Skip to main content
Sessionboard keeps three logs for your organization. Your SIEM pulls them on a schedule with a dedicated API token, one stream at a time, using a cursor so that no event is missed or fetched twice.
Security events cover your organization’s current members. Activity by Sessionboard staff — for example a support engineer signing in to help you — is not part of this export.

1. Create a log export token

An administrator who can manage users creates the token in Organization Settings → API Tokens → Create Token and checks Audit log export (read:audit_logs). A log export token is separate from your integration tokens:
  • It holds read:audit_logs and nothing else, so it can read logs but cannot read or change events, sessions or contacts. Any other endpoint answers 403.
  • It always covers the whole organization. Event restrictions don’t apply to it.
  • It must be an API token sent as x-access-token. OAuth (Bearer) tokens are refused.
Store the token in your SIEM’s secret store. Use the host for your region: https://public-api.sessionboard.com (US) or https://public-api-eu.sessionboard.com (EU).

2. Pull a page

Every stream returns events in this same shape, so one field mapping in your SIEM covers all three.

3. Keep pulling with the cursor

The first call starts at since (24 hours ago if you leave it out). After that, send back the next_cursor you got and nothing else changes:
  1. Call with cursor=<next_cursor> and the same filters as before. A cursor remembers its filters; changing them returns 400 CURSOR_FILTER_MISMATCH.
  2. Save next_cursor only after your SIEM has stored the page.
  3. If has_more is true, call again straight away. If it is false, you’re caught up — wait for your next poll.
An empty page returns the cursor you sent, so a caught-up poller simply keeps it. Events become visible about a minute after they happen. Pages are ordered by when Sessionboard recorded each event, not when it happened, so an event that is recorded late still lands after your cursor instead of being skipped. Use id to de-duplicate if you ever replay a page.

Filters

Failed authentication shows up in api-requests with outcome: "failure" and a reason of missing_token, invalid_token, revoked_token, expired_token, org_archived, member_inactive, ai_disabled, log_export_only or cross_org_event. A request with a key that was never valid can’t be tied to an organization, so it doesn’t appear in your export. A key you revoked does.

Splunk

Run a scripted input per stream. The script keeps its cursor in a file next to it and prints one JSON event per line.
sessionboard_logs.py
inputs.conf
props.conf
Add one [script://…] stanza per stream you want. Timestamps are ISO 8601 in UTC; security events carry microseconds, the other streams milliseconds, and Splunk’s automatic ISO 8601 recognition reads both.

Microsoft Sentinel

Run the same cursor loop as the Splunk script on a timer — an Azure Function every five minutes works well — and send each page to a custom table through the Logs Ingestion API. Keep next_cursor in durable storage (a blob or table entity) and map occurred_at to TimeGenerated in the data collection rule.
Sentinel’s codeless REST poller queries fixed time windows and doesn’t carry a cursor from one poll to the next. Because events become visible about a minute after they happen, a window that ends at “now” misses the events of its last minute. Use the cursor loop instead.

Elastic

Use the Elastic Agent Custom API (CEL) input, polling every few minutes. Keep next_cursor in the input’s cursor state, emit each item of data as an event, and set want_more to has_more. Map occurred_at to @timestamp.