Forward the downpipes audit trail to Elastic
Elastic receives the downpipes audit trail through the Filebeat or Elastic Agent http_endpoint input. The engine dials out to that input’s HTTPS URL on the scheduler tick and posts the audit events as a JSON array, so the input splits the array into one document per event. This platform needs that input set up first, where Splunk and Datadog parse a first-time feed on their own.
The intake here is the http_endpoint input you run and expose yourself, not a hosted Elastic Cloud URL. Elastic Cloud has no generic HTTP log intake of its own, so you place the input on a Filebeat or Elastic Agent you control, and point the engine at it.
Because the engine makes the outbound call, a Cloudflare Access perimeter on your console hostname never blocks this: there is no inbound request for Access to turn away.
What you need
- A Filebeat or Elastic Agent you run, with the
http_endpointinput you can configure and expose over HTTPS. - The input’s URL and any auth you set on it, and owner access to the downpipes console.
Set it up
- On your Filebeat or Elastic Agent, configure the
http_endpointinput: set a listen host and port, a URL path, TLS, and (recommended) a secret header token. Point its output at your Elastic destination. - Note the input’s public HTTPS URL and the secret header you set.
- In the downpipes console, open Integrations, choose this vendor’s tile, and set up the SIEM audit push there (owner-only, asks for a fresh step-up sign-in).
- This tile fixes Delivery to HTTP endpoint and Format to JSON array, with no picker to set either. Paste the input URL into Endpoint URL. The Datadog Logs intake array shape also splits cleanly, but this tile does not offer it; reach it from the Custom endpoint tile, which leaves both settings to you.
- Set Auth header name to the secret header the input expects, and paste its value as the Auth secret.
- Leave Enabled ticked to start draining at the next scheduler tick, or clear it to test before any real event leaves. Choose Configure to save. With a second owner on the account, the save waits for that owner’s approval first.
- Choose Test send and confirm the input accepts it. A test send works whether the destination is enabled or not, and never advances the delivery cursor. If you cleared Enabled, choose Enable now.
What lands in Elastic
Each batch arrives as a JSON array of raw audit events, and the http_endpoint input emits one document per array element:
[{"seq":4097,"ts":"2026-06-19T02:14:08.221Z","actorEmail":"ops@acme.example","action":"restore-approve","outcome":"success","...":"..."}]
From there your Filebeat or Agent pipeline indexes the documents. Add an ingest pipeline if you want ts mapped to @timestamp, or the fields renamed to ECS.
Good to know
- The
http_endpointinput is yours to run and expose, not a hosted Elastic endpoint. Give it TLS and a secret header, since the engine dials out to it over the public internet. - The array splits into one document per event, and delivery is at-least-once. Dedup on the stable
seqorhash. The feed carries operator identity (member emails, source IPs, roles and approver emails); no backup data and no secret values. For the shared push mechanics and the pull alternative, see forwarding the audit log to your SIEM.
Last updated .