> ## Documentation Index
> Fetch the complete documentation index at: https://hellotars.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Stream audit events to your SIEM

> Connect Splunk HEC, Amazon S3, or a signed HTTPS webhook from the SIEM streaming tab, then monitor, replay, and rewind delivery.

export const img = {
  activity: {
    activityTimeline: "/docs/guides/activity/images/activity-timeline.png",
    capturedVariablesPanel: "/docs/guides/activity/images/captured-variables-panel.png",
    dataViewCards: "/docs/guides/activity/images/data-view-cards.png",
    exportDataDialog: "/docs/guides/activity/images/export-data-dialog.png",
    tasksPanelExportReady: "/docs/guides/activity/images/tasks-panel-export-ready.png"
  },
  analytics: {
    analyticsOverview: "/docs/guides/analytics/images/analytics-overview.png",
    exploreGallery: "/docs/guides/analytics/images/explore-gallery.png",
    exploreTab: "/docs/guides/analytics/images/explore-tab.png",
    goalForm: "/docs/guides/analytics/images/goal-form.png",
    goalsTab: "/docs/guides/analytics/images/goals-tab.png",
    improveDiagnostics: "/docs/guides/analytics/images/improve-diagnostics.png",
    improveTab: "/docs/guides/analytics/images/improve-tab.png",
    teamTab: "/docs/guides/analytics/images/team-tab.png"
  },
  billing: {
    billingOverview: "/docs/guides/billing/images/billing-overview.png",
    buyConversationsDialog: "/docs/guides/billing/images/buy-conversations-dialog.png",
    buySeatsDialog: "/docs/guides/billing/images/buy-seats-dialog.png",
    livechatSeatsTab: "/docs/guides/billing/images/livechat-seats-tab.png",
    organizationDeletionLifecycle: "/docs/guides/billing/images/organization-deletion-lifecycle.svg",
    organizationSwitcher: "/docs/guides/billing/images/organization-switcher.png",
    rolesAndAccessMatrix: "/docs/guides/billing/images/roles-and-access-matrix.png"
  },
  building: {
    agentBehaviorGuardrails: "/docs/guides/building/images/agent-behavior-guardrails.png",
    agentCardMenu: "/docs/guides/building/images/agent-card-menu.png",
    agentConfigure: "/docs/guides/building/images/agent-configure.png",
    agentExitRoutesDialog: "/docs/guides/building/images/agent-exit-routes-dialog.png",
    agentLibrary: "/docs/guides/building/images/agent-library.png",
    agentModelParameters: "/docs/guides/building/images/agent-model-parameters.png",
    aiAgentGambitLoop: "/docs/guides/building/images/ai-agent-gambit-loop.svg",
    builderBasics: "/docs/guides/building/images/builder-basics.png",
    builderConnectHandlePanel: "/docs/guides/building/images/builder-connect-handle-panel.png",
    builtInToolsDialog: "/docs/guides/building/images/built-in-tools-dialog.png",
    configureDebugTab: "/docs/guides/building/images/configure-debug-tab.png",
    configureLanguage: "/docs/guides/building/images/configure-language.png",
    configureNotifications: "/docs/guides/building/images/configure-notifications.png",
    createAgentDialog: "/docs/guides/building/images/create-agent-dialog.png",
    draftPublishRollbackPinning: "/docs/guides/building/images/draft-publish-rollback-pinning.svg",
    draftSwitcherChip: "/docs/guides/building/images/draft-switcher-chip.png",
    duplicateAgentDialog: "/docs/guides/building/images/duplicate-agent-dialog.png",
    flowConditions: "/docs/guides/building/images/flow-conditions.png",
    gambitPalette: "/docs/guides/building/images/gambit-palette.png",
    gambits: {
      gambitAiAgent: "/docs/guides/building/gambits/images/gambit-ai-agent.png",
      gambitApiCall: "/docs/guides/building/gambits/images/gambit-api-call.png",
      gambitAutoSuggestion: "/docs/guides/building/gambits/images/gambit-auto-suggestion.png",
      gambitButton: "/docs/guides/building/gambits/images/gambit-button.png",
      gambitCard: "/docs/guides/building/gambits/images/gambit-card.png",
      gambitChannel: "/docs/guides/building/gambits/images/gambit-channel.png",
      gambitCustomCode: "/docs/guides/building/gambits/images/gambit-custom-code.png",
