Team: Huntress Managed Security Information and Event Management (SIEM)
Product: IT Glue
Environment: IT Glue Account Settings; Huntress Platform
Summary: Collect the IT Glue activity log in Huntress Managed SIEM using an IT Glue API key.
Vendor Information
| Vendor | IT Glue (a Kaseya company) |
| Supported Plans | Any IT Glue plan that includes API access |
| Collection Method | Huntress polls the IT Glue REST API every five minutes |
| Provider Name | IT Glue |
| Vendor Reference Links | IT Glue API developer docs, Activity Logs, Getting started with the IT Glue API |
In this Article
What Huntress Collects
Before You Begin
Generate the API Key in IT Glue
Hand Credentials to Another Admin
Configure the Source in Huntress
Map Your Organizations
What to Expect After Connecting
Search IT Glue Logs in SIEM
Example Log Messages
What Is Not Collected
Troubleshooting
What Huntress Collects
Huntress collects the IT Glue activity log: one record per action taken in your account, including the actor, affected resource, source IP address with city, region, and country, and user agent. Read actions and changes are included as well, so opening or copying a password, viewing an organization, and signing in are all collected.
Measured on two live accounts, the records covered these resource types: Organization, User, AccountsUser, Group, APIKey, Password, Export, ScheduledTask, and MyGlueAccount. IT Glue documents the activity log as covering all account activity, so other types, such as documents and configurations, might also appear.
Huntress attaches the actor's name and email and the organization's name to each record at collection time, so records are searchable by name and location rather than by numeric ID. Huntress also normalizes each record onto shared SIEM fields, so IT Glue sign-ins, failed sign-ins, and user administration are searchable alongside the same activity from your other data sources.
Before You Begin
Before you begin setup, ensure you have:
- An IT Glue Administrator. Only administrators can generate API keys.
- Your IT Glue data center. IT Glue serves three regional API hosts: standard (
api.itglue.com), EU (api.eu.itglue.com), and Australia (api.au.itglue.com). A key works only against its region, so know which region your account uses before starting. - A Huntress account with the Huntress Managed SIEM entitlement.
Note: API request volume is not a concern. IT Glue allows 3,000 requests per five-minute window, and each Huntress poll uses a small fraction of that limit.
Generate the API Key in IT Glue
1. Sign in to IT Glue as an Administrator.
2. Go to Account > Settings > API Keys.
3. Generate a new key. Use a recognizable name, such as "Huntress Managed SIEM".
4. Copy the key. Treat it as a password; it grants read access to your account data.
Note: IT Glue keys do not expire, but IT Glue revokes a key after 90 days of inactivity and warns account administrators 10 days in advance. A connected Huntress log source polls every five minutes and keeps its key active. Revocation only affects a source that has been deactivated for months; see Troubleshooting.
Configure the Source in Huntress
1. Log in to Huntress and go to Source Management > Add Source.
2. Under RMM, select IT Glue.
3. Name the source and enter a description.
4. Select your Data Center.
5. Enter the API Key.
6. Save your changes. Huntress validates the key against your IT Glue account before creating the log source.
Map Your Organizations
After creating the source, open Configure on the source page. Huntress lists every organization in your IT Glue account across the Mapped Organizations and Unmapped Organizations tabs. For each IT Glue organization whose activity you want to collect, select the corresponding Huntress organization and save your changes.
Warning: Activity inside an unmapped IT Glue organization is discarded, and mapping the organization later does not recover history. Two kinds of records are preserved: activity inside a mapped organization (such as opening a password, which routes to the selected Huntress organization) and account-level activity (which routes to the source itself). While no organization is mapped, the source page and the Source Management page display a warning. The warning clears once any organization is mapped, so a partially mapped source displays no warning while discarding activity for unmapped organizations. Map all necessary organizations during setup, and return to the Unmapped Organizations tab when adding organizations in IT Glue.
Note: Account-level activity includes sign-ins, user and group administration, API key changes, and views or edits of organization records. IT Glue records an organization view without an organization ID, so it routes to the source rather than to the mapped Huntress organization.
What to Expect After Connecting
Activity appears within minutes. Huntress polls every five minutes, and each record becomes searchable shortly after the poll fetches it.
Collection starts upon connection. IT Glue's API serves the most recent 30 days of activity, but Huntress collects forward from the moment you save the log source rather than importing past history.
Integrations can generate high log volume. PSA, RMM, and documentation integrations constantly read IT Glue, generating activity records for each read action. Measured on live accounts, 90% of password retrievals in one account originated from a PSA integration, and 90% of another account's total records originated from a single API integration.
