Docs
Skills
Log in
API
CLI
JS Client

Put audit log sink

Creates or fully replaces an audit log sink.

Required permission

Account > Admin > AuditLogSinks > Create

Path parameters

    • sinkId

      string required
      ID of the audit log sink

Request body

  • {object}
    Create or replace an audit log sink
    • name

      string required
      Name of the audit log sink.
    • description

      string
      Description of the audit log sink.
      max length
      200
      pattern
      ^[a-zA-Z0-9.,?\s\\/'"()[\];`%^&*\-_:!]+$
    • sinkType

      string required
      The type of the audit log sink.
      one of
      aws_s3
    • sinkData

      (multiple options: oneOf) required
      • {object}
        AWS S3 or compatible API audit-log sink configuration.
        • endpoint

          string required
          Endpoint for the AWS S3 or compatible API bucket.
        • region

          string required
          Region of the S3 bucket.
        • bucket

          string required
          Name of the S3 bucket.
        • pathPrefix

          string
          Optional path prefix inside the bucket where objects are written.
        • compression

          string required
          Compression method applied to exported audit log batches.
          one of
          gzip, none
        • auth

          {object} required
          Authentication object.
          • accessKeyId

            string required
            Access key id for the bucket.
          • secretAccessKey

            string required
            Secret access key for the bucket.
    • includeSpec

      boolean
      When true, exported events include the enriched `before` and `after` spec of the audited resource. Secrets are always stripped from specs before export. Set to false to export only event headers (action, actor, scope).

Response body

  • {object}
    Response object.
    • data

      {object} required
      Result data.
      • id

        string required
        Identifier for the audit log sink.
      • name

        string required
        Name of the audit log sink.
      • description

        string
        Description of the audit log sink.
        max length
        200
        pattern
        ^[a-zA-Z0-9.,?\s\\/'"()[\];`%^&*\-_:!]+$
      • sinkType

        string required
        The type of the audit log sink.
        one of
        aws_s3
      • includeSpec

        boolean required
        Whether exported events include the enriched `before`/`after` spec or only headers.
      • status

        string required
        Current status of the audit log sink.
        one of
        paused, running, failing, creating
      • createdAt

        string required
        Timestamp of when the audit log sink was created.
      • updatedAt

        string required
        Timestamp of when the audit log sink was last updated.
      • sinkData

        {object} required
        Configuration of the destination. Secrets are omitted.
        • endpoint

          string required
        • region

          string required
        • bucket

          string required
        • pathPrefix

          string
        • compression

          string required
          one of
          gzip, none
        • auth

          {object} required
          Authentication object (secret omitted).
          • accessKeyId

            string required
API
CLI
JS Client

PUT /v1/integrations/audit-log-sinks/{sinkId}

PUT /v1/teams/{teamId}/integrations/audit-log-sinks/{sinkId}

Example request

Request body
curl --header "Content-Type: application/json" \
  --header "Authorization: Bearer NORTHFLANK_API_TOKEN" \
  --request PUT \
  --data '{"name":"compliance-bucket","description":"Forwards audit logs to the compliance S3 bucket.","sinkType":"aws_s3","sinkData":{"endpoint":"s3.amazonaws.com","region":"eu-west-2","bucket":"northflank-audit-logs","pathPrefix":"audit-logs/","compression":"gzip","auth":{"accessKeyId":"AKIAIOSFODNN7EXAMPLE","secretAccessKey":"wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY"}},"includeSpec":false}' \
  https://api.northflank.com/v1/integrations/audit-log-sinks/{sinkId}

Example response

200 OK

Details about the created or replaced sink.

JSON

{
  "data": {
    "id": "compliance-bucket",
    "name": "compliance-bucket",
    "description": "Forwards audit logs to the compliance S3 bucket.",
    "sinkType": "aws_s3",
    "includeSpec": false,
    "createdAt": "2026-05-11T12:00:00.000Z",
    "updatedAt": "2026-05-11T12:00:00.000Z"
  }
}

© 2026 Northflank Ltd. All rights reserved.

northflank.com / Terms / Privacy / feedback@northflank.ai