Skip to main content

Log Delivery

The Log Delivery page tracks the delivery of audit logs to your configured log providers (Splunk, Grafana Loki, Coralogix, CrowdStrike, and Webhook) and shows whether each delivery succeeded or failed. Reach it from the Logs page: open the overflow (three-dot) menu and select Log Delivery.

Log Delivery page with Start Date, End Date, Provider, Status, and Trigger filters, a search field, and a table with Date, Provider, Destination, Trigger, Status, and Details columns

Providers are configured under Settings › Logs. This page is the delivery history for those providers: use it to confirm logs are reaching your SIEM and to diagnose failed deliveries.

Filters

  • Start Date and End Date set the window of deliveries to show.
  • Provider filters to a single configured log provider.
  • Status filters by outcome (a delivery either succeeded or failed).
  • Trigger filters by what initiated the delivery.
  • Search deliveries does a free-text search across the entries.

Table columns

ColumnDescription
DateWhen the delivery was attempted.
ProviderThe configured log provider the logs were sent to.
DestinationThe endpoint the logs were delivered to.
TriggerWhat initiated the delivery.
StatusWhether the delivery succeeded or failed.
DetailsSelect to inspect the delivery, including any error returned by the provider.

What to do next

On this page