1.0 Introduction
Fortanix Armor automatically maintains an internal audit log of system operations across Armor and its solutions, such as Fortanix Key Insight and Fortanix Confidential Computing Manager (CCM), as well as actions related to all Fortanix Armor accounts, users, and sessions