      gambitDateTime: "/docs/guides/building/gambits/images/gambit-date-time.png",
      gambitGeoLocation: "/docs/guides/building/gambits/images/gambit-geo-location.png",
      gambitLanguage: "/docs/guides/building/gambits/images/gambit-language.png",
      gambitLiveChat: "/docs/guides/building/gambits/images/gambit-live-chat.png",
      gambitMediaUpload: "/docs/guides/building/gambits/images/gambit-media-upload.png",
      gambitNoInput: "/docs/guides/building/gambits/images/gambit-no-input.png",
      gambitRedirect: "/docs/guides/building/gambits/images/gambit-redirect.png",
      gambitStarRating: "/docs/guides/building/gambits/images/gambit-star-rating.png",
      gambitStartAndEnd: "/docs/guides/building/gambits/images/gambit-start-and-end.png",
      gambitText: "/docs/guides/building/gambits/images/gambit-text.png",
      gambitTrigger: "/docs/guides/building/gambits/images/gambit-trigger.png"
    },
    languagesTranslateGambit: "/docs/guides/building/images/languages-translate-gambit.png",
    languageSystemMessages: "/docs/guides/building/images/language-system-messages.png",
    newDraftDialog: "/docs/guides/building/images/new-draft-dialog.png",
    outputComponentsGrid: "/docs/guides/building/images/output-components-grid.png",
    publishDialog: "/docs/guides/building/images/publish-dialog.png",
    systemPromptDialog: "/docs/guides/building/images/system-prompt-dialog.png",
    testModeEventLog: "/docs/guides/building/images/test-mode-event-log.png",
    testModePanel: "/docs/guides/building/images/test-mode-panel.png",
    validationProblemsPanel: "/docs/guides/building/images/validation-problems-panel.png",
    variablePickerPanel: "/docs/guides/building/images/variable-picker-panel.png",
    variablePillInserted: "/docs/guides/building/images/variable-pill-inserted.png",
    versionsDraftsPanel: "/docs/guides/building/images/versions-drafts-panel.png"
  },
  campaigns: {
    campaignFlavorsTriggers: "/docs/guides/campaigns/images/campaign-flavors-triggers.svg",
    campaignReplyRouting: "/docs/guides/campaigns/images/campaign-reply-routing.svg",
    campaignSendAnatomy: "/docs/guides/campaigns/images/campaign-send-anatomy.svg",
    createACampaign: "/docs/guides/campaigns/images/create-a-campaign.png",
    walletReserveSettleRefund: "/docs/guides/campaigns/images/wallet-reserve-settle-refund.svg",
    webhookCampaignContractLocking: "/docs/guides/campaigns/images/webhook-campaign-contract-locking.svg",
    webhookCampaignLifecycleStates: "/docs/guides/campaigns/images/webhook-campaign-lifecycle-states.svg",
    webhookCampaignOneCallOneDelivery: "/docs/guides/campaigns/images/webhook-campaign-one-call-one-delivery.svg"
  },
  channels: {
    distributeWhatsappConnect: "/docs/guides/channels/images/distribute-whatsapp-connect.png",
    whatsappConnectDialogWaiting: "/docs/guides/channels/images/whatsapp-connect-dialog-waiting.png",
    whatsappEmptyState: "/docs/guides/channels/images/whatsapp-empty-state.png"
  },
  deploy: {
    bridgeEventGambitSection: "/docs/guides/deploy/images/bridge-event-gambit-section.png",
    deploymentSurfacesAndChannels: "/docs/guides/deploy/images/deployment-surfaces-and-channels.svg",
    designAgentTab: "/docs/guides/deploy/images/design-agent-tab.png",
    designLauncherTab: "/docs/guides/deploy/images/design-launcher-tab.png",
    embedIframeTab: "/docs/guides/deploy/images/embed-iframe-tab.png",
    embedTheWidget: "/docs/guides/deploy/images/embed-the-widget.png",
    mobileAppIntegration: "/docs/guides/deploy/images/mobile-app-integration.png",
    onYourDomain: "/docs/guides/deploy/images/on-your-domain.png",
    shareYourAgentLink: "/docs/guides/deploy/images/share-your-agent-link.png"
  },
  developer: {
    api: {
      channelSendTemplateVsMessage: "/docs/developer/api/images/channel-send-template-vs-message.svg",
      endUsers: {
        endUsersListCursorPagination: "/docs/developer/api/end-users/images/end-users-list-cursor-pagination.svg"
