Forward the downpipes audit trail to Graylog
Graylog receives the downpipes audit trail through a GELF HTTP input. The engine dials out to the input on the scheduler tick and posts the audit events as GELF.
GELF is the one format the engine does not batch. A GELF HTTP input ships with Enable Bulk Receiving off, and an input in that state reads only the first GELF object in a multi-object body and drops the rest, so the engine sends one GELF object per request instead: a tick with 40 new audit events makes 40 requests, and every event lands whether or not Bulk Receiving is on. There is nothing to turn on for this feed, and turning it on changes nothing about what the engine sends.
Because the engine makes the outbound call, a Cloudflare Access perimeter on your console hostname never blocks this: there is no inbound request for Access to turn away.
What you need
- A Graylog role that can create and edit a GELF HTTP input.
- The input’s URL (default port 12201) and owner access to the downpipes console.
Set it up
- In Graylog, open System, Inputs, and create a GELF HTTP input. Launch it on a node, and note the host and port (the default is
12201). - Leave Enable Bulk Receiving as you found it. The engine posts one GELF object per request, so this feed does not depend on it either way.
- Put the input behind HTTPS with a header check. The engine sends only over HTTPS and sends an auth header unless you tick Carry the auth token in the URL, and a bare GELF HTTP input has neither TLS nor authentication, so terminate TLS and validate a header token at a reverse proxy (or load balancer) in front of the input.
- In the downpipes console, open Integrations, choose this vendor’s tile, and set up the SIEM audit push there (owner-only, asks for a fresh step-up sign-in).
- This tile fixes Delivery to HTTP endpoint and Format to GELF, with no picker to set either. Paste the HTTPS URL that fronts the input into Endpoint URL (for example
https://graylog.example.com/gelf). - Set Auth header name to the header your proxy checks, and paste its token as the Auth secret.
- Leave Enabled ticked to start draining on the first scheduler tick after you save, or clear it to test before any real event leaves. Choose Configure to save. When the account has two or more owners, nothing changes until a second owner approves the save.
- Choose Test send and confirm the event lands in Graylog. A test send works whether the destination is enabled or not, and never advances the delivery cursor. If you cleared Enabled, choose Enable now.
What lands in Graylog
Each request carries exactly one GELF object as its whole body:
{"version":"1.1","host":"downpipes","short_message":"restore-approve success","timestamp":1751681648.221,"level":6,"_seq":4097,"_actorEmail":"ops@acme.example","_action":"restore-approve","_outcome":"success","_targetKind":"restore","...":"..."}
Graylog reads short_message, timestamp and level, and every audit field arrives as a custom _-prefixed field (_action, _outcome, _actorEmail and so on), so you can search and build streams on them.
Good to know
- One request per event, so Bulk Receiving is not a prerequisite. A GELF HTTP input with Bulk Receiving off keeps only the first object of a multi-object body, so the engine never sends one: it posts each GELF object on its own. A backlog therefore arrives as a burst of small requests rather than one large POST.
levelreflects the outcome, and delivery is at-least-once. It is 3 (error) for a failed event, 4 (warning) for a denied one, and 6 (info) otherwise; dedup on_seqor_hash. The feed carries operator identity (member emails, subjects and source IPs); no backup data and no secret values. For the shared push mechanics and the pull alternative, see forwarding the audit log to your SIEM.
Last updated .