Activity Logs Token
Any user can generate a long-lived Activity Logs token in Settings → Tokens. This token provides read-only access to the activity logs that user can already access, plus the organizational metadata required to retrieve them. For a SIEM integration, we recommend creating a dedicated user and adding them to the Activity Log Viewer Role, which grants read-only access to all activity across your organization.
Supported Providers
Get started by following the setup guide for your provider:- Hosted Elasticsearch (Elastic Cloud) — via the Custom API integration (HTTPJSON input)
- Sumo Logic — via a self-hosted forwarding container