      },
      triggerCallConversationLifecycle: "/docs/developer/api/images/trigger-call-conversation-lifecycle.svg"
    },
    developerSurfacesMap: "/docs/developer/images/developer-surfaces-map.svg",
    embed: {
      embedConfigToWidgetContext: "/docs/developer/embed/images/embed-config-to-widget-context.svg",
      hostPageBridgeFlow: "/docs/developer/embed/images/host-page-bridge-flow.svg",
      identitySigningFlow: "/docs/developer/embed/images/identity-signing-flow.svg",
      scriptVsIframeEmbed: "/docs/developer/embed/images/script-vs-iframe-embed.svg"
    },
    mobile: {
      bridgeMessageProtocol: "/docs/developer/mobile/images/bridge-message-protocol.svg",
      webviewBridgeArchitecture: "/docs/developer/mobile/images/webview-bridge-architecture.svg"
    }
  },
  endUsers: {
    anonymousToIdentifiedProfile: "/docs/guides/end-users/images/anonymous-to-identified-profile.svg",
    bulkActionBar: "/docs/guides/end-users/images/bulk-action-bar.png",
    campaignConsentGate: "/docs/guides/end-users/images/campaign-consent-gate.svg",
    consentPerChannelStates: "/docs/guides/end-users/images/consent-per-channel-states.svg",
    dynamicVsStaticSegments: "/docs/guides/end-users/images/dynamic-vs-static-segments.svg",
    endUserDirectory: "/docs/guides/end-users/images/end-user-directory.png",
    endUserProfileAcrossChannels: "/docs/guides/end-users/images/end-user-profile-across-channels.svg",
    endUserProfilePanes: "/docs/guides/end-users/images/end-user-profile-panes.png",
    profileMergeAndTakeoverProtection: "/docs/guides/end-users/images/profile-merge-and-takeover-protection.svg",
    segmentBuilder: "/docs/guides/end-users/images/segment-builder.png",
    segmentsPage: "/docs/guides/end-users/images/segments-page.png"
  },
  getStarted: {
    agentStates: "/docs/get-started/images/agent-states.svg",
    buildToLivePath: "/docs/get-started/images/build-to-live-path.svg",
    dashboardSidebarMap: "/docs/get-started/images/dashboard-sidebar-map.png",
    organizationOwnershipAndRoles: "/docs/get-started/images/organization-ownership-and-roles.svg",
    quickstart: {
      step1CreateYourAccount: "/docs/get-started/images/quickstart/step-1-create-your-account.png",
      step3ConnectTheAiAgent: "/docs/get-started/images/quickstart/step-3-connect-the-ai-agent.png",
      step4TestMode: "/docs/get-started/images/quickstart/step-4-test-mode.png"
    },
    quickstartCanvas: "/docs/get-started/images/quickstart-canvas.png"
  },
  knowledge: {
    addASource: "/docs/guides/knowledge/images/add-a-source.png",
    addRetrieverPicker: "/docs/guides/knowledge/images/add-retriever-picker.png",
    attachKnowledgeGambit: "/docs/guides/knowledge/images/attach-knowledge-gambit.png",
    configureARetriever: "/docs/guides/knowledge/images/configure-a-retriever.png",
    createKnowledgeBaseDialog: "/docs/guides/knowledge/images/create-knowledge-base-dialog.png",
    customRetrieverDialog: "/docs/guides/knowledge/images/custom-retriever-dialog.png",
    datasetTab: "/docs/guides/knowledge/images/dataset-tab.png",
    documentChangeReindexLifecycle: "/docs/guides/knowledge/images/document-change-reindex-lifecycle.svg",
    documentsTabPreview: "/docs/guides/knowledge/images/documents-tab-preview.png",
    importAWebsite: "/docs/guides/knowledge/images/import-a-website.png",
    kbList: "/docs/guides/knowledge/images/kb-list.png",
    retrieverIndexStates: "/docs/guides/knowledge/images/retriever-index-states.svg",
    retrieverQueryPipeline: "/docs/guides/knowledge/images/retriever-query-pipeline.svg",
    standardVsParentChildChunking: "/docs/guides/knowledge/images/standard-vs-parent-child-chunking.svg",
    syncManagement: "/docs/guides/knowledge/images/sync-management.png",
    testRetriever: "/docs/guides/knowledge/images/test-retriever.png"
  },
  liveChat: {
    agentWorkspace: "/docs/guides/live-chat/images/agent-workspace.png",
    assignedAgentPicker: "/docs/guides/live-chat/images/assigned-agent-picker.png",
