Logging, streaming, and events

Last validated:

Manage the logs and events within your Tailscale network, known as a tailnet.

Capture logs and events

You can capture configuration changes to your tailnet as well as network traffic flow.


Identify who did what, and when, to your tailnet configuration.

View networking telemetry for nodes in your Tailscale network.

Stream logs and events to a SIEM or storage bucket

Stream configuration audit logs and network flow logs to your preferred log streaming integration, such as a security information and event management (SIEM) system and Amazon S3 or S3-compatible storage buckets. You can also stream Tailscale SSH session recordings to another node in your tailnet or storage buckets.


Stream Tailscale logs to a security information and event management (SIEM) system, Amazon S3, and S3-compatible service.

Use Tailscale SSH session recording to collect end-to-end encrypted recordings of Tailscale SSH sessions.

Configure an S3 backend for SSH session recording.

Integrate log events with your infrastructure

Use webhooks to integrate log events with your infrastructure, such as with apps like Slack.


Set up a webhook to receive notification of events on your Tailscale network.