Update the audit logging storage integration
Modify the cloud storage location used for audit log exports for an organization. To update the storage provider or its credentials, you must delete and recreate the storage integration.
Usage notes
- To perform this operation, you must use API credentials owned by a user assigned the Admin account type.
- To read or update this setting for a tenant organization, use impersonation to obtain a token for that tenant, then call this endpoint with that token.
- Create, update, and delete requests may return before the storage integration is actually provisioned or removed. Call GET /v2/organizations/settings/storageIntegration/auditLogging afterward to confirm the change has taken effect.
Authentication
AuthorizationBearer
OAuth authentication of the form <token>.
Request
The request body.
allowedLocation
New cloud storage URI for the audit log exports.
updateScheduledExports
Whether to update export schedules to use the new storage location. If false, scheduled exports are paused.
Response
The storage integration settings after accepting the update request.
provider
Cloud storage provider for the audit log exports.
Allowed values:
allowedLocation
Cloud storage URI for the audit log exports.
storageAwsRoleArn
AWS IAM role ARN Sigma assumes to write to the destination bucket.
tenantId
Azure AD tenant ID that owns the destination storage account.