    automaticAssignmentRouting: "/docs/guides/live-chat/images/automatic-assignment-routing.svg",
    availabilityDropdown: "/docs/guides/live-chat/images/availability-dropdown.png",
    cannedResponses: "/docs/guides/live-chat/images/canned-responses.png",
    composerPreferences: "/docs/guides/live-chat/images/composer-preferences.png",
    copilotPanel: "/docs/guides/live-chat/images/copilot-panel.png",
    filterConversationsDialog: "/docs/guides/live-chat/images/filter-conversations-dialog.png",
    inboxAnalyticsTab: "/docs/guides/live-chat/images/inbox-analytics-tab.png",
    inboxAvailabilityTab: "/docs/guides/live-chat/images/inbox-availability-tab.png",
    inboxesSettings: "/docs/guides/live-chat/images/inboxes-settings.png",
    inboxRoutingTab: "/docs/guides/live-chat/images/inbox-routing-tab.png",
    labelsSettings: "/docs/guides/live-chat/images/labels-settings.png",
    newAttributeDialog: "/docs/guides/live-chat/images/new-attribute-dialog.png",
    newCannedResponseDialog: "/docs/guides/live-chat/images/new-canned-response-dialog.png",
    notificationPreferences: "/docs/guides/live-chat/images/notification-preferences.png",
    notificationsPage: "/docs/guides/live-chat/images/notifications-page.png",
    pickupTargetCard: "/docs/guides/live-chat/images/pickup-target-card.png",
    resolveMenu: "/docs/guides/live-chat/images/resolve-menu.png",
    searchDialog: "/docs/guides/live-chat/images/search-dialog.png",
    seatGateConversation: "/docs/guides/live-chat/images/seat-gate-conversation.png",
    seatsSettings: "/docs/guides/live-chat/images/seats-settings.png",
    workTheInbox: "/docs/guides/live-chat/images/work-the-inbox.png"
  },
  security: {
    addOpenRouterKeyDialog: "/docs/guides/security/images/add-open-router-key-dialog.png",
    auditChainVerified: "/docs/guides/security/images/audit-chain-verified.png",
    auditEventDrawer: "/docs/guides/security/images/audit-event-drawer.png",
    auditExportDialog: "/docs/guides/security/images/audit-export-dialog.png",
    auditLogViewer: "/docs/guides/security/images/audit-log-viewer.png",
    auditRecordLifecycle: "/docs/guides/security/images/audit-record-lifecycle.svg",
    logPrivacyRedactionEnabled: "/docs/guides/security/images/log-privacy-redaction-enabled.png",
    modelProviderEmptyState: "/docs/guides/security/images/model-provider-empty-state.png",
    privacySettings: "/docs/guides/security/images/privacy-settings.png",
    siemConnectWizard: "/docs/guides/security/images/siem-connect-wizard.png",
    supportActorMasking: "/docs/guides/security/images/support-actor-masking.svg"
  },
  tools: {
    addToolModal: "/docs/guides/tools/images/add-tool-modal.png",
    addToolsPanel: "/docs/guides/tools/images/add-tools-panel.png",
    codekitActionEditor: "/docs/guides/tools/images/codekit-action-editor.png",
    codekitConnectToolkitsDialog: "/docs/guides/tools/images/codekit-connect-toolkits-dialog.png",
    codekitSchemaDialog: "/docs/guides/tools/images/codekit-schema-dialog.png",
    codekitToolkit: "/docs/guides/tools/images/codekit-toolkit.png",
    codekitToolkitAnatomy: "/docs/guides/tools/images/codekit-toolkit-anatomy.svg",
    createActionDialog: "/docs/guides/tools/images/create-action-dialog.png",
    createCodekitDialog: "/docs/guides/tools/images/create-codekit-dialog.png",
    responseFilteringDialog: "/docs/guides/tools/images/response-filtering-dialog.png",
    toolGambitEditorAgentMode: "/docs/guides/tools/images/tool-gambit-editor-agent-mode.png",
    toolGambitEditorWorkflowMode: "/docs/guides/tools/images/tool-gambit-editor-workflow-mode.png",
    toolkitDetail: "/docs/guides/tools/images/toolkit-detail.png",
    toolsConnected: "/docs/guides/tools/images/tools-connected.png",
    toolsDirectory: "/docs/guides/tools/images/tools-directory.png",
    viewActionsModal: "/docs/guides/tools/images/view-actions-modal.png",
    workflowModeResponse: "/docs/guides/tools/images/workflow-mode-response.png"
  }
};

