Audit Log Streaming

actionDescriptionSampleRule
audit_log_streaming.checkA manual check of the endpoint configured for audit log streaming was performed.NN
audit_log_streaming.createAn endpoint was added for audit log streaming.NN
audit_log_streaming.destroyAn audit log streaming endpoint was deleted.NY
audit_log_streaming.updateAn endpoint configuration was updated for audit log streaming, such as the stream was paused, enabled, or disabled.NY

audit_log_streaming.check

#
Category
audit-log-streaming

Description

A manual check of the endpoint configured for audit log streaming was performed.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

audit_log_streaming.create

#
Category
audit-log-streaming

Description

An endpoint was added for audit log streaming.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

audit_log_streaming.destroy

#
Category
audit-log-streaming

Description

An audit log streaming endpoint was deleted.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

YARA-L #

audit_log_streaming.update

#
Category
audit-log-streaming

Description

An endpoint configuration was updated for audit log streaming, such as the stream was paused, enabled, or disabled.

Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

YARA-L #