feat(docs): audit log stream docs rewrite
@@ -6,56 +6,74 @@ description: "Learn how to stream Infisical Audit Logs to external logging provi
|
|||||||
<Info>
|
<Info>
|
||||||
Audit log streams is a paid feature.
|
Audit log streams is a paid feature.
|
||||||
|
|
||||||
If you're using Infisical Cloud, then it is available under the **Enterprise Tier**. If you're self-hosting Infisical,
|
If you're using Infisical Cloud, then it is available under the **Enterprise Tier**. If you're self-hosting Infisical, then you should contact [email protected] to purchase an enterprise license to use it.
|
||||||
then you should contact [email protected] to purchase an enterprise license to use it.
|
|
||||||
</Info>
|
</Info>
|
||||||
|
|
||||||
Infisical Audit Log Streaming enables you to transmit your organization's Audit Logs to external logging providers for monitoring and analysis.
|
Infisical Audit Log Streaming enables you to transmit your organization's audit logs to external logging providers for monitoring and analysis.
|
||||||
|
|
||||||
The logs are formatted in JSON, requiring your logging provider to support JSON-based log parsing.
|
|
||||||
|
|
||||||
|
|
||||||
## Overview
|
## Overview
|
||||||
|
|
||||||
<Steps>
|
<Steps>
|
||||||
<Step title="Navigate to Organization Settings in your sidebar." />
|
<Step title="Create Stream">
|
||||||
<Step title="Select Audit Log Streams Tab.">
|
1. Navigate to **Organization Settings**
|
||||||
|
2. Select the **Audit Log Streams** tab
|
||||||
|
3. Click **Add Log Stream**
|
||||||
|
|
||||||

|

|
||||||
</Step>
|
</Step>
|
||||||
<Step title="Click on Create">
|
<Step title="Select Provider">
|
||||||

|
If your log provider is included in this list, select it. Otherwise click on **Custom** to input your own Endpoint URL and headers.
|
||||||
|
|
||||||
Provide the following values
|

|
||||||
<ParamField path="Endpoint URL" type="string" required>
|
</Step>
|
||||||
The HTTPS endpoint URL of the logging provider that collects the JSON stream.
|
<Step title="Input Credentials">
|
||||||
</ParamField>
|
Depending on your chosen provider, you'll be asked to input different credentials.
|
||||||
<ParamField path="Headers" type="string" >
|
|
||||||
The HTTP headers for the logging provider for identification and authentication.
|
For **Custom**, you need to input an endpoint URL and headers.
|
||||||
</ParamField>
|
|
||||||
|

|
||||||
|
|
||||||
|
Once you're finished, click **Create Log Stream**.
|
||||||
|
</Step>
|
||||||
|
<Step title="Log Stream Created">
|
||||||
|
Your audit logs are now ready to be streamed.
|
||||||
|
|
||||||
|

|
||||||
</Step>
|
</Step>
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|
||||||

|
|
||||||
Your Audit Logs are now ready to be streamed.
|
|
||||||
|
|
||||||
## Example Providers
|
## Example Providers
|
||||||
|
|
||||||
### Better Stack
|
<AccordionGroup>
|
||||||
|
<Accordion title="Better Stack">
|
||||||
|
You can stream to Better Stack using a **Custom** log stream.
|
||||||
|
|
||||||
<Steps>
|
<Steps>
|
||||||
<Step title="Select Connect Source">
|
<Step title="Connect Source">
|
||||||

|
On Better Stack, select **Connect Source** and click **Create source** after providing a name.
|
||||||
</Step>
|
|
||||||
<Step title="Provide a name and select platform"/>
|
|
||||||
<Step title="Provide Audit Log Stream inputs">
|
|
||||||

|
|
||||||
|
|
||||||
1. Copy the **endpoint** from Better Stack to the **Endpoint URL** field.
|