Actions taken with an API key do not contain user details. IT Glue records API key actions against the account rather than a user, so user.name and user.email are absent. The user agent identifies the integration: user_agent.original contains the client string, such as node, python-requests/2.33.0, or a PowerShell version string.
IT Glue server-side actions do not contain an IP address. When IT Glue performs an action directly, such as an integration's password retrieval, the record lists Server in itglue.ip_country and omits source.ip. Server indicates a system marker, not a physical location.
Actor and organization names are attached during polling. Huntress looks up user and organization names from your IT Glue account during each poll. A record for a user deleted after the action retains its numeric ID but omits its name. An API key without user or organization read permissions produces records with numeric IDs only; activity collection continues.
An outage longer than 30 days creates a permanent log gap. The API serves only the most recent 30 days, and there is no backfill path beyond that window. A source that is broken, deactivated, or that uses a revoked key for more than 30 days permanently loses log data older than 30 days. IT Glue's UI retains full history, so records remain accessible in IT Glue even if they are not synced to Huntress.
Retention of collected events follows standard Huntress SIEM retention rules. IT Glue retains activity logs in its UI indefinitely and serves 30 days over the API. Events collected by Huntress are governed by your Huntress retention policy, not IT Glue policies.
Search IT Glue Logs in SIEM
The event.provider field identifies the source. Normalized fields appear first; every field sent by IT Glue is searchable under the itglue. prefix with dashes normalized to underscores.
| Field | Description | Example |
|---|---|---|
event.provider |
Always identifies the source vendor. | IT Glue |
@timestamp |
When the action happened, according to IT Glue's record. | 2026-09-16T14:54:06.047Z |
event.action |
IT Glue's action, exactly as IT Glue names it. | saml_sso_user_login |
event.category |
Normalized category. Set on sign-ins and on user, group, API key, and password records; absent otherwise. |
authentication, iam
|
event.type |
Normalized type. |
start, access, creation, deletion, change, info
|
event.outcome |
Set on sign-ins. |
success, failure
|
user.name |
Actor's name, attached by Huntress. Absent on API key actions. | Jane Analyst |
user.email |
Actor's email, attached by Huntress. | jane@example.com |
user.id |
IT Glue user ID of the actor. | 54 |
source.ip |
Actor's IP address. Absent on the IT Glue server-side actions. | 203.0.113.24 |
user_agent.original |
Actor's browser or API client. | Mozilla/5.0 ... |
itglue.resource_type |
The kind of resource acted on. | Password |
itglue.resource_name |
The name of the resource acted on. | Billing portal login |
itglue.organization_id |
IT Glue is the organization where the action happened. Absent on account-level actions. | 226 |
itglue.organization_name |
That organization's name, attached by Huntress. | Example Client Co |
itglue.log_id |
IT Glue's unique ID for the activity record. | 574989297464115201 |
itglue.level |
IT Glue's log level for the record. | 2 |
itglue.ip_city / itglue.ip_region / itglue.ip_country
|
Location IT Glue derived from the IP. itglue.ip_country reads Server on IT Glue server-side actions. |
San Diego / CA / United States
|
Note: Search an IT Glue organization by
itglue.organization_name. In SIEM search,organization.namealways refers to the Huntress organization a record belongs to, not the IT Glue one.
Note: IT Glue truncates country names longer than 50 characters and ends them with
..., so an exact match on a long country name initglue.ip_countryfails.
Category, type, and outcome by IT Glue action and resource type:
| IT Glue action | Resource type | event.category | event.type | event.outcome |
|---|---|---|---|---|
saml_sso_user_login |
User |
authentication |
start |
success |
failed_login |
User |
authentication |
start |
failure |
locked_account |
User |
iam |
change |
not set |
create, sso_user_create, complex_create
|
User, AccountsUser, Group, APIKey, Password
|
iam |
creation |
not set |
destroy |
User, AccountsUser, Group, APIKey, Password
|
iam |
deletion |
not set |
edit, update
|
User, AccountsUser, Group, APIKey, Password
|
iam |
change |
not set |
access, show, copy
|
Password |
iam |
access |
not set |
show |
Organization, Export, and other types |
not set | access |
not set |
edit, update
|
Organization and other types |
not set | change |
not set |
Note: An action not listed above keeps its name in
event.actionand receivesevent.typeofinfo. A resource type not listed above receives noevent.category. Search either by itsitglue.field.
