SIEM Audit Log Streaming
Stream the Ours Privacy audit trail into your SIEM, including Splunk and Microsoft Sentinel, so sign-ins, permission changes, and data access are monitored alongside the rest of your security telemetry.
Ours Privacy keeps a full audit trail of activity in your account. We can stream it into the SIEM your security team already uses.
If you only need periodic review, the Audit Log may be enough — it's self-serve in the app.
Available on request. Streaming is configured by our team rather than in the app, and priced separately based on categories, volume, and destination. Contact your account representative to scope it.
What you can stream
The stream carries the same three categories the in-app Audit Log shows, together or on their own.
- Data Access. Each read or search of protected data, with the acting user, what they accessed, the filters applied, the outcome, and the originating IP address.
- Configuration. Creates, updates, and deletes across sources, destinations, allowed events, policies, permissions, and organization settings.
- Authentication. Sign-ins and failures, MFA challenges, password and 2FA changes, invitations, and membership changes.
Every entry carries a timestamp, the acting user, the affected resource, and the outcome. Unlike the in-app view, which is metadata-only, a stream can include the full before-and-after detail of a configuration change.
Note: We can backfill an initial window of history when the stream is set up, so onboarding later doesn't cost you history.
Supported SIEMs
Splunk and Microsoft Sentinel are supported out of the box. Running something else? Reach out to your account representative — most SIEMs and data pipelines can receive the stream.
How the stream works
No collector or agent required. Contact your account representative with the categories, SIEM, and any retention or region requirements — we'll take it from there.
Frequently asked questions
Do we need a SIEM to get audit logs at all?
No. The Audit Log is available in the app, and you can request a full export from that page. Streaming is additive.
Can we stream only authentication events?
Yes. The three categories are independent.
Does streaming send PHI to our SIEM?
The Data Access category records which records were accessed and by whom. Tell us what your security program allows and we'll scope the fields accordingly.
Can we send to more than one destination?
Yes.
Next Steps
- Audit Log: Review activity in the app and request a full export.
- Security Controls: Configure MFA, inactivity timeout, and data protection.
- Policies and Permissions: Set up the policies and PHI access that these logs record.
How is this guide?

