Files
authentik/website/docs/sys-mgmt/events/index.md
T
authentik-automation[bot] ea97e2f109 website/docs: add Splunk event forwarding docs (cherry-pick #22938 to version-2026.5) (#23163)
* Cherry-pick #22938 to version-2026.5 (with conflicts)

This cherry-pick has conflicts that need manual resolution.

Original PR: #22938
Original commit: 7bdbfade30

* Update categories.mjs

Signed-off-by: Dewi Roberts <dewi@goauthentik.io>

---------

Signed-off-by: Dewi Roberts <dewi@goauthentik.io>
Co-authored-by: Dominic R <dominic@goauthentik.io>
Co-authored-by: Dewi Roberts <dewi@goauthentik.io>
2026-06-17 14:42:29 +00:00

1.4 KiB

title
title
Events

Events are authentik's built-in logging system. Every event is logged, whether it is initiated by a user or by authentik.

Certain information is stripped from events to ensure that no passwords or other credentials are saved in the log.

About notifications

Events can be used to define notification rules, with specified transport options of either local (shown in the authentik UI), email, or webhook.

About logging

Event logging in authentik provides several layers of transparency about user and system actions, from a quick view on the Overview dashboard, to a full, searchable list of all events, with a volume graph to highlight any spikes, in the Admin interface under Events > Logs.

Refer to our Logging documentation for more information.

Event retention and forwarding

The event retention setting is configured in the System > Settings area of the Admin interface, with the default being set to 365 days.

If you want to forward these events to another application, forward the log output of all authentik containers. Every event creation is logged with the log level "info". For this configuration, it is also recommended to set the internal retention time period to a short time frame (for example, days=1).

If you want to forward authentik events to another system, see Log forwarding.