Skip to content

Audit logging: immutable trail with SIEM export #350

@mikemcdougall

Description

@mikemcdougall

Context

Compliance teams require immutable audit trails. Esri's audit capabilities are limited and expensive.

Scope

  • Immutable append-only audit log: who queried/edited what, when, from where
  • Structured events: user, action, resource, timestamp, source IP, result
  • SIEM export: Splunk, Datadog, Elastic (webhook or log forwarding)
  • Retention policies: configurable retention period, archival to object storage
  • Admin UI: audit log viewer with filtering and search
  • No performance impact on ungated Community endpoints

References

  • ADR-0024: Enterprise tier feature (Audit Logging pillar)
  • ADR-0020: Previously deferred as MVP operational deferral

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/serverCore server (protocols, query, edits)edition/enterpriseEnterprise edition featureeffort/L🌳 L: 1-2 days (complex feature, multiple components)enhancementNew feature or requestphase/BetaBeta scopepriority/P3📋 Low priority - nice to have in phase, can be deferred

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions