enabled: true, audit events begin streaming immediately. Requires the Enterprise tier.
Parameters
SIEM provider type. One of
splunk, datadog, cloudwatch, elastic, or webhook.HTTPS URL of the destination. For Splunk, use the HEC endpoint. For Datadog, use the log intake URL. For CloudWatch, use the regional Logs endpoint.
Authentication token for Splunk, Datadog, or Elastic destinations.
AWS access key ID. Required when
provider is cloudwatch.AWS secret access key. Required when
provider is cloudwatch.Shared secret for HMAC signature verification. Required when
provider is webhook.Whether to start streaming immediately. Defaults to
true.