> ## Documentation Index
> Fetch the complete documentation index at: https://docs.replit.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Audit Logs

> Track and monitor security-relevant actions in your Replit Enterprise organization with comprehensive audit logs and SIEM integration.

## Introduction

<Note>
  Audit logs are available exclusively for Enterprise customers. Account admins can enable them in Settings.
</Note>

Audit logs provide a detailed record of security-relevant actions within your Replit organization. They allow you to track who did what, when, and where — giving your security and compliance teams the visibility they need to monitor and investigate activity.

Replit's audit log system is powered by [WorkOS](https://workos.com/), ensuring enterprise-grade reliability and security for log storage, retrieval, and streaming.

## Key Features

<CardGroup cols={2}>
  <Card icon="list-check">
    Review audit events across your organization, with 65+ additional events introduced in Audit Logs V2.
  </Card>

  <Card title="Audit Log Portal" icon="magnifying-glass">
    View, filter, and bulk-export audit events.
  </Card>

  <Card title="SIEM Integration" icon="arrow-right-arrow-left">
    Stream events to Datadog, Splunk, Amazon S3, or a generic HTTP endpoint.
  </Card>

  <Card title="Admin-Only Access" icon="shield">
    Only account admins can view audit logs and configure streaming, keeping your security data protected.
  </Card>
</CardGroup>

## Getting Started

<Steps>
  <Step title="Enable Audit Logs">
    Navigate to **Settings** > **Advanced** > **Audit Logs** and select **Enable audit logs**. You must be an [account admin](/teams/identity-and-access-management/account-and-workspace-admins) to enable this feature.
  </Step>

  <Step title="View Audit Logs">
    Once enabled, select **View audit logs** to open the audit log portal
  </Step>

  <Step title="Set Up SIEM Integration (Optional)">
    Select **Set up SIEM integration** to configure real-time log streaming to your security tools
  </Step>
</Steps>

## Tracked Events

Audit Logs V2 adds 65+ events, expanding coverage across your organization. Tracked event categories include:

* Deployments
* Access and identity
* Workspace administration
* Project activity
* Secrets
* Connectors
* Domains
* Agent activity

The [public audit log schema catalog](https://replit.com/security/audit-logs) lists approved event contracts, including action versions, targets, and metadata schemas.

## Viewing Audit Logs

To view your organization's audit logs:

1. Go to **Settings** > **Advanced**
2. In the **Audit Logs** section, select **View audit logs**
3. The audit log portal opens, where you can view, filter, and bulk-export events

The portal provides:

* **Search** — Find specific events by keyword
* **Filters** — Narrow results by event type, date range, actor, or target
* **Bulk export** — Download log data for offline analysis or compliance reporting

## Retrieve Prompt Text with the Compliance API

Enterprise [account admins](/teams/identity-and-access-management/account-and-workspace-admins) can use the Compliance API to retrieve the full prompt text for `project.message_sent` audit events. Use it to enrich security investigations, compliance monitoring, data loss prevention (DLP), SIEM, retention, and eDiscovery workflows.

Create an [API key](/teams/admin-api#create-an-api-key) with the `compliance:messages:read` scope, then call `GET /v1/compliance/messages`.

<Warning>
  Prompt text can contain secrets, personal data, and other sensitive content. Grant the `compliance:messages:read` scope only to authorized systems and administrators.
</Warning>

For request parameters, responses, and examples, see the [Replit API developer documentation](https://api.replit.com/docs).

## SIEM Integration

SIEM (Security Information and Event Management) integration allows you to stream audit log events in real time to your existing security tools. This is useful for:

* Centralizing security monitoring across all your enterprise tools
* Setting up automated alerts based on audit log patterns
* Meeting compliance requirements for log retention and analysis

### Setting Up Log Streaming

1. Go to **Settings** > **Advanced**
2. In the **Audit Logs** section, select **Set up SIEM integration**
3. The log streaming configuration portal opens
4. Follow the instructions to connect your SIEM provider

Replit supports any destination compatible with WorkOS Log Streams, including:

* **Datadog**
* **Splunk**
* **Amazon S3**
* **Generic HTTP endpoint (webhook)**

<Note>
  Log streaming is configured through the WorkOS portal. Changes to your streaming configuration take effect immediately.
</Note>

## FAQs

### Who can view audit logs?

Only [account admins](/teams/identity-and-access-management/account-and-workspace-admins) can access audit logs and configure SIEM integration. Non-admin members do not have access to any audit log data.

### Do I need SCIM enabled to use audit logs?

No. SCIM is not required to use audit logs. SCIM and audit logs share your account's WorkOS organization, but you must enable each feature separately. When audit logs are enabled, they can include SCIM provisioning and deprovisioning events.

### What happens if an audit log event fails to record?

Audit log recording is designed to never interfere with the underlying operation. If an event fails to be recorded, the original action (such as user provisioning) still completes successfully. Failed events are logged internally for investigation.

### How long are audit logs retained?

Replit retains audit logs for 30 days by default. To keep events longer, set up [SIEM integration](#siem-integration) and stream them to your own storage. For longer in-portal retention, [contact Replit Support](https://replit.com/support).

### Can I export audit logs?

Yes. You can bulk-export audit log data from the audit log portal. You can also stream events to a supported destination.

## Related Resources

<CardGroup cols={2}>
  <Card title="Workspace Settings" icon="sliders" href="/features/collaboration/workspace-settings">
    Set Enterprise policy for the Agent models and model providers each Workspace can use.
  </Card>

  <Card title="SCIM" icon="key" href="/teams/identity-and-access-management/scim">
    Set up automated user provisioning with SCIM integration
  </Card>

  <Card title="SAML SSO" icon="lock" href="/teams/identity-and-access-management/saml">
    Configure single sign-on authentication for your organization
  </Card>

  <Card title="Groups & Permissions" icon="shield" href="/teams/identity-and-access-management/groups-and-permissions">
    Manage user roles and access controls
  </Card>

  <Card title="Privacy and deployment settings" icon="eye-slash" href="/teams/privacy-and-deployment-settings">
    Configure organization-wide publishing privacy and deployment settings
  </Card>

  <Card title="Admin API" icon="code" href="/teams/admin-api">
    Create API keys and access account data programmatically
  </Card>
</CardGroup>
