Skip to main content

Logging & Monitoring

Witboost provides comprehensive, enterprise-grade logging and monitoring capabilities designed for security operations, compliance auditing, and operational excellence.

What Is Logged

All security-relevant events are captured:

CategoryEvents
AuthenticationUser logins, logouts, failed authentication attempts
AuthorizationPermission evaluations (allow/deny), role changes, group assignments
Data AccessMetadata access events — who accessed which catalog entries, when
AdministrativeConfiguration changes, policy modifications, template updates
DeploymentDeployment actions, approval workflows, governance policy evaluations
SystemSystem errors, component health, resource utilization

Log Integrity

Witboost emits logs and audit records that customers can collect, retain, and protect through their own logging infrastructure:

  • Customer-controlled storage — Logs can be stored in the customer's chosen logging platform
  • Protected infrastructure — Customers can enforce access control, retention, and immutability policies in their log archive
  • Regular review — Logging configuration and retention can be reviewed as part of the customer's operational controls

SIEM Integration

Platform logs can be integrated with the customer's Security Information and Event Management (SIEM) system:

  • Standard log format (Syslog)
  • Real-time log streaming support
  • Compatible with common SIEM platforms (Splunk, Elastic, Azure Sentinel, etc.)
  • Centralised alerting and correlation

Audit Trail

Every audited action in Witboost generates an audit record containing:

  • Who — Authenticated user identity (from the customer's IdP)
  • What — The specific action performed
  • When — Timestamp with timezone
  • Where — Source IP / session identifier
  • Result — Success or failure, with reason codes for denials
note

Logs contain user identifiers (usernames or user IDs from the identity provider) for audit traceability. Logs do not contain personal data content from the data plane, since Witboost does not process consumer data.


Identifiers in Logs

If the customer's identity provider uses email addresses as user IDs, those will appear in audit logs. This is necessary for:

  • Accountability and non-repudiation
  • Incident investigation
  • Compliance with access logging requirements (e.g., GDPR Article 5(2))

The customer controls what identifier format is used by configuring their identity provider.


Log Retention

In on-premises deployments, the customer has full control over:

  • Log retention periods
  • Log storage location
  • Log archival and rotation policies
  • Log access permissions

Agile Lab can provide guidance and best practices for log management configuration.