External Logging

Prev Next

1.0 Introduction

Fortanix Armor automatically maintains an internal audit log of system operations across Armor and its solutions, such as Fortanix Key Insight and Fortanix Confidential Computing Manager (CCM), as well as actions related to all Fortanix Armor accounts, users, and sessions.

This article describes the steps to configure a Fortanix Armor account to send these audit log entries to an external logging system.  

2.0 Audit Logging with Fortanix Armor

NOTE

  • Only users with the Account Administrator role can configure integrations between Fortanix Armor and external logging systems.

  • The maximum number of external logging integrations that can be configured for a Fortanix Armor account is five.

2.1 Log Management

Fortanix Armor supports integration with the following external logging systems:

  • Splunk

  • Azure Log Analytics

  • Syslog

  • Azure Log Ingestion – Azure Monitor Integration

Perform the following steps to configure a logging integration in the Fortanix Armor user interface (UI):

  1. Navigate to an Armor account and click the MANAGE ACCOUNT drop down menu on the top-right corner of the page.

  2. In the Account Log Management section, click MANAGE INTEGRATIONS.

  3. On the Log management page, configure one of the integrations below to access all system activity and user login logs.

2.2 Sending Audit Logs to Splunk

You can configure Fortanix Armor to send audit log entries to a Splunk server using the HTTP Event Collector (HEC).

Perform the following steps to configure logging events to Splunk:

  1. On the Log management page, click Splunk → INTEGRATE.

  2. In the Add Splunk integration form:

    1. Splunk server host: Enter the hostname or IP address of the Splunk server.

    2. Enable HTTPS: Select this check box to communicate with the Splunk server over HTTPS (recommended). Also, select the Enable SSL check box in the Splunk Global Settings. Refer to Section 3.0: Appendix for a sample screenshot.

      NOTE

      If you are using an HTTP connection, then clear the Enable HTTPS check box in the Fortanix Armor Log Management screen for Splunk and clear the Enable SSL check box in the Splunk Global Settings. Refer to Section 3.0: Appendix for the screenshot.

      When you select the Enable HTTPS option for alert integrations, the following settings are displayed and are enabled by default:

      • Validate hostname: The Validate host option, if selected, ensures that the hostname or IP address you entered matches the hostname on the server certificate, verifying that the connection is securely directed to the intended server.

      • Validate certificate:

        • Global Root CAs: Use this certificate if you are using a certificate that is signed by a well-known public Certificate Authority (CA).

        • Custom CA Certificate: Use this certificate if you, as an enterprise, want to self-sign the certificate using your own internal CA.

          Click UPLOAD A FILE to upload the CA certificate. When Fortanix Armor, as a client, connects to the Splunk server and is presented with the server’s certificate, it validates the connection using the enrolled custom CA Certificate.

          Run the following command to generate the CA certificate:

          openssl s_client -connect <endpoint/ipaddress>:port -showcerts

          Where,

          • ipaddress : Defines the IP address of the Splunk server.

          • port : Defines the value of the Management port, under Server settings → General settings in the Splunk Server. Refer to Section 3.0: Appendix for a sample screenshot.

          NOTE

          In case the Custom CA Certificate has a Common Name (CN) that does not match the server on which Splunk is deployed, clear the Validate host check box, which prompts Fortanix Armor to ignore the hostname of the Splunk deployment instance. Only the certificate chain will be validated in this case.

    3. Splunk service port number: Enter the port number for the Splunk service. The default is port 80, or if HTTPS was enabled above, the default is port 443. If a different port is in use, enter the applicable port number.

    4. Splunk index: Enter the name of the Splunk index to submit events. Use the same index name configured in your Splunk instance. When you push the logs to Splunk, you must push them to a specific index. Fortanix Armor sends this value to the Splunk server. You can set the index name as needed to differentiate logs from various sources. For example, you can push Fortanix Armor logs to a Splunk index named SDKMS. Refer to Section 3.0: Appendix for a sample screenshot.

    5. Authentication token: Enter a valid authentication token to authenticate Fortanix Armor with the HTTP Event Collector (HEC) of your Splunk instance. This token allows Fortanix Armor to push events to Splunk. For example, the logs from Fortanix Armor can be pushed to the Index source name fortanix_cloud. For more information about generating HEC authentication tokens, refer to the Splunk official documentation.  

