Skip to content

Integration options for Audit Logs #81337

@janstice

Description

@janstice

Problem Statement

We'd like to be able to import platform audit logs (or better still, selected events) into our SIEM to detect things like escalation of account privilege, changes to SSO or MFA settings, integration changes, changes to data scrubbing settings, etc -- the usual things that security teams get excited about (and ask about without fail in security reviews).

Currently the best option here is to build something of the internal undocumented endpoints, which can change without notice - having stable APIs would make things more robust.

Solution Brainstorm

No response

Product Area

Settings - Security & Privacy

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    Status

    No status

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions