Skip to main content
PATCH
Update an audit log export destination

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Path Parameters

id
string
required
Maximum string length: 128

Body

application/json
bucket
string
Required string length: 3 - 63
kms_key_id
string

KMS key ID, alias, or ARN. Set to an empty string to remove the configured KMS key; omit or send null to leave unchanged.

Maximum string length: 2048
prefix
string
Maximum string length: 512
region
string
Required string length: 1 - 128
role_arn
string
Required string length: 1 - 2048
status
enum<string>
Available options:
active,
paused

Response

Audit log export destination updated

An organization-scoped audit log export destination.

Delivery is at-least-once for rows visible when their window is committed: a delivery that is retried rewrites the same object, and the same event_id can appear in more than one object, so consumers must deduplicate on event_id. Each event-time window is held for ten minutes before it commits; a row that becomes visible after its window is committed may not be delivered.

Objects are written as <prefix>/destination_id=<destination>/org_id=<org>/date=<YYYY-MM-DD>/hour=<HH>/<window>-<chunk>.jsonl.gz, where date and hour are the UTC calendar hour that fully contains every row in the object, so the layout is safe to register as a Hive-partitioned table. The object name is derived from the rows it holds, so a retried delivery rewrites its own object.

bucket
string
required
Required string length: 3 - 63
consecutive_failures
integer
required
read-only
Required range: x >= 0
created_at
string<date-time>
required
read-only
external_id
string
required
read-only
Maximum string length: 128
format
enum<string>
required
Available options:
jsonl.gz
id
string
required
read-only
Maximum string length: 128
kernel_role_arn
string
required
read-only

The Kernel role that assumes role_arn in your account to deliver logs. Allow this role as the principal in your role's trust policy, and require external_id as the sts:ExternalId condition.

Recreating a destination issues a new external_id, which the trust policy has to be updated to match.

Maximum string length: 2048
prefix
string
required
Maximum string length: 512
region
string
required
Required string length: 1 - 128
role_arn
string
required
Required string length: 1 - 2048
status
enum<string>
required

Pausing prevents new delivery attempts. An S3 upload already in progress may complete after the pause response; its rows can appear again after the destination is resumed.

Available options:
active,
paused
type
enum<string>
required
Available options:
s3
updated_at
string<date-time>
required
read-only
kms_key_id
string
Maximum string length: 2048
last_error
string
read-only

Sanitized description of the most recent delivery failure.

last_error_at
string<date-time>
read-only
last_exported_cursor
string
read-only

Opaque, versioned checkpoint for forward-only continuous export. This value is not compatible with audit-log list page tokens.

Delivery starts at the moment the destination is activated, so events recorded before that are not delivered. Pausing stops delivery and resuming starts again from the time of the resume: events recorded while a destination was paused are never exported, and pausing is not a way to defer delivery.

last_success_at
string<date-time>
read-only
next_attempt_at
string<date-time>
read-only