Security events cover your organization’s current members. Activity by Sessionboard staff — for example a support engineer signing in to help you — is not part of this export.
1. Create a log export token
An administrator who can manage users creates the token in Organization Settings → API Tokens → Create Token and checks Audit log export (read:audit_logs).
A log export token is separate from your integration tokens:
- It holds
read:audit_logsand nothing else, so it can read logs but cannot read or change events, sessions or contacts. Any other endpoint answers403. - It always covers the whole organization. Event restrictions don’t apply to it.
- It must be an API token sent as
x-access-token. OAuth (Bearer) tokens are refused.
https://public-api.sessionboard.com (US) or https://public-api-eu.sessionboard.com (EU).
2. Pull a page
3. Keep pulling with the cursor
The first call starts atsince (24 hours ago if you leave it out). After that, send back the next_cursor you got and nothing else changes:
- Call with
cursor=<next_cursor>and the same filters as before. A cursor remembers its filters; changing them returns400 CURSOR_FILTER_MISMATCH. - Save
next_cursoronly after your SIEM has stored the page. - If
has_moreistrue, call again straight away. If it isfalse, you’re caught up — wait for your next poll.
id to de-duplicate if you ever replay a page.
Filters
Failed authentication shows up in
api-requests with outcome: "failure" and a reason of missing_token, invalid_token, revoked_token, expired_token, org_archived, member_inactive, ai_disabled, log_export_only or cross_org_event. A request with a key that was never valid can’t be tied to an organization, so it doesn’t appear in your export. A key you revoked does.
Splunk
Run a scripted input per stream. The script keeps its cursor in a file next to it and prints one JSON event per line.sessionboard_logs.py
inputs.conf
props.conf
[script://…] stanza per stream you want. Timestamps are ISO 8601 in UTC; security events carry microseconds, the other streams milliseconds, and Splunk’s automatic ISO 8601 recognition reads both.
Microsoft Sentinel
Run the same cursor loop as the Splunk script on a timer — an Azure Function every five minutes works well — and send each page to a custom table through the Logs Ingestion API. Keepnext_cursor in durable storage (a blob or table entity) and map occurred_at to TimeGenerated in the data collection rule.
Elastic
Use the Elastic Agent Custom API (CEL) input, polling every few minutes. Keepnext_cursor in the input’s cursor state, emit each item of data as an event, and set want_more to has_more. Map occurred_at to @timestamp.
