Stream audit logs to your SIEM

Last updated: October 5, 2026

Note: Available on the Enterprise plan only, in the Admin Portal at admin.wisprflow.ai. Wispr must enable streaming for your organization before you can configure it — contact your Wispr account team or support to request it. Once enabled, an Audit log streaming section appears on the Audit Logs page.

Stream Wispr Flow's admin audit log to your own SIEM or log destination, so audit events land in the tools your security team already monitors instead of relying on manual CSV or JSON exports.

Streaming is delivered through WorkOS, our audit log partner.


Set up streaming

  1. Sign in to the Admin Portal at admin.wisprflow.ai as an admin.

  2. Go to Audit Logs.

  3. Click Configure streaming in the Audit log streaming section.

  4. Choose your destination on the setup page hosted by our partner, WorkOS, and follow its connection steps.

  5. Return to the Admin Portal and choose a retention period: 30 days or 365 days.

To change the destination later, use Manage streaming in the same section.


Supported destinations

  • Splunk

  • Datadog

  • Microsoft Sentinel

  • Snowflake

  • Google Cloud Storage

  • Amazon S3, using your own bucket connected through a cross-account IAM role

  • Generic HTTPS webhook

Syslog is not supported. You can connect one streaming destination per organization.


What is streamed

Streaming carries the same events as the audit log export on the Audit Logs page, each with a unique event ID, a UTC timestamp, the action, and the actor and target:

  • Members added and removed, including individual removals made through SCIM

  • Join requests approved or rejected

  • Meeting Notetaker consent confirmations

  • Organization setting changes, recorded with the previous and new value: data controls such as Context Awareness, model improvement and data storage; Notetaker policy; sharing policy; access restrictions such as SSO enforcement and IP allowlist; product access; and membership policy

  • Access to shared meeting notes and transcripts

Not recorded yet: admin sign-ins, admin role changes, SSO and SCIM connection configuration, and users added through SCIM.

Note: The audit log never contains dictation content, audio or transcripts. Audit log data is hosted in the United States.

Events stream from the point streaming is set up. Earlier activity is not sent, so use the export on the Audit Logs page for history.


Still stuck?

I don't see the Audit log streaming section

Your organization is either not on the Enterprise plan, or streaming hasn't been enabled yet. Contact your Wispr account team.

"Couldn't load audit log streaming status"

Refresh the page. If the message persists, contact support with your organization name and the destination you were connecting.