Set up the Bitdefender integration

Connect Bitdefender GravityZone to octoja to see agent health, quarantined threats and EDR incidents on every device.

Written By Stefan Steuer

Last updated 8 days ago

Bitdefender GravityZone is a cloud-managed endpoint security platform. When you connect it to octoja, the Bitdefender Protection check shows for every device whether the local Bitdefender agent is running, whether its signatures are current and whether real-time protection is active β€” plus the quarantined threats and EDR incidents that GravityZone reports for that device. While the integration is in beta, its card on the Integrations page carries a BETA badge.

Prerequisites

  • You need the Integration Management permission in octoja. Administrators assign permissions to groups under Administration β†’ Groups.
  • You need a GravityZone Control Center API key. Create it in the GravityZone account that manages your customers' companies (your partner account) β€” a key only sees the companies below its own account. When creating the key, enable the Network, Quarantine and Incidents APIs; those are the three octoja calls. See Bitdefender's documentation for where to create API keys.
  • Know which cloud region your GravityZone tenant lives in: the EU cloud (cloudgz.gravityzone.bitdefender.com) or the non-EU cloud (cloud.gravityzone.bitdefender.com). An API key only works against its own region.
  • The Bitdefender Protection check runs on Windows and macOS devices with Bitdefender Endpoint Security installed.

Connect Bitdefender

  1. Go to Administration β†’ Integrations. Under Other platforms, find the Bitdefender card β€” it carries the BETA and Antivirus badges β€” and click Set up.
  2. In the Set up Bitdefender dialog, paste your API key and pick your Cloud region.
  3. Optionally click Test connection. A green "API key verified." line confirms a working key; a red "Bitdefender rejected this API key." line shows Bitdefender's reason if it is rejected.
  4. Click Save. The card switches to its connected layout: a Customers matched progress bar plus the Match customers button and the Disconnect icon. octoja stores the key in your instance configuration and never returns it through the API.

Match customers to GravityZone companies

octoja customers and GravityZone companies are independent records β€” after connecting you tell octoja which is which. Each octoja customer maps to exactly one GravityZone company.

  1. On the Bitdefender card, click Match customers.
  2. The dialog lists each octoja customer in a row. Pick the matching GravityZone company from the picker on each row β€” the picker shows each company's Company ID so you can tell same-named companies apart. Leave a row empty if the customer is not in GravityZone.
  3. Click Save. The progress bar on the card turns green when every octoja customer is matched and amber while the mapping is partial.

If companies are missing from the picker: the list contains exactly the companies that are managed under the account your API key was created in. Companies managed in a different partner account never appear β€” create the key in the account that manages them. If the dialog reports "Could not load companies", the key may no longer be valid or the account it belongs to is not a partner account.

Your matches are preserved across disconnect and reconnect β€” you do not lose the mapping when rotating the API key.

Matching links customers, not devices. Devices link automatically: the Bitdefender Protection check reads the GravityZone endpoint ID from the local agent, and octoja attaches the cloud data to the device through that ID. A device only shows GravityZone threat data when its own octoja customer is matched to the GravityZone company the device belongs to β€” if quarantine and incident data stays empty on a device whose health rows work, check that mapping first.

Add the check to your devices

The integration brings the Bitdefender Protection check. Assign it like any other check: open a device, switch to its Checks tab and click Add Check β€” or roll it out to many devices at once with a config package. The check runs on the device itself and reads the locally installed Bitdefender Endpoint Security, so the Bitdefender agent must be installed on the device; the health rows work even without the cloud connection. By default the check runs every 5 minutes.

Understanding the values

ValueWhat it means
Agent runningAt least one Bitdefender Endpoint Security service is running on the device. A stopped agent always reports critical.
Definitions currentThe signature database on the device has been updated within the last 48 hours. The check's warning/critical state additionally follows the signature-age thresholds you configure.
Real-time protectionOn-access scanning is enabled on the device.
Threats / quarantineThe number of entries in the device's local quarantine store. Shows "No threats" when it is 0.
Signatures / Signature ageThe signature version number and its age, as reported on the device.
Endpoint IDThe GravityZone ID of this device β€” octoja uses it to attach the cloud data below.
Quarantine (list)Threat name and file path for each item GravityZone holds in quarantine for this device. Refreshed about every 5 minutes; octoja shows up to 50 entries.
EDR incidentsThe number of EDR incidents GravityZone reports for this device. Requires an EDR license for the company β€” otherwise the check shows "No EDR license assigned β€” incidents unavailable."

The Threats / quarantine number is counted on the device itself: it is the raw number of files in the local Bitdefender quarantine store. That is not necessarily the number of detections the GravityZone console shows, so the two can differ. For the cloud view with threat names and file paths, use the Quarantine list on the same check.

Configure the thresholds

The check's warning and critical behaviour is configurable per assignment:

SettingDefaultEffect
Signature age β€” warning (hours)48Warn when the signature database is older than this many hours.
Signature age β€” critical (hours)168Report critical when the signature database is older than this many hours.
Real-time protection offCriticalSeverity when real-time protection is disabled: Ignore, Warning or Critical.
Quarantine β€” warning (count)1Warn when at least this many threats are quarantined. 0 disables.
Quarantine β€” critical (count)0 (off)Report critical when at least this many threats are quarantined. 0 disables.

What the integration card shows

Once connected, the Bitdefender card on the Integrations page aggregates across all matched companies: Endpoints with threats and EDR incidents as counts, and a warning line "Companies without EDR license" when some matched companies have no EDR add-on.

Rotate the key or disconnect

  • Bitdefender has rejected your key: the card shows "The API key is no longer valid. Update it to keep receiving data from Bitdefender." and an Update credentials button. Click it and save the new key.
  • Disconnect: click the Disconnect icon and confirm. The API key is removed; your customer matches are preserved in case you reconnect later.

Tips

  • If a device reports "Bitdefender Endpoint Security was not detected on this device.", the Bitdefender agent is not installed there β€” the check reports a warning, not a failure.
  • If the health rows work but the Quarantine list and EDR incidents stay empty, verify under Match customers that the device's customer is matched to the GravityZone company the device actually belongs to.
  • GravityZone threat data is refreshed about every 5 minutes β€” new detections appear on the device shortly after they show up in the GravityZone console.