Create the audit logging storage integration
Configure the cloud storage destination to use for audit log exports for an organization.
Usage notes
- To perform this operation, you must use API credentials owned by a user assigned the Admin account type.
- To read or update this setting for a tenant organization, use impersonation to obtain a token for that tenant, then call this endpoint with that token.
- Create, update, and delete requests may return before the storage integration is actually provisioned or removed. Call GET /v2/organizations/settings/storageIntegration/auditLogging afterward to confirm the change has taken effect.
Authentication
AuthorizationBearer
OAuth authentication of the form <token>.
Request
The request body.
AWS audit logging storage integration.
OR
Azure audit logging storage integration.
OR
GCP audit logging storage integration.
Response
The storage integration settings after accepting the create request.
provider
Cloud storage provider for the audit log exports.
Allowed values:
allowedLocation
Cloud storage URI for the audit log exports.
storageAwsRoleArn
AWS IAM role ARN Sigma assumes to write to the destination bucket.
tenantId
Azure AD tenant ID that owns the destination storage account.

