Logs → Audit log → Settings.
Connect GitHub Enterprise Cloud
- In Wirespeed, open Settings → Integrations and select GitHub Enterprise Cloud.
- Review these instructions, then select Integrate.
- In GitHub, choose the Enterprise Cloud organization you want to monitor.
- Review the requested read-only organization permission and install the Wirespeed GitHub App.
- Authorize the App when GitHub prompts you. GitHub returns you to Wirespeed when the connection is ready.
Deleting the Wirespeed connection does not uninstall the GitHub App. To
connect the same organization again, uninstall the App in GitHub
(Organization Settings → GitHub Apps), then reconnect from Wirespeed so
GitHub can run the OAuth install flow again.
Wirespeed uses the authorizing user’s short-lived GitHub token only to verify
access to the selected installation. Polling uses a one-hour installation
token that is regenerated automatically; the user’s token is not retained.
Data collection
The first sync imports up to seven days of available organization audit events. Later syncs resume from the latest successfully ingested event and include both web and Git events.Source IP disclosure is disabled by default. Audit events are still ingested
when it is disabled, but they do not include the actor IP address used by
IP-based investigations and detections.

