SIEM Log Forwarding
Allow your security teams to track critical data flows are being modified in Activations.
We are removing this feature from the Activations platform. Use External Logs and the Fivetran Platform Connector instead. The remaining Activations SIEM events will become available through these services in late 2026.
Introduction
The Enterprise plan offers a robust SIEM (Security Information and Event Management) log forwarding feature, compatible with all major SIEM providers including Datadog, Splunk, Sumo, and Panther. This feature is designed to enhance your organization's security and compliance capabilities by forwarding detailed event logs.
Requesting SIEM Log Forwarding Setup
To initiate the SIEM log forwarding setup, please reach out to our support team. During this process, you will need to provide an HTTP endpoint to which we will forward the events. We can support a variety of authentication mechanisms. Our team will guide you through the setup process to ensure seamless integration with your chosen SIEM system.
Log Forwarding Schedule
Events are forwarded in batches every 15 minutes, ensuring timely updates without overwhelming your SIEM system.
Log Format and Content
Logs are sent in JSON format. Each log includes the following properties:
- ACTION: The action that was performed by the user.
- ACTOR_EMAIL: The email of the user performing the action, if applicable.
- ACTOR_ID: The email of the user performing the action, if applicable.
- COMMENT: A description of the action.
- ENTITY: The entity related to the action.
- UNIQUE_ID: A unique id for the event.
- ORGANIZATION_ID: The actor's Activations organization ID.
- SOURCE_IP: The IP address associated with the actor.
- TIMESTAMP: When the action happened.
Supported Actions
Our system supports the following actions:
workspace_invite_sentuser_joined_organizationuser_workspace_role_updateduser_claimed_workspace_invitationorganization_invite_revokeduser_removed_from_workspaceworkspace_invite_revokedworkspace_invite_role_changedorganization_invite_sentuser_organization_role_updateduser_removed_from_organizationmodel_createdmodel_updatedmodel_deleteddestination_createddestination_deleted
Discontinued Events
We discontinued the following events in April 2026 as a result of the Census migration to Fivetran:
success_exchangefailed_loginsuccess_silent_authsuccess_loginsuccess_signuplogoutwarnings_during_loginfailed_exchangefailed_login_(invalid_email/username)failed_change_password_requestsuccess_change_passwordsuccess_change_password_requestfailed_login_(incorrect_password)success_verification_emailfailed_signupfailed_silent_authsuccess_logoutfailed_change_passwordfailed_sending_notificationfailed_verification_emailsuccess_user_deletionuser_login_block_releasedsuccess_verification_email_requestfailed_logoutsuccess_change_email