Audit Logging
Immutable audit trails for every action, exportable to your SIEM
Every action. Forever. Cryptographically verifiable.
Who did what, when, from where — captured at the source, stored immutably, streamed to your SIEM in real time. Compliance-ready retention, tamper-evident integrity, and a query interface that won't time out on a year of data.
Overview
VxCloud captures every user action, API call, system event, and administrative change in a structured audit log. Records include the actor, action, target resource, source IP, user agent, result, and cryptographic hash chained to previous records for tamper detection. Storage is append-only in write-once-read-many (WORM) object storage with configurable retention up to 7 years.
Real-time streaming exports audit events to your SIEM of choice — Splunk, Elastic, Chronicle, Sentinel, or any syslog-compatible collector — with field mappings pre-configured for major SIEM schemas. Compliance frameworks supported include SOC 2 CC7, ISO 27001 A.12.4, HIPAA §164.312(b), PCI DSS Requirement 10, and FedRAMP AU family controls. Query the log directly from the platform UI, via API, or in your SIEM.
What's included
Production-grade capabilities, ready to enable in your workspace.
Immutable storage
Append-only WORM storage with hash-chained records. Deletes and modifications are architecturally impossible.
Real-time SIEM export
Streaming export to Splunk HEC, Elastic, Chronicle, Sentinel, Datadog, Sumo Logic, or syslog endpoints.
Configurable retention
Retention policies from 30 days to 7 years per event category. Regulatory-aligned defaults for common frameworks.
Cryptographic integrity
SHA-256 hash chain across records. Independent integrity verification at any time via our verification tool.
Rich event context
Actor, action, resource, before/after values, source IP, user agent, request ID, session ID — not just "user did a thing."
Query interface
Fast time-range queries with filters, saved searches, and scheduled reports. No Athena-sized wait times.
Business outcomes
Measurable impact teams see when they adopt audit logging.
Action coverage
Every user action, API call, and administrative event is logged. No silent background changes.
SIEM ingest latency
Events reach your SIEM within seconds, supporting near-real-time alerting and incident response.
Maximum retention
Long enough for every US and EU financial, healthcare, and privacy retention requirement.
Hash-chain integrity
Any modification to historical records breaks the hash chain and is detected at verification time.
How customers use it
Real scenarios from VxCloud customers across regulated industries and fast-moving teams.
Bank subject to SEC and FINRA recordkeeping requirements
7-year retention with WORM storage and hash-chain integrity satisfies SEC 17a-4(f) and FINRA recordkeeping requirements.
Hospital tracking PHI access for HIPAA audits
Every PHI access is logged with actor, patient record, and reason. Quarterly HIPAA access reviews completed via automated reports.
Fortune 500 running unified threat detection
Real-time streaming to Splunk feeds existing SOC playbooks. VxCloud events correlate with endpoint and network data.
Federal agency under FedRAMP AU family controls
Audit event types, retention, and protection align to AU-2, AU-3, AU-9, AU-11, AU-12. ConMon package includes audit-log evidence.
Frequently asked questions
Still have questions? Our enterprise team answers within one business day.
No. Audit logs are stored in append-only WORM storage. The hash chain makes any attempted modification cryptographically detectable. Not even VxCloud administrators can delete historical records.
Related enterprise capabilities
Ready to move forward with Audit Logging?
Talk to our enterprise team — we'll scope your requirements, map the right capabilities, and build a rollout plan tailored to your organization.