Logging, streaming, and events
Manage the logs and events within your Tailscale network, known as a tailnet.
Capture logs and events
You can capture configuration changes to your tailnet as well as network traffic flow.
Configuration audit logs
Configure audit logging to capture configuration changes, such as a new device added to your tailnet.
Network audit logs
Configure network flow logging to capture connection information between nodes in your tailnet.
Stream logs and events to a SIEM or storage bucket
Stream configuration audit logs and network flow logs to your preferred log streaming integration, such as a security information and event management (SIEM) system and Amazon S3 or S3-compatible storage buckets. You can also stream Tailscale SSH session recordings to another node in your tailnet or storage buckets.
Log streaming
Send configuration audit logs and network flow logs to a streaming integration.
Tailscale SSH sessions
Send Tailscale SSH activity to another node in your tailnet.
Tailscale SSH session recording
Send Tailscale SSH activity to a storage bucket.
Integrate log events with your infrastructure
Use webhooks to integrate log events with your infrastructure, such as with apps like Slack.
Webhooks
Configure and manage webhooks in your tailnet.