Skip to main content

Overview

Formal can forward all activity logs to your SIEM, data lake, or observability platform. This enables centralized log management, long-term retention, compliance reporting, and integration with your existing security tools.

Supported Platforms

  • AWS S3
  • Google Cloud Storage (GCS)
  • Azure Blob Storage
  • Datadog
  • Splunk
  • Panther
By default, Formal forwards all logs to your configured destination, including Insights findings.

Setup

AWS S3

The AWS S3 log integration requires an AWS Cloud Integration with S3 access enabled.
1

Set Up AWS Integration

First, configure an AWS Cloud Integration with:
  • AllowS3Access: true
  • S3BucketARN: Your S3 bucket ARN
2

Navigate to SIEM

Go to SIEM
3

Create Integration

Click Create Integration
4

Select AWS S3

Choose AWS S3 as your provider
5

Configure

  • S3 Bucket Name: Your bucket name
  • Cloud Integration: Select your AWS Cloud Integration
  • Compression: the codec log objects are written with (see Compression)

Terraform

Google Cloud Storage

The GCS log integration requires a GCP Cloud Account with Cloud Storage access enabled.
1

Set Up GCP Integration

First, configure a GCP Cloud Account with:
  • allow_gcs_access: true
  • gcs_buckets: the buckets Formal may write to (empty allows every bucket in the project)
2

Navigate to SIEM

Go to SIEM
3

Create Integration

Click Create Integration
4

Select Google Cloud Storage

Choose Google Cloud Storage as your provider
5

Configure

  • GCS Bucket Name: your bucket name
  • Cloud Account: select your GCP Cloud Account
  • Compression: the codec log objects are written with (see Compression)

Terraform

Creating the GCP Cloud Account also requires the terraform-formal-gcp module and an activation resource. See the GCP Integration guide for the full setup.

Azure Blob Storage

The Blob Storage log integration requires an Azure Cloud Account with Blob Storage access enabled.
1

Set Up Azure Integration

First, configure an Azure Cloud Account with:
  • allow_blob_access: true
  • blob_storage_accounts: the storage accounts Formal may write to (empty allows every account in scope)
2

Navigate to SIEM

Go to SIEM
3

Create Integration

Click Create Integration
4

Select Azure Blob Storage

Choose Azure Blob Storage as your provider
5

Configure

  • Storage Account: the account to write to. Accounts named on the Cloud Account are offered as a list.
  • Container: the container within that account
  • Cloud Account: select your Azure Cloud Account
  • Compression: the codec log objects are written with (see Compression)
The Terraform provider does not yet support Blob Storage log integrations. Create them from the Control Plane or the API.

Datadog

1

Get Datadog Credentials

From your Datadog account, retrieve:
  • Application Key
  • API Key
  • Site (e.g., datadoghq.com, datadoghq.eu)
2

Navigate to SIEM

Go to SIEM
3

Create Integration

Click Create Integration
4

Select Datadog

Choose Datadog as your provider
5

Enter Credentials

  • Application Key: Your Datadog Application Key
  • API Key: Your Datadog API key
  • Site: Your Datadog site

Terraform

Datadog Dashboard

Import this template JSON for a sample of some of the analyses you can do with the Datadog log integration.

Splunk

1

Create Splunk HEC Token

In Splunk, create a new HTTP Event Collector (HEC) token
2

Navigate to SIEM

Go to SIEM
3

Create Integration

Click Create Integration
4

Select Splunk

Choose Splunk as your provider
5

Enter Configuration

  • Access Token: Your HEC token
  • Host: Your Splunk instance hostname
  • Port: HEC port (usually 8088)

Terraform

Panther

Custom.Formal.Logs schema

Compression

Log objects written to AWS S3, Google Cloud Storage, and Azure Blob Storage can be sent as compressed files. Compression applies per log object, and Formal currently writes one object per log line. Compression reduces stored bytes but not the number of objects.
Formal records the codec in the object name and leaves the Content-Encoding metadata unset.

Object Storage Layout

For AWS S3, Google Cloud Storage, and Azure Blob Storage, Formal writes objects under:
{source} is the Connector’s name for Connector logs. For other logs, it is desktop, control-plane, workflow, or insights. Datadog and Splunk receive the same value as the service name. See Control Plane Logs for Control Plane-specific details.

Use Cases

Compliance and Auditing

Forward logs to long-term storage for compliance requirements:

Real-Time Security Monitoring

Send logs to your SIEM for real-time threat detection:
Create alerts in Datadog for:
  • Failed authentication attempts
  • Policy violations
  • Unusual query patterns
  • Off-hours access

Data Lake Integration

Forward logs to your data lake for analytics:
Then use Athena, Redshift Spectrum, or Databricks to analyze:
  • User access patterns
  • Query performance
  • Policy effectiveness
  • Resource utilization

Multi-Destination Forwarding

Send logs to multiple destinations:

Next Steps

Cloud Accounts

Connect AWS or GCP for S3 and GCS log delivery

View Logs

Monitor logs in the Control Plane