Audit Log Streaming
| action | Description | Sample | Rule |
|---|---|---|---|
| audit_ | A manual check of the endpoint configured for audit log streaming was performed. | N | N |
| audit_ | An endpoint was added for audit log streaming. | N | N |
| audit_ | An audit log streaming endpoint was deleted. | N | Y |
| audit_ | An endpoint configuration was updated for audit log streaming, such as the stream was paused, enabled, or disabled. | N | Y |
audit_log_streaming.check
#Description
A manual check of the endpoint configured for audit log streaming was performed.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
audit_log_streaming.create
#Description
An endpoint was added for audit log streaming.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages.
audit_log_streaming.destroy
#Description
An audit log streaming endpoint was deleted.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Splunk #
T1195, T1685, T1685.002YARA-L #
T1562
audit_log_streaming.update
#Description
An endpoint configuration was updated for audit log streaming, such as the stream was paused, enabled, or disabled.
Documented only in GitHub's enterprise audit log reference, not the organization or user audit log pages. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Splunk #
T1195, T1685, T1685.002T1195, T1685, T1685.002YARA-L #
T1562