Example Query Builder rows. Each row is a field, an operator, and a value:
| Goal | Field | Operator | Value |
|---|---|---|---|
| Failed IT Glue sign-ins | event.provider |
is | IT Glue |
event.outcome |
is | failure |
|
| Password retrievals | itglue.resource_type |
is | Password |
event.type |
is | access |
|
| Users, groups, or API keys deleted | event.provider |
is | IT Glue |
event.category |
is | iam |
|
event.type |
is | deletion |
|
| Activity by one user | user.email |
is | jane@example.com |
| Activity from one API integration | user_agent.original |
is | python-requests/2.33.0 |
| Activity in one client's organization | itglue.organization_name |
is | Example Client Co |
| Activity from one country | itglue.ip_country |
is | United States |
Note: The field box suggests the most common ECS fields and also accepts anything you type. Every
itglue.field is searchable but absent from the suggestion list, so type those in full.
Example Log Messages
The examples below are synthesized from the field sets and values observed on live accounts. Names, addresses, and IDs are placeholders.
A user signing in through SAML single sign-on:
{
"@timestamp": "2026-09-16T14:54:06.047Z",
"event.provider": "IT Glue",
"event.kind": "event",
"event.action": "saml_sso_user_login",
"event.category": "authentication",
"event.type": "start",
"event.outcome": "success",
"user.id": "54",
"user.name": "Jane Analyst",
"user.email": "jane@example.com",
"source.ip": "203.0.113.24",
"user_agent.original": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) ...",
"itglue.log_id": "574989297464115201",
"itglue.action": "saml_sso_user_login",
"itglue.resource_type": "User",
"itglue.resource_name": "Jane Analyst",
"itglue.ip_city": "San Diego",
"itglue.ip_region": "CA",
"itglue.ip_country": "United States"
}
A PSA integration retrieving a password, performed by IT Glue server-side:
{
"@timestamp": "2026-09-16T15:02:41.310Z",
"event.provider": "IT Glue",
"event.kind": "event",
"event.action": "access",
"event.category": "iam",
"event.type": "access",
"user.id": "61",
"user.name": "PSA Integration",
"user.email": "psa-integration@example.com",
"itglue.log_id": "574989297464115388",
"itglue.action": "access",
"itglue.resource_type": "Password",
"itglue.resource_name": "Billing portal login",
"itglue.organization_id": "226",
"itglue.organization_name": "Example Client Co",
"itglue.ip_country": "Server"
}
An API integration viewing an organization record, with no user and no organization ID:
{
"@timestamp": "2026-09-21T09:17:55.802Z",
"event.provider": "IT Glue",
"event.kind": "event",
"event.action": "show",
"event.type": "access",
"source.ip": "198.51.100.40",
"user_agent.original": "node",
"itglue.log_id": "574989297464120017",
"itglue.action": "show",
"itglue.resource_type": "Organization",
"itglue.resource_name": "Example Client Co",
"itglue.ip_city": "Ashburn",
"itglue.ip_region": "VA",
"itglue.ip_country": "United States"
}
What Is Not Collected
- Activity from before you connected. Huntress collects forward from the moment the log source is saved.
- Activity inside unmapped IT Glue organizations. See Map Your Organizations. This is a discard, not a deferral. Huntress warns that if no organization is mapped, activity in the rest is discarded without warning.
- Anything older than 30 days during an outage. The API serves only the most recent 30 days, with no backfill beyond that.
- The person behind an API key action. IT Glue does not record one. The user agent and source IP are the only record carriers.
- Real-time pushed events. IT Glue offers no outgoing event feed for the activity log; its Workflows feature is a separate product with its own trigger list. Huntress polls.
Troubleshooting
Saving the log source fails with an invalid credentials error:
- Confirm the key was copied in full from Account > Settings > API Keys.
- Confirm the Data Center matches where your IT Glue account lives. A valid key fails against the wrong regional host.
- Rarely, the validation request itself is rate-limited and reports as invalid credentials. Wait a minute and save again.
The source is healthy, but one organization's activity never appears. That IT Glue organization is unmapped. Open Configure, find it on the Unmapped Organizations tab, and map it. The collection for it starts from the mapping forward; the discarded history does not come back. If no organization is mapped, the source page displays a warning.
Organization views appear on the source rather than the mapped Huntress organization. Expected. IT Glue records views and edits of an organization record without an organization ID, so they are captured as account-level activity.
Most records have no username. Those are actions taken with an API key, which IT Glue records against the account rather than a person. Use user_agent.original to tell the integrations apart. A record with Server in itglue.ip_country and no IP address is an action IT Glue performs server-side, usually on behalf of an integration.
Records show numeric IDs instead of user and organization names. The names are looked up in real time for each poll. A deleted user keeps only the ID. If no record carries names, the key can't read your account's users and organizations; generate a full-access key.
No data appears at all, and the log source looks healthy. The activity log records actions, so a quiet account produces nothing until someone signs in, views, or changes something. Open any record in IT Glue, and it should appear within minutes.