OBSERVABILITY Signal 269
Audit Log Drains now support Datadog, Splunk, and Panther
Audit Log Drains can now forward team audit events to Datadog, Splunk, or Panther in addition to the existing HTTPS endpoint and S3 options, replacing the previous Custom SIEM Log Streaming feature.
Engineers gain more direct integration paths for audit data into their observability and security stacks, reducing the need for custom middleware. The change is limited to Enterprise plans, so teams must evaluate their subscription level before adopting. Migration from the legacy Custom SIEM Log Streaming is required to continue receiving audit log streams.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Audit Log Drains now support Datadog, Splunk, and Panther as destinations.
The feature supersedes Custom SIEM Log Streaming and requires a migration guide for existing integrations.
Availability is restricted to Enterprise plans, and configuration is performed via the team settings Drains page.
THE READ
What the cluster adds up to.
The primary change is the addition of three new commercial destinations for Audit Log Drains, expanding the set of places where audit events can be sent beyond the original custom HTTPS endpoint and Amazon S3. This means teams can now stream audit data directly into Datadog, Splunk, or Panther without building their own forwarding logic. The underlying mechanism remains the same: every event from the Activity Log plus extra audit metadata is forwarded to the chosen destination.
Adopting the new drains requires an Enterprise subscription, as the feature is not available on lower tiers. Teams already using Custom SIEM Log Streaming must follow the provided migration guide to switch their integration to the new Audit Log Drain format, which involves re-configuring the drain in the team settings interface. The migration step introduces a small operational cost but avoids maintaining two parallel streaming paths.
If a team remains on a non-Enterprise plan, the new drain destinations cannot be used at all, limiting audit log forwarding to the legacy HTTPS endpoint or S3. Continuing to rely on Custom SIEM Log Streaming without completing the migration will result in missing out on the new destination options and may eventually lead to unsupported configurations as the older feature is phased out. The solution works only for the explicitly listed destinations; any other system would still require a custom endpoint or alternative approach.
Written by elseif from the cluster below · checked for specifics the sources never containedTHE CLUSTER
↗