Creates or fully replaces an audit log sink.
Required permission
Account > Admin > AuditLogSinks > Create
Path parameters
sinkId
string requiredID of the audit log sink
Request body
- {object}Create or replace an audit log sink
name
string requiredName of the audit log sink.description
stringDescription of the audit log sink.max length200pattern^[a-zA-Z0-9.,?\s\\/'"()[\];`%^&*\-_:!]+$sinkType
string requiredThe type of the audit log sink.one ofaws_s3sinkData
(multiple options: oneOf) required- {object}AWS S3 or compatible API audit-log sink configuration.
endpoint
string requiredEndpoint for the AWS S3 or compatible API bucket.region
string requiredRegion of the S3 bucket.bucket
string requiredName of the S3 bucket.pathPrefix
stringOptional path prefix inside the bucket where objects are written.compression
string requiredCompression method applied to exported audit log batches.one ofgzip, noneauth
{object} requiredAuthentication object.accessKeyId
string requiredAccess key id for the bucket.secretAccessKey
string requiredSecret access key for the bucket.includeSpec
booleanWhen true, exported events include the enriched `before` and `after` spec of the audited resource. Secrets are always stripped from specs before export. Set to false to export only event headers (action, actor, scope).
Response body
- {object}Response object.
data
{object} requiredResult data.id
string requiredIdentifier for the audit log sink.name
string requiredName of the audit log sink.description
stringDescription of the audit log sink.max length200pattern^[a-zA-Z0-9.,?\s\\/'"()[\];`%^&*\-_:!]+$sinkType
string requiredThe type of the audit log sink.one ofaws_s3includeSpec
boolean requiredWhether exported events include the enriched `before`/`after` spec or only headers.status
string requiredCurrent status of the audit log sink.one ofpaused, running, failing, creatingcreatedAt
string requiredTimestamp of when the audit log sink was created.updatedAt
string requiredTimestamp of when the audit log sink was last updated.sinkData
{object} requiredConfiguration of the destination. Secrets are omitted.endpoint
string requiredregion
string requiredbucket
string requiredpathPrefix
stringcompression
string requiredone ofgzip, noneauth
{object} requiredAuthentication object (secret omitted).accessKeyId
string required
API
CLI
JS Client
PUT /v1/integrations/audit-log-sinks/{sinkId}
PUT /v1/teams/{teamId}/integrations/audit-log-sinks/{sinkId}
Example request
Request body
curl --header "Content-Type: application/json" \
--header "Authorization: Bearer NORTHFLANK_API_TOKEN" \
--request PUT \
--data '{"name":"compliance-bucket","description":"Forwards audit logs to the compliance S3 bucket.","sinkType":"aws_s3","sinkData":{"endpoint":"s3.amazonaws.com","region":"eu-west-2","bucket":"northflank-audit-logs","pathPrefix":"audit-logs/","compression":"gzip","auth":{"accessKeyId":"AKIAIOSFODNN7EXAMPLE","secretAccessKey":"wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY"}},"includeSpec":false}' \
https://api.northflank.com/v1/integrations/audit-log-sinks/{sinkId}Example response
200 OK
Details about the created or replaced sink.
JSON
{
"data": {
"id": "compliance-bucket",
"name": "compliance-bucket",
"description": "Forwards audit logs to the compliance S3 bucket.",
"sinkType": "aws_s3",
"includeSpec": false,
"createdAt": "2026-05-11T12:00:00.000Z",
"updatedAt": "2026-05-11T12:00:00.000Z"
}
}