Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

GHEC Audit Log Streaming General Availability #213

Open
github-product-roadmap opened this issue Jul 12, 2021 · 0 comments
Open

GHEC Audit Log Streaming General Availability #213

github-product-roadmap opened this issue Jul 12, 2021 · 0 comments

Comments

@github-product-roadmap
Copy link
Collaborator

@github-product-roadmap github-product-roadmap commented Jul 12, 2021

Summary

Audit log streaming will enable customers to stream a high-fidelity set of audit log and git event data to a log collection point of their choosing. This capability will sit alongside our existing audit log and git events APIs and UI.

Intended Outcome

Audit and compliance objectives are increasing in importance to enterprise customers. We want enterprise administrators to be able to use the right tools for the job they need to do, whether that be short term investigation or longer term threat analysis and prevention. With audit log streaming, customers can be assured that no audit log event will be lost, and that they will be able to satisfy longer term data retention goals by storing streamed events within their own log aggregation systems. Administrators will also be able to analyze GitHub audit log data using the SIEM tool of their choosing.

How will it work?

We will support integration within multiple ecosystems including, but not limited to, Splunk and Azure. An enterprise owner will be able to configure a destination domain, port, and token with write authorization to the streaming endpoint. Stream data will be retained by GitHub for at least 7 days when the stream is paused or if otherwise unable to write to the configured location.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
1 participant