The audit log and log streams both record events in your Zapier account, such as a member creating a Zap, turning a Zap off, or changing an app connection. Each event shows who did something, what they did, and when. The audit log lets you review these events in Zapier. Log streams send the same events to your own endpoint so you can review your logs in other tools.
Use this article to understand what each feature does and which one fits your needs. By the end, you will know how they differ and where to go to set each one up.
How the audit log and log streams work
The audit log and log streams share the same audit log events, such as Zaps created, app connections updated, variables changed, and members added to the account.
Each event has an event name and an event key. The event name is the readable name shown in Zapier, such as Zap created. The event key is a short code for the same event, such as zap.created. Zapier includes the event key in the event data, so your endpoint can tell which event it received.
The audit log displays these events in the Admin Center for you to review within Zapier. You can open an event to review its details and its full event data, and you can filter events to find what you need.
Log streams send each event as a JSON payload to a destination URL that you choose, at the moment the event occurs. This lets you review logs in another tool that you select. The payload is the same one that the audit log displays for an event. You can start a log stream from scratch or from a template. The template opens a draft Zap in the Zap editor, and you finish setting it up there.
Log streams also support Zap execution events, which report the outcome of a Zap run: success, error, or halted. These events are not in the audit log.
Log streams only capture events that occur after you create them.
When to use each feature
- Review who did what in your account: Use the audit log to review the full history of a Zap, or everything a specific member did.
- Investigate suspicious activity: Use the audit log to filter events by IP address and review everything performed from that address. If you suspect a member's account is compromised, filter by that member to review every IP address they used.
- Investigate a specific app version: Use the audit log to filter by app name and app version, such as a Gmail version you are concerned about, and review every event related to it.
- Alert your team when something changes: Use log streams to send events, such as a new app connection created, to a Zap that notifies your team in Slack.
- Track changes you need to follow up on: Use log streams to send a Slack message when someone submits a Zap for approval, or to create a Jira ticket when someone creates a Zap.
- Track Zap run outcomes: Use log streams to monitor Zap run success and failure rates, since Zap execution events are not in the audit log.
- Respond to Zap problems automatically: Use log streams to start a workflow when a Zap is halted, such as one that creates a support ticket.
- Build a long-term history: Use log streams to send events to your security information and event management (SIEM) or monitoring software.
Your team wants a Slack notification whenever someone creates a Zap. You can create a log stream that sends Zap creation events to a Zap with a webhook trigger. The Zap sends a message to a Slack channel each time, and the message includes the event payload. You can also add rules to the Zap, such as only sending the message when the new Zap uses a specific app.
When you need to investigate a notification, you can find the same event in the audit log and filter by the affected object ID to review everything that happened to that Zap.
Audit log versus log streams
Learn the differences between the audit log and log streams.
| Audit log | Log streams | |
|---|---|---|
| Where you use it | Audit log page in the Admin Center | Log streams page in the Admin Center |
| What it does | Displays events in Zapier so you can review and filter them | Sends events to your HTTPS endpoint as they occur |
| Events | Audit log events | Audit log events and Zap execution events |
| Plans | Team and Enterprise | Enterprise |
| Who can use it | Account owners on Team plans. Super admins and owners on Enterprise plans | Super admins and owners |
| History | Past 6 months on Team plans. Past 12 months on Enterprise plans | Starts when you create the log stream. Historical data is unavailable |