      NOTE

      For security reasons, the authentication token is not displayed in the interface when editing an existing configuration.

  3. Click INTEGRATE to add the Splunk integration.

2.3 Sending Audit Logs to Azure Log Analytics

NOTE

Microsoft has announced the retirement of the legacy HTTP Data Collector API, which will stop functioning after September 14, 2026. Fortanix recommends migrating to the Azure Log Ingestion – Azure Monitor Integration as described in Section 2.5: Sending Audit Logs to Azure Log Ingestion. For more information, refer to the Microsoft official documentation.

You can configure Fortanix Armor to send audit log entries to Azure Log Analytics in the Azure Portal to write log queries and interactively analyse the Fortanix Armor log data.

Perform the following steps to configure logging events to Azure Log Analytics:

  1. On the Log management page, click Azure Log Analytics → INTEGRATE.

  2. In the Add Azure Log Analytics integration form:

    1. In the Workspace ID field, enter the Workspace ID of the Log Analytics workspace in the Azure portal. The Workspace ID is a GUID that uniquely identifies the specific Log Analytics workspace in Azure. For more information to create a log-analytics workspace, refer to Create a Log Analytics workspace.

      To obtain the Workspace ID:

      1. In the Azure portal, open the Log Analytics workspace.

      2. Click Agents management and copy the Workspace ID.

        Figure 1: Workspace ID

    2. The Custom Log Type for event logs published from Fortanix services to the Azure Log Analytics workspace is fortanix_audit_v1_CL. This value is included in the HTTP POST request header for the logs published to the Azure Log Analytics workspace and is used to query Fortanix service logs in the workspace. For more information, refer to Use queries in Log Analytics.  

      Graphical user interface, text, application, email  Description automatically generated

      Figure 2: Armor Event Log Query

    3. In the Primary shared key field, enter the primary shared key of the Log Analytics workspace. Requests to the Azure Monitor HTTP Data Collector API must include an authorization header. Each event log sent from the logging service to the Azure Log Analytics workspace is authenticated by the Azure Monitor service, which validates the request and verifies that it is signed using either the primary or secondary key associated with the workspace.

      To obtain the primary shared key:

      1. In the Azure portal, open the Log Analytics workspace.

      2. Click Agents management and copy the Primary key.

        Figure 3: Primary shared key

  3. Click INTEGRATE to add the Azure Log Analytics integration.

NOTE

For security reasons, the Primary Shared Key is not displayed in the interface when editing an existing shared key.

2.3.1 Azure Monitor References

2.4 Sending Audit Logs to Syslog

You can configure Fortanix Armor to send audit log entries to the Syslog server.

Perform the following steps to configure logging events to the Syslog:

  1. On the Log management page, click SysLogs → INTEGRATE.

  2. In the Add Syslog integration form:

    1. Syslog server host: Enter the hostname or IP address of your Syslog server.

    2. Enable TLS: Select this check box to communicate with the Syslog server over a secure connection using TLS.

      1. Validate hostname: The Validate host option, if selected, ensures that the hostname or IP address you entered matches the hostname on the server certificate, verifying that the connection is securely directed to the intended server.

      2. Validate certificate: You can connect to the Syslog server over a non-secure connection or a secure TLS connection.

        • Global Root CAs: Use this certificate if you are using a certificate that is signed by a well-known public Certificate Authority (CA).

        • Custom CA Certificate: Use this certificate if you, as an enterprise, want to self-sign the certificate using your own internal CA.

          Click UPLOAD A FILE to upload the CA certificate. When Fortanix Armor, as a client, connects to the Splunk server and is presented with the server’s certificate, it validates the connection using the enrolled custom CA Certificate.

    3. Syslog service port number: Enter the port number for the Syslog service. The default is port 514, or if you are using a different port, update the port number accordingly.

    4. Facility: When you log an event in Syslog, you can choose to log it in different facilities. Use this setting to filter logs by a specific facility, such as User, Local0, Local1, and others that are well-defined in the Syslog protocol. For example, configure Fortanix Armor to use the Local0 facility to easily filter logs from a specific appliance.