|
||||||
3. Create a new header with key **Authorization** and set the value as **Bearer \<source token from betterstack\>**.
|
|
||||||
|
Once your source is created, take note of the **endpoint** and **Source token** for the next step.
|
||||||
|
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
<Step title="Create Audit Log Stream on Infisical">
|
||||||
|
On Infisical, create a new audit log stream and select the **Custom** option.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
1. Fill in the endpoint URL with your Better Stack source endpoint
|
||||||
|
2. Create a new header with key `Authorization` and set the value as `Bearer <betterstack-src-token>`
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
Once you're finished, click **Create Log Stream**.
|
||||||
</Step>
|
</Step>
|
||||||
</Steps>
|
</Steps>
|
||||||
|
</Accordion>
|
||||||
### Datadog
|
<Accordion title="Datadog">
|
||||||
|
You can stream to Datadog using the **Datadog** provider log stream.
|
||||||
|
|
||||||
<Steps>
|
<Steps>
|
||||||
<Step title="Navigate to API Keys section">
|
<Step title="Navigate to API Keys section">
|
||||||
@@ -65,25 +83,56 @@ Your Audit Logs are now ready to be streamed.
|
|||||||

|

|
||||||

|

|
||||||
</Step>
|
</Step>
|
||||||
<Step title="Find your Datadog region specific logging endpoint.">
|
<Step title="Create Audit Log Stream on Infisical">
|
||||||

|
On Infisical, create a new audit log stream and select the **Datadog** provider option.
|
||||||
|
|
||||||
1. Navigate to the [Datadog Send Logs API documentation](https://docs.datadoghq.com/api/latest/logs/?code-lang=curl&site=us5#send-logs).
|
Input your **Datadog Region** and the **Token** obtained from step 2.
|
||||||
2. Pick your Datadog account region.
|
|
||||||
3. Obtain your Datadog logging endpoint URL.
|
|
||||||
</Step>
|
|
||||||
<Step title="Provide audit log stream inputs">
|
|
||||||

|
|
||||||
|
|
||||||
1. Copy the **logging endpoint** from Datadog to the **Endpoint URL** field.
|

|
||||||
2. Copy the **API Key** from previous step
|
|
||||||
3. Create a new header with key **DD-API-KEY** and set the value as **API Key**.
|
Once you're finished, click **Create Log Stream**.
|
||||||
</Step>
|
</Step>
|
||||||
</Steps>
|
</Steps>
|
||||||
|
</Accordion>
|
||||||
|
<Accordion title="Splunk">
|
||||||
|
You can stream to Splunk using the **Splunk** provider log stream.
|
||||||
|
|
||||||
## Audit Log Stream Data
|
<Steps>
|
||||||
|
<Step title="Obtain Splunk Token">
|
||||||
|
Navigate to **Settings** > **Data Inputs**.
|
||||||
|
|
||||||
Each log entry sent to the external logging provider will follow the same structure.
|

