There are several ways to access and retain audit log data for your enterprise:
- Web interface: View recent activity in your enterprise settings. See Viewing the enterprise's audit log via the web interface.
- JSON/CSV exports: Download a file of audit log activity. See Exporting audit log activity for your enterprise.
- REST API endpoint: Query audit log events programmatically. See Using the audit log API for your enterprise.
- Streaming to an external system: Deliver events continuously to a system that your incident responders can access and query. See Streaming the audit log for your enterprise.
Each method exposes a different subset of your audit log data. For the full list of events, see Audit log events for your enterprise.
Audit log data available by access method
| Data available | Web interface | JSON/CSV exports | REST API endpoint | Streaming to an external system |
|---|---|---|---|---|
| Range of web events | 180 days | 180 days | 180 days | Determined by the retention policy of your external system |
| API request events | (If enabled) | |||
| Git events | (JSON only). The audit log retains Git events for seven days. | . The audit log retains Git events for seven days. | ||
| Single sign-on responses (organization and enterprise) | ||||
| Created and completed workflow runs | ||||
| Started workflow jobs, including the secrets provided to each job | ||||
| Online and offline self-hosted runners |
For enterprises that use Enterprise Managed Users, the enterprise audit log also includes user events. For a list of these user events, see Security log events.
To retain Git events beyond their availability in the audit log, save them to external storage before they expire. Configure audit log streaming in advance to collect events continuously.
Git event exports do not include events initiated through the web interface or the REST or GraphQL APIs. For example, when someone merges a pull request in the web interface, the resulting push to the base branch is missing from the export.
api.request events are available only in streamed enterprise audit logs, and only when the option to stream API request events has been enabled. For more information, see Streaming the audit log for your enterprise.
중요
Audit log streaming only includes activity from the time you enable it. Enabling it during an incident will not recover earlier activity.
Preparing for an incident response
Enable enterprise audit log streaming, API request event streaming, and source IP address disclosure to prepare for incident response. Without all three features enabled, responders will have critical visibility gaps when investigating incidents affecting your enterprise or its organizations. Set an appropriate retention period for the streamed logs and ensure incident responders can access them.
For setup instructions, see Streaming the audit log for your enterprise, Enabling audit log streaming of API requests, and Displaying IP addresses in the audit log for your enterprise.
During a security incident, GitHub Support can answer questions about features and available data, but does not investigate on your behalf or preserve logs for your investigation. For more information, see Understanding how GitHub Support can help during a security incident.
Viewing the enterprise's audit log via the web interface
The audit log lists events triggered by activities that affect your enterprise within the last 180 days. The audit log retains Git events for seven days.
By default, only events from the past three months are displayed. To view older events, you must specify a date range with the created parameter. See Understanding the search syntax.
- Navigate to your enterprise. For example, from the Enterprises page on GitHub.com.
- At the top of the page, click Settings.
- Under "Settings", click Audit log.