heroku / heroku/roadmap

Heroku Trails audit logs

Open
#10 8 comments 21 reactions 0 assignees View on GitHub
Security
Dominant language
No language data
Stars
225
Forks
19
PR merge metrics
No merged PRs in 30d

Description

There is a need to automate the flow of customers' Heroku platform audit logs to their log repository or security monitoring tools. Today, these audit logs are served through our [Audit Trails](https://devcenter.heroku.com/articles/audit-trail) feature available for export in JSON format.

We are exploring the potential benefits for our customers to automate the flow of audit logs served through Audit Trails.

### Sensitive areas

* `heroku run` and `ps exec` (because that's accessing production data, potentially)

**Reference**
_[Audit Trails for Enterprise Accounts](https://devcenter.heroku.com/articles/audit-trail)_

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with the linked Audit Trails for Enterprise Accounts reference and clarify the target log repositories, security monitoring integrations, and scope for sensitive commands. Done requires an agreed automation path with defined export and delivery requirements.

Written by the indexing model from the issue text.

Assessment

Tech stack
json
Domain
observability, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.