Skip to content
User Guide

Settings → System → Log Forwarding

Log Forwarding sends MisterShell’s audit events to your own logging or SIEM systems, so security and operations teams can correlate platform activity with the rest of their estate. You define one or more destinations; each destination receives the event streams you choose, at or above a severity you set.

Adding or changing a destination requires the Pro edition or higher. This includes enabling or disabling it and changing its connection details or credentials. Without Pro, existing destinations remain visible and can still be tested or deleted. Enabled destinations continue forwarding events, including after a restart, so a license change does not interrupt an established SIEM feed.

What you can do

  • Forward audit events to an external syslog collector or an HTTP webhook.
  • Choose which event streams each destination receives, including AI activity metadata.
  • Set a minimum severity so a destination only gets what matters to it.
  • Send a test event to confirm a destination is wired up correctly.
  • Enable or disable a destination without deleting it.

Fields

FieldMeaning
Start from a preset (optional)Pre-fills the form for common targets; everything remains editable afterwards.
NameA label for the destination.
TypeSyslog or Webhook.
StreamsWhich audit streams to forward: AI, Security, Policy, API, and App. Two more — Config and Health — are shown but marked coming soon and cannot be selected yet.
Min SeverityForward only events at or above this level: Info, Low, Medium, High, or Critical.
Verify TLS certificateThe destination form’s toggle starts off. Destinations created via the API without an explicit value verify by default. If your syslog or webhook destination presents a certificate signed by an internal certificate authority, load it into CA Certificates before turning this on.
EnabledWhether the destination is currently receiving events.

Syslog destinations additionally take a Host and Port, a Protocol (UDP, TCP, or TLS), a message Format (RFC 3164, RFC 5424, or CEF), and a syslog Facility.

Webhook destinations additionally take a URL, an HTTP Method (POST or PUT), a Body Format (Raw JSON, or Splunk HEC for sending straight to a Splunk HTTP Event Collector), a Timeout (s), an Authentication section (None, Bearer Token, Basic username/password, or a custom Header name/value), and optional Extra Headers added to every request.

Common tasks

Add a destination

  1. Click Add Destination.
  2. Choose the type, fill in the target, pick the streams, and set the minimum severity — or start from a preset and adjust.
  3. Save.

Test a destination

Click Test on a destination to send it a sample event. Confirm the event arrives in your collector before relying on the destination for production auditing.

Edit, disable, or delete

Use the per-row controls to edit a destination, toggle it off, or remove it. Editing and toggling require Pro; deleting remains available without Pro.

The AI stream forwards terminal activity metadata—actor, correlation IDs, origin, outcome, agent/model/tool names, and timing. It never forwards captured inputs, outputs, hashes, tool arguments/results, or credential material.

Permissions

  • View destinations: app.audit.read.
  • Add, edit, enable or disable destinations: app.audit.write, plus the Pro edition or higher.
  • Test a destination: app.audit.write.
  • Delete a destination: app.audit.delete.