Datadog
Forward identity and security events to Datadog Logs with Authdog-tagged sources for filtering and monitors.
SIEM
Every sign-in, permission change, and admin action becomes a normalized event you can forward to the tools your security team already runs. No scraping dashboards, no custom exporters.
Log streaming
Configure destinations per environment in the console. Each channel is independently enabled, tested, and retried.
Forward identity and security events to Datadog Logs with Authdog-tagged sources for filtering and monitors.
Push events to a Splunk HTTP Event Collector endpoint with your own index, source, and sourcetype.
Deliver structured JSON events to a Sumo Logic hosted collector for search, dashboards, and alerting.
Emit security-relevant identity activity to the Sysdig Events API alongside your runtime signals.
Ship the raw event payload to any HTTPS endpoint and verify it with a shared signing secret.
Post high-signal security events straight into the channel your on-call team watches.
Audit trail
Channels forward what the audit log already captures, so exported events and in-console history never disagree.
Append-only history of authentication, authorization, and configuration changes with actor and origin.
Every entry records who acted and through which surface, from the console, the API, the CLI, or an agent.
Filter the event families you forward so noisy operational traffic never buries a security signal.
Failed deliveries are retried with exponential backoff and surfaced in the console when a channel stays unhealthy.
Retain identity evidence in the system your auditors already accept instead of a second silo.
Pick a destination in the console under your environment's notification channels and paste in its endpoint or token.
Verify the connection end to end before you depend on it, and see the exact payload your collector will receive.
Join Authdog identity events with the rest of your telemetry to investigate access changes alongside incidents.
Connect a SIEM destination in minutes and start streaming your audit trail where it can be correlated.