Introduction
Audit logs are available exclusively for Enterprise customers. Account admins can enable them in Settings.
Key Features
Review more than 50 event types across your organization.
Audit Log Portal
View, filter, and bulk-export audit events.
SIEM Integration
Stream events to Datadog, Splunk, Amazon S3, or a generic HTTP endpoint.
Admin-Only Access
Only organization admins can view audit logs and configure streaming, keeping your security data protected
Getting Started
1
Enable Audit Logs
Navigate to Settings > Advanced > Audit Logs and select Enable audit logs. You must be an organization admin to enable this feature.
2
View Audit Logs
Once enabled, select View audit logs to open the audit log portal
3
Set Up SIEM Integration (Optional)
Select Set up SIEM integration to configure real-time log streaming to your security tools
Tracked Events
Audit logs capture more than 50 event types across your organization, including:- Deployments
- Access and identity
- Workspace administration
- Project activity
- Secrets
- Connectors
- Domains
- Agent activity
Viewing Audit Logs
To view your organization’s audit logs:- Go to Settings > Advanced
- In the Audit Logs section, select View audit logs
- The audit log portal opens, where you can view, filter, and bulk-export events
- Search — Find specific events by keyword
- Filters — Narrow results by event type, date range, actor, or target
- Bulk export — Download log data for offline analysis or compliance reporting
SIEM Integration
SIEM (Security Information and Event Management) integration allows you to stream audit log events in real time to your existing security tools. This is useful for:- Centralizing security monitoring across all your enterprise tools
- Setting up automated alerts based on audit log patterns
- Meeting compliance requirements for log retention and analysis
Setting Up Log Streaming
- Go to Settings > Advanced
- In the Audit Logs section, select Set up SIEM integration
- The log streaming configuration portal opens
- Follow the instructions to connect your SIEM provider
- Datadog
- Splunk
- Amazon S3
- Generic HTTP endpoint (webhook)
Log streaming is configured through the WorkOS portal. Changes to your streaming configuration take effect immediately.
FAQs
Who can view audit logs?
Only organization admins can access audit logs and configure SIEM integration. Non-admin members do not have access to any audit log data.Do I need SCIM enabled to use audit logs?
No. SCIM is not required to use audit logs. SCIM and audit logs share your account’s WorkOS organization, but you must enable each feature separately. When audit logs are enabled, they can include SCIM provisioning and deprovisioning events.What happens if an audit log event fails to record?
Audit log recording is designed to never interfere with the underlying operation. If an event fails to be recorded, the original action (such as user provisioning) still completes successfully. Failed events are logged internally for investigation.How long are audit logs retained?
Replit retains audit logs for 30 days by default. To keep events longer, set up SIEM integration and stream them to your own storage. For longer in-portal retention, contact Replit Support.Can I export audit logs?
Yes. You can bulk-export audit log data from the audit log portal. You can also stream events to a supported destination.Related Resources
Workspace Settings
Set Enterprise policy for the Agent models and model providers each Workspace can use.
SCIM
Set up automated user provisioning with SCIM integration
SAML SSO
Configure single sign-on authentication for your organization
Groups & Permissions
Manage user roles and access controls
Enterprise Privacy Settings
Configure organization-wide privacy and security settings