Stream org-level audit logs for SIEM
in progress
A
Adam Harvey
While self-service audit capability by an end-user through the UI is a very nice feature, it would be great to allow for dynamic log shipping or making the audit logs queryable through the REST API , so they can be fed into a Security Incident and Event Management type solution. (or into Splunk, another logging tool, etc)
As a fall out of the CircleCI Security incident announced in early January 2023 (rotate secrets), having the ability to quickly diagnose this data and compare it to other data we already had from other systems would have made security triage significantly faster/easier.
H
Henna Abbas
Hi All,
This feature is in progress. Below is how we plan on addressing Audit Log streaming. Feel free to share your feedback. Let us know if this does/does not meet your needs:
Problem: Manual audit log extraction lacks real-time visibility and complicates compliance reporting.
Solution: Automated streaming of audit logs directly to your AWS S3 buckets.
Simple Setup (see linked images below)
Step 1: Connect to AWS
Step 2: Verify Connection
Step 3: Monitor
Key Benefits:
Real-time security visibility with logs delivered in under 1 hour
Long-term compliance storage in your infrastructure
SIEM integration (Splunk, DataDog, Rapid7)
Enhanced security with OIDC authentication
99.9% streaming reliability
Technical Highlights:
Comprehensive event coverage (authentication, configuration changes, pipeline executions)
AWS S3 server-side encryption with JSON format
Compatible with Splunk, DataDog, and Rapid7
OIDC authentication support
99.9% streaming uptime and reliability
This post was marked as
in progress
This post was marked as
under review
A
Arkadiy Tetelman
Works for us - thank you! The AWS connection should please use role assumption / not require IAM users