Docs
Skills
Log in
API
CLI
JS Client

Create audit log sink

Creates a new audit log sink.

Required permission

Account > Admin > AuditLogSinks > Create

Request body

  • {object}
    Create or replace an audit log sink
    • name

      string required
      Name of the audit log sink.
    • description

      string
      Description of the audit log sink.
      max length
      200
      pattern
      ^[a-zA-Z0-9.,?\s\\/'"()[\];`%^&*\-_:!]+$
    • sinkType

      string required
      The type of the audit log sink.
      one of
      aws_s3
    • sinkData

      (multiple options: oneOf) required
      • {object}
        AWS S3 or compatible API audit-log sink configuration.
        • endpoint

          string required
          Endpoint for the AWS S3 or compatible API bucket.
        • region

          string required
          Region of the S3 bucket.
        • bucket

          string required
          Name of the S3 bucket.
        • pathPrefix

          string
          Optional path prefix inside the bucket where objects are written.
        • compression

          string required
          Compression method applied to exported audit log batches.
          one of
          gzip, none
        • auth

          {object} required
          Authentication object.
          • accessKeyId

            string required
            Access key id for the bucket.
          • secretAccessKey

            string required
            Secret access key for the bucket.
    • includeSpec

      boolean
      When true, exported events include the enriched `before` and `after` spec of the audited resource. Secrets are always stripped from specs before export. Set to false to export only event headers (action, actor, scope).

Response body

  • {object}
    Response object.
    • data

      {object} required
      Result data.
      • id

        string required
        The ID of the new audit log sink.
API
CLI
JS Client

POST /v1/integrations/audit-log-sinks

POST /v1/teams/{teamId}/integrations/audit-log-sinks

Example request

Request body
curl --header "Content-Type: application/json" \
  --header "Authorization: Bearer NORTHFLANK_API_TOKEN" \
  --request POST \
  --data '{"name":"compliance-bucket","description":"Forwards audit logs to the compliance S3 bucket.","sinkType":"aws_s3","sinkData":{"endpoint":"s3.amazonaws.com","region":"eu-west-2","bucket":"northflank-audit-logs","pathPrefix":"audit-logs/","compression":"gzip","auth":{"accessKeyId":"AKIAIOSFODNN7EXAMPLE","secretAccessKey":"wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY"}},"includeSpec":false}' \
  https://api.northflank.com/v1/integrations/audit-log-sinks

Example response

200 OK

Details about the created audit log sink.

JSON

{
  "data": {
    "id": "compliance-bucket"
  }
}

© 2026 Northflank Ltd. All rights reserved.

northflank.com / Terms / Privacy / feedback@northflank.com