Skip to content

SIEM Export

Everything governance-relevant that happens in IronArchitects lands in the audit log: sign-ins, decisions, approvals, drift findings, permission denials. SIEM export streams that log to your security operations stack, so the platform shows up where your analysts already look.

Plan Availability

SIEM export is available on the Large plan and above.

Destinations

Configure one or more destinations per organization:

  • Splunk (HTTP Event Collector)
  • Datadog (Logs API)
  • Syslog (TCP)

Each destination takes its endpoint and credential, can be tested from the page, and can be paused without being deleted.

What Streams

Audit events stream with their actor, action, resource, outcome, and time; the same record the in-product audit trail shows. Notably that includes drift findings as they open, so "the approved architecture changed in production" can alert in the same place as everything else your team watches.

Delivery Semantics

Streaming is at-least-once with per-destination progress tracking: a destination that was down catches up from where it left off rather than losing the gap. Your SIEM's own deduplication handles the rare repeat.