Understand STACKIT Audit Log
Last updated on
The STACKIT Audit Log is a centralized service that records administrative and access events across your cloud products. Use these logs for compliance and security monitoring to track infrastructure changes.
The system records every action taken by users, service accounts, or the STACKIT platform. This helps you answer these key questions:
- What happened? (Event name)
- When did it happen? (Timestamp)
- Who started it? (Initiator)
- Where did it occur? (Target organization or project)
Service coverage
Section titled “Service coverage”Most managed services in STACKIT generate audit events when a user or system modifies a resource.
| Category | Specific products or services | Examples of logged events |
|---|---|---|
| Compute & Runtime | STACKIT Kubernetes Engine (SKE), Compute Engine | Creating or deleting clusters, scaling VM instances, or changing firewall rules. |
| Databases | PostgreSQL Flex, MongoDB Flex, MariaDB, SQLServer Flex, Redis | Creating database instances, manual backups, or changing access credentials. |
| Security & Identity | STACKIT IAM, KMS, Secrets Manager | Role assignments (RBAC), rotating keys, or creating service accounts. |
| Storage | Object Storage, Block Storage | Creating buckets, changing access permissions (ACLs), or deleting volumes. |
| Network | Load Balancer, DNS | Creating listeners, updating DNS records, or modifying ingress rules. |
| Management | Resource Manager, Billing | Creating or deleting projects, and changing billing account details. |
Core platform events
Section titled “Core platform events”The STACKIT Audit Log captures events from the following STACKIT platform services:
- Membership service: Track when you add, remove, or update memberships at the organization, folder, and project levels.
- Resource Manager: Monitor the creation, deletion, or update of organizations, folders, and projects.
- Service Account service: View events for creating or deleting service accounts, as well as creating or revoking access tokens.
Key features
Section titled “Key features”- Default visibility: Admin activities are recorded by default. You do not need to set this up manually. You can view your history for 90 days via the STACKIT Portal. Via Telemetry Router you are able to route your audit logs to external destinations.
- Complete history: The log collects activities from both human users and automated system tasks within the STACKIT platform, leaving no change undocumented.
Benefits and use cases
Section titled “Benefits and use cases”- Support governance and compliance: Meet regulatory requirements by keeping security-relevant audit trails that document your sequence of actions for auditors.
- Improve traceability: Trace changes to identify who performed an action and when. This provides transparency and accountability for your entire team.
- Resolve problems: Troubleshoot system issues more effectively by tracking the historical progression of events to find a root cause.
- Optimize performance: Use log insights to identify bottlenecks or inefficient manual processes that you could automate.