Introducing near real-time audit logs
![]()
Starting August 18, 2026, Enterprise customers can stream audit log events to their cloud storage destination within approximately 5 minutes of the event occurring.
Near real-time audit logs give security and platform teams immediate visibility into who is accessing and changing content across their organisation. Events arrive in minutes, enabling fast detection and investigation of suspicious activity, and feed directly into existing security workflows and SIEM tools. Events are delivered in OCSF format (Open Cybersecurity Schema Framework), compatible with major SIEM tools including Splunk, Datadog, and Azure Sentinel.
With near real-time audit logs, you can:
- Receive audit events within approximately 5 minutes to your AWS S3, Azure Blob, or Google Cloud Storage destination.
- Monitor who accessed or changed content in near real time and feed events directly into your existing security workflows.
- Capture read access (GET requests) in addition to write operations, giving you visibility into who viewed sensitive content.
Near real-time audit logs and daily audit logs operate independently and continue to co-exist.
Near real-time audit logs are configured through the Enterprise Observability UI, under Organization settings > Observability. Or by using the Management API (CMA).
To learn more, see the near real-time audit logs documentation.