Tracking Infrastructure Events
Deployment Started
- JavaScript
- Python
- cURL
Configuration Changed
- JavaScript
- Python
- cURL
Secret Rotated
- JavaScript
- Python
- cURL
Incident Created and Rollback Executed
- JavaScript
- Python
- cURL
Alert Rules for Anomalous Activity
Ingestion Spike — Mass Deployments
Detect unusual bursts of deployment events that might indicate a runaway CI/CD pipeline:Repeated Destructive Actions
Alert when the same actor performs many destructive operations in a short window:SIEM Integration via Log Streams
Forward all infrastructure events to your SIEM (Splunk, Datadog, Elastic) in real-time using log streams. Configure an HTTPS webhook destination that points to your SIEM’s ingestion endpoint.HTTPS Webhook to Splunk HEC
S3-Compatible Destination for Long-Term Storage
X-Immutable-Signature header, allowing your SIEM to verify the payload’s authenticity.
Log streams automatically pause after 3 consecutive delivery failures and enter an error state. Monitor your stream status in the dashboard and fix connectivity issues promptly.
Investigating an Incident
When something breaks, query recent changes to the affected service:- JavaScript
- Python
- cURL
What’s Next
Log Streams
Full guide to configuring HTTPS and S3 log stream destinations.
Alert Rules
Set up ingestion spike and repeated action alerts.
SIEM Integration
Detailed guide to connecting Immutable with your SIEM.
Webhook Signatures
Verify the authenticity of log stream payloads.