|
||||||
|
|
||||||
|
Click on **HTTP Event Collector**.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
Click on **New Token** in the top left.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
Provide a name and click **Next**.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
On the next page, click **Review** and then **Submit** at the top. On the final page you'll see your token.
|
||||||
|
|
||||||
|
Copy the **Token Value** and your Splunk hostname from the URL to be used for later.
|
||||||
|
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
<Step title="Create Audit Log Stream on Infisical">
|
||||||
|
On Infisical, create a new audit log stream and select the **Splunk** provider option.
|
||||||
|
|
||||||
|
Input your **Splunk Hostname** and the **Token** obtained from step 1.
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
Once you're finished, click **Create Log Stream**.
|
||||||
|
</Step>
|
||||||
|
</Steps>
|
||||||
|
</Accordion>
|
||||||
|
</AccordionGroup>
|
||||||
|
|
||||||
### Example Log Entry
|
### Example Log Entry
|
||||||
|
|
||||||
@@ -117,6 +166,11 @@ Each log entry sent to the external logging provider will follow the same struct
|
|||||||
```
|
```
|
||||||
|
|
||||||
### Audit Logs Structure
|
### Audit Logs Structure
|
||||||
|
|
||||||
|
<Warning>
|
||||||
|
Streamed audit log structure **varies based on provider**, but they all share the audit log fields shown below.
|
||||||
|
</Warning>
|
||||||
|
|
||||||
<ParamField path="id" type="string" required>
|
<ParamField path="id" type="string" required>
|
||||||
The unique identifier for the log entry.
|
The unique identifier for the log entry.
|
||||||
</ParamField>
|
</ParamField>
|
||||||
@@ -128,6 +182,7 @@ Each log entry sent to the external logging provider will follow the same struct
|
|||||||
<ParamField path="actorMetadata" type="object" required>
|
<ParamField path="actorMetadata" type="object" required>
|
||||||
The metadata associated with the actor. This varies based on the actor type.
|
The metadata associated with the actor. This varies based on the actor type.
|
||||||
|
|
||||||
|
<AccordionGroup>
|
||||||
<Accordion title="User Metadata">
|
<Accordion title="User Metadata">
|
||||||
This metadata is present when the `actor` field is set to `user`.
|
This metadata is present when the `actor` field is set to `user`.
|
||||||
|
|
||||||
@@ -141,7 +196,6 @@ Each log entry sent to the external logging provider will follow the same struct
|
|||||||
The username of the actor.
|
The username of the actor.
|
||||||
</ParamField>
|
</ParamField>
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="Identity Metadata">
|
<Accordion title="Identity Metadata">
|
||||||
This metadata is present when the `actor` field is set to `identity`.
|
This metadata is present when the `actor` field is set to `identity`.
|
||||||
|
|
||||||
@@ -152,7 +206,6 @@ Each log entry sent to the external logging provider will follow the same struct
|
|||||||
The name of the identity.
|
The name of the identity.
|
||||||
</ParamField>
|
</ParamField>
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="Service Token Metadata">
|
<Accordion title="Service Token Metadata">
|
||||||
This metadata is present when the `actor` field is set to `service`.
|
This metadata is present when the `actor` field is set to `service`.
|
||||||
|
|
||||||
@@ -163,12 +216,11 @@ Each log entry sent to the external logging provider will follow the same struct
|
|||||||
The name of the service.
|
The name of the service.
|
||||||
</ParamField>
|
</ParamField>
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
</AccordionGroup>
|
||||||
|
|
||||||
<Note>
|
<Note>
|
||||||
If the `actor` field is set to `platform`, `scimClient`, or `unknownUser`, the `actorMetadata` field will be an empty object.
|
If the `actor` field is set to `platform`, `scimClient`, or `unknownUser`, the `actorMetadata` field will be an empty object.
|
||||||
</Note>
|
</Note>
|
||||||
|
|
||||||
</ParamField>
|
</ParamField>
|
||||||
|
|
||||||
<ParamField path="ipAddress" type="string" required>
|
<ParamField path="ipAddress" type="string" required>
|
||||||
|
|||||||
|
After Width: | Height: | Size: 462 KiB |
|
After Width: | Height: | Size: 111 KiB |
|
Before Width: | Height: | Size: 74 KiB |
|
Before Width: | Height: | Size: 38 KiB |
|
After Width: | Height: | Size: 98 KiB |
|
After Width: | Height: | Size: 436 KiB |
|
After Width: | Height: | Size: 324 KiB |
|
After Width: | Height: | Size: 523 KiB |
|
After Width: | Height: | Size: 103 KiB |
|
After Width: | Height: | Size: 421 KiB |
|
After Width: | Height: | Size: 541 KiB |
|
After Width: | Height: | Size: 205 KiB |
|
Before Width: | Height: | Size: 361 KiB After Width: | Height: | Size: 698 KiB |
|
Before Width: | Height: | Size: 36 KiB |
|
Before Width: | Height: | Size: 112 KiB After Width: | Height: | Size: 702 KiB |