export const planNames = {
  premium: "Premium",
  enterprise: "Enterprise"
};

export const props_0 = undefined

export const urls = {
  app: "https://dashboard.hellotars.com",
  site: "https://hellotars.com",
  support: "mailto:support@hellotars.com",
  status: "https://status.hellotars.com"
};

At the end of this page, your organization's audit events stream to your security tooling. You also know how to read a destination card, replay held batches, and rotate a webhook secret.

<Info>
  This capability needs the **{planNames[props_0.plan] ?? props_0.plan}** plan or higher.
</Info>

## Before you start

Before you start, sign in to <a href={urls.app}>the dashboard</a> and select the organization you want to work in.

* You need the Admin role on an Enterprise plan. Other members do not see the **SIEM streaming** tab.
* Have your destination details ready. For Splunk you need the HEC endpoint and token. For Amazon S3 you need a bucket, region, and an access key pair. For a webhook you need an HTTPS endpoint URL.
* For what the audit log records and how to search it, see [Search and export the audit log](/docs/guides/security/audit-log).

## Open the SIEM streaming tab

Open **Settings**, select **Audit log**, then select the **SIEM streaming** tab. Before any destination exists, the tab shows a **Connect your SIEM** panel with a single button of the same name.

Once destinations exist, a summary bar reads, for example, **2 destinations · all healthy**, next to the audit integrity status and an **Add destination** button. You can have up to 5 destinations. At the limit, the button is disabled and the tab says **You've reached the maximum of 5 destinations**.

## Connect a destination

Select **Connect your SIEM** or **Add destination**. The dialog opens as a three-step wizard with the tabs **Destination**, **Connection**, and **What to stream**.

<Frame>
  <img src={img.security.siemConnectWizard} alt="The Connect your SIEM dialog on the What to stream step, with category checkboxes, the Minimum severity select, and the Send test event button" />
</Frame>

### Step 1: Destination

The wizard asks **Where should your audit events go?** and offers three cards.

| Card              | Subtitle                    | How events arrive                                                                                 |
| ----------------- | --------------------------- | ------------------------------------------------------------------------------------------------- |
| **Splunk HEC**    | HTTP Event Collector        | Posted to your collector's event endpoint.                                                        |
| **Amazon S3**     | NDJSON, gzip, daily folders | Written to your bucket as gzipped NDJSON files, one folder per day, under a `tars-audit/` prefix. |
| **HTTPS Webhook** | Signed JSON batches         | Posted to your endpoint as JSON arrays, in order, each request signed.                            |

Select a card and select **Continue**.

### Step 2: Connection

Every type starts with a **Label**, for example `Splunk prod`. The remaining fields depend on the type. Select **Continue** once the required fields are filled.

<Tabs>
  <Tab title="Splunk HEC">
    Enter the **HEC endpoint**, such as `https://splunk.acme.com:8088`, and the **HEC token**. The token is stored encrypted, and only its last 4 characters stay visible after saving. **Index** and the source type are optional. Leave **Index** empty to use the token's default index, and keep the default source type `tars:audit` unless your Splunk administrator has a naming convention.
  </Tab>

  <Tab title="Amazon S3">
    Enter the **Bucket**, for example `acme-audit-archive`, the **Region**, for example `us-east-1`, then the **Access key ID** and **Secret access key**. Below the fields, a **Bucket policy** snippet shows the `s3:PutObject` statement your bucket needs, already filled with your bucket name. Copy it into your bucket policy before you test.
  </Tab>

  <Tab title="HTTPS Webhook">
    Enter the **Endpoint URL**, for example `https://siem.acme.com/tars-events`. HTTPS is required. A **Verify each delivery** snippet shows how to check the `X-Tars-Signature` header on each request. An optional **Bearer token** is sent with every delivery if you set one.

    The signing secret itself is generated when the destination is created, in the next step.
  </Tab>
</Tabs>

### Step 3: What to stream

Choose the event groups to stream, then choose a **Minimum severity**. You can change both later from **Edit destination**.

The groups are **Security & auth**, **Data access & exports**, **Billing**, **Members & org**, **Product changes**, and **Privacy & consent**. All groups are selected by default. The severity options are **Info and above (everything)**, **Warning and above**, and **Critical only**.

The six groups do not cover every audit category. Campaign events and TARS Support events belong to no group, so they do not reach a destination even with every group ticked. See [How Tars support accesses your organization](/docs/guides/security/how-tars-support-accesses-your-org) for where those support actions are auditable.

### Test and save

<Steps>
  <Step title="Select Send test event">
    Tars creates the destination and sends one sample event. The status text reads **Waiting for the destination…** while it runs.
  </Step>

  <Step title="Read the result">
    On success the status text turns green and starts with **Test event received**. On failure a toast shows the destination's error, and you can fix the connection and test again.
  </Step>

  <Step title="If the type is HTTPS Webhook, copy the Signing secret">
    A **Signing secret** panel appears below the test result with a copy button. It is shown once. Afterwards only the last 4 characters stay visible.
  </Step>

  <Step title="Select Save destination">
    The button stays disabled until a test succeeds. The new destination card appears in the tab.
  </Step>
</Steps>

<Warning>
  Changing a field or a filter after a successful test resets the test. Test again before you save, or the **Save destination** button stays disabled.
</Warning>

## Read a destination card

Each destination has its own card in the tab.

* The header shows the label, a status pill, and the endpoint. The pill reads **Healthy**, **Degraded**, **Failing**, or **Paused**.
* The switch pauses or resumes streaming. The **Send test event** button sends one sample event and toasts **Test event delivered** or the error.
* The **More actions** menu holds **Edit destination**, **Rewind cursor…**, and **Delete destination**.
* Four tiles show **Delivered**, **Events behind**, **Last delivery**, and **Held batches**.
* A **Streams:** line lists the selected groups, or **All categories**, and the severity floor.

Below the cards a note explains that events stream in order within about a minute, and that a destination that becomes unreachable is retried automatically. Held events replay once the connection recovers.

## Handle a failing destination

When a destination is **Failing**, a red banner appears at the top of the tab, and the card shows the last error with the number of held events.

* The banner reads, for example, **Delivery to "Splunk prod" has been failing since 2 hours ago**, then **Your security tooling is not receiving new events**.
* Its **Fix connection** button opens the edit dialog.
* If the alert email went out, the banner adds **Admins were emailed**. Admin members receive one email when a destination starts failing, and at most one more every 24 hours while it stays failing.
* On the card, **Replay held events** re-ships every held batch, oldest first, and toasts how many batches are replaying.
* On the card, **Update token** opens the edit dialog so you can enter a new credential.

## Review dead letters

A batch that exhausts its delivery retries is kept as a dead letter instead of being lost. When the **Held batches** tile is above zero, select it to open the **Dead letters** dialog for that destination.

The table shows one row per batch with **Spilled**, **Sequence range**, **Events**, **Attempts**, **Last error**, and a **Replay** badge of `pending`, `succeeded`, or `failed`. Each row has a **Replay** button, and the header has **Replay all** with the count of outstanding batches. Succeeded batches stay in the table for the record. When nothing is held, the dialog says **No dead-lettered batches**.

## Rewind the cursor

Use **Rewind cursor…** from the card's **More actions** menu to re-send events the destination already received, for example to backfill a new Splunk index. The dialog shows the **Current cursor** and the **Latest sequence**, and asks for a **Rewind to sequence** value.

<Warning>
  Re-delivery can duplicate events your SIEM has already indexed. The target must also fall inside the searchable audit window, because archived events cannot be re-shipped.
</Warning>

Enter a sequence below the current cursor and select **Rewind cursor**. A toast confirms the new cursor and how many events will re-ship.

## Edit, rotate, or delete

**Edit destination** opens the dialog on the **Connection** step, titled **Edit destination** followed by the label. Secret fields show **Leave blank to keep •••• 4f2a**, so you only enter a credential when you replace it. The category groups and severity from the wizard are on the same dialog. Select **Save changes** to apply.

### Rotate a webhook signing secret

For an HTTPS Webhook destination, the **Signing secret** row in the edit dialog has a **Rotate…** button. Selecting it generates a new secret and shows it once with a copy button. The old secret stays valid for 24 hours, so your endpoint can switch without failed verifications.

### Delete a destination

**Delete destination** in the **More actions** menu opens a confirmation that reads **Delete SIEM destination?**. Streaming stops immediately and undelivered events for that destination are discarded. This cannot be undone.

## Verify

Trigger an audited action, such as changing a member's role. Within about a minute the destination card shows a fresh **Last delivery** time, **Events behind** returns to 0, and the event appears in your security tooling.

## Related pages

* [Search and export the audit log](/docs/guides/security/audit-log)
* [Data retention](/docs/guides/security/data-retention)
* [Roles and permissions](/docs/guides/billing/roles-and-permissions)