  3. Click INTEGRATE to add the Syslog integration.

2.5 Sending Audit Logs to Azure Log Ingestion

You can configure Fortanix Armor to send audit log entries to Azure Monitor using the Data Collection Rule (DCR)-based Log Ingestion API.

NOTE

Changes to the logging configuration may disrupt Azure Log Ingestion Logs.

Perform the following steps to configure logging events to Azure Log Ingestion – Azure Monitor Integration:

  1. Ensure that you have already set up a Data Collection Rule and registered an Azure application in the Azure portal. For more information, refer to Send data to Azure Monitor Logs by using the Logs ingestion API (Azure portal).

    Use the following sample sample.json file in the Parse and filter sample data section:

    {"action_type":"CRYPTOOPERATION","actor_type":"User","message":"User \"jane.doe@fortanix.com\" created key \"test sobject\"","client_provided_context":"","severity":"INFO","time":"2026-06-02T20:59:43Z","acct_id":"d8a53d93-1ff0-4064-80a7-fc22802b93b9","actor_id":"e9f915fe-4530-45cc-983c-2715ceb5727c","group_ids":["31d91eaf-e636-4a78-ba85-f676800740a5"],"object_id":"13f52831-95bc-470a-9bbd-f41f3005f76d","client_ip":"127.0.0.1","operation":"CreateKey","response_time":{"secs":0,"nanos":765056453}}
    • The Tenant ID and Client ID are available on the Overview page of your registered Azure application under Microsoft Entra ID → App registrations.

      Figure 4: Copy tenant and client id

    • The Logs Ingestion Endpoint URL is available on the Overview page of the linked Data Collection Endpoint.

      Figure 5: Copy Logs Ingestion endpoint URL

    • The DCR Immutable ID is available on the Overview page of your Data Collection Rule under Monitor → Data Collection Rules.

      Figure 6: Copy immutable ID

    • The Stream Name follows the format Custom-{table name}, where the table name is the custom table created in your Log Analytics workspace.

      Figure 7: copy stream name

      OR

    • The Stream Name can also be found in the Data Collection Rule → JSON View → Data Flows → Streams.

      Figure 8: Stream name in DCR JSON view

  2. On the Log management page, click Azure Logs Ingestion → INTEGRATE.

  3. In the Add Azure Logs Ingestion integration form:

    1. Client ID: Enter the Client ID of your registered Azure application. This value is available on the app registration's Overview page in the Azure portal.

    2. Tenant ID: Enter the Tenant ID of your registered Azure application. This is the Directory ID/Tenant ID associated with your Azure subscription.

    3. Logs ingestion endpoint URL: Enter the endpoint URL from your Azure DCR.

    4. Data Collection Rule (DCR) immutable ID: Enter the immutable ID of your Azure DCR.

    5. Stream name: Enter the stream name configured in your Azure DCR.

    6. In the Client credential section, select either of the following:

      • Client secret: Enter the client secret value of your registered Azure application. A client secret is a secret string that the registered application uses to prove its identity when requesting a token. It is also referred to as an application password. Enter the Value from the Client secrets section of your registered Azure application in the Azure portal.

      • Certificate: Upload a client certificate and private key or paste the values directly in the text box to allow Fortanix Armor to authenticate itself to Azure Monitor. Ensure that the certificate file is in .cer, .pem, or .crt format.

        1. Certificate: Click UPLOAD FILE to upload the client certificate.

        2. Private Key: Click UPLOAD FILE to upload the private key.

  4. Click INTEGRATE to add the Azure Log Ingestion integration.

NOTE

  • Ensure that the certificate and private key uploaded here match the certificate uploaded in the Azure registered application under Certificates & secrets.

  • Currently, only RSA asymmetric key is supported for Certificate Authentication.

3.0 Appendix

The following are the Splunk Server screenshots:

If you are using an HTTPS connection, then in the Global Settings:

  • Select the Enable SSL check box.

  • Select the Default Source Type as sdkms_audit.

    Sp1.png

    Figure 9: Enable SSL

  • Port number on the Splunk server used for generating the Custom CA Certificate.

    Sp2.png

    Figure 10: Management port number

  • The index value in the Fortanix Armor Splunk Log Management Integration form should be the same as the Default Index value.

    Sp3.png

    Figure 11: Fortanix Armor system events

Fortanix-logo

4.6

star-ratings

As of August 2025