> ## Documentation Index
> Fetch the complete documentation index at: https://docs.wirespeed.co/llms.txt
> Use this file to discover all available pages before exploring further.

# GitHub Enterprise Cloud

> Ingest organization audit events from GitHub Enterprise Cloud

<Info>
  GitHub Team and Free organizations should use the
  [GitHub integration](/integrations/github), which collects the security
  events available through GitHub App webhooks.
</Info>

The GitHub Enterprise Cloud integration imports organization audit events into
Wirespeed. Events include web and Git activity, such as changes to organization
membership, repositories, permissions, settings, and authentication. Wirespeed
indexes actor IP addresses and usernames for investigation and threat detection.

## Before you connect

* Confirm the organization uses **GitHub Enterprise Cloud**, which is required
  for organization audit-log access.
* Have a GitHub organization owner available to complete or approve the
  Wirespeed GitHub App installation.
* Review and accept the App's read-only **Organization administration**
  permission. The App cannot modify repositories, organization settings,
  members, or code.
* For IP-based investigations and detections, enable source IP disclosure under
  **Organization Settings → Logs → Audit log → Settings**.

## Connect GitHub Enterprise Cloud

1. In Wirespeed, open
   [Settings → Integrations](https://app.wirespeed.co/settings/integrations?tab=browse)
   and select **GitHub Enterprise Cloud**.
2. Review these instructions, then select **Integrate**.
3. In GitHub, choose the Enterprise Cloud organization you want to monitor.
4. Review the requested read-only organization permission and install the
   Wirespeed GitHub App.
5. Authorize the App when GitHub prompts you. GitHub returns you to Wirespeed
   when the connection is ready.

Repeat the connection flow for each organization that should be monitored.

<Note>
  Deleting the Wirespeed connection does not uninstall the GitHub App. To
  connect the same organization again, uninstall the App in GitHub
  (**Organization Settings → GitHub Apps**), then reconnect from Wirespeed so
  GitHub can run the OAuth install flow again.
</Note>

<Note>
  Wirespeed uses the authorizing user's short-lived GitHub token only to verify
  access to the selected installation. Polling uses a one-hour installation
  token that is regenerated automatically; the user's token is not retained.
</Note>

## Data collection

The first sync imports up to seven days of available organization audit events.
Later syncs resume from the latest successfully ingested event and include both
web and Git events.

<Note>
  Source IP disclosure is disabled by default. Audit events are still ingested
  when it is disabled, but they do not include the actor IP address used by
  IP-based investigations and detections.
</Note>

GitHub can return **403** or **404** when the organization is not on Enterprise
Cloud or the App does not have Organization administration read permission.
Wirespeed reports that state on the integration rather than collecting partial
audit data.

## Detections

Wirespeed includes starter managed detections for organization IP allow-list
changes, owner-role assignments, SAML and two-factor requirement changes, and
grants of personal access tokens, OAuth Apps, or GitHub Apps.
