Audit Logs for WarpStream: Full Visibility Into Every Action on Your Clusters
Blog post from WarpStream
WarpStream has introduced Audit Logs to provide a comprehensive and structured record of all authentication actions, authorization decisions, and platform operations across Kafka clusters, addressing the challenges of limited built-in auditing in Kafka. This feature is crucial for compliance and enhances incident response and root-cause analysis by offering a centralized view of operations, with logs that are structured, queryable, and compatible with existing tools. Audit Logs capture two categories of events: Cluster Audit Logs for Kafka-level operations and Platform Audit Logs for account-level operations, following the CloudEvents spec for seamless integration. These logs are produced into a fully-managed WarpStream cluster, allowing consumption via the Kafka protocol and integration with various systems like SIEMs or data lakes, enhancing both audit trail visibility and flexibility. Each log event is a structured JSON payload detailing the action, actor, timing, and result, with all metadata retained without egressing data from WarpStream clusters. The pricing model is based on data written, storage, and network usage, with most use cases remaining cost-effective. Audit Logs are now available for all WarpStream Pro or Enterprise accounts, requiring minimal setup and offering immediate data flow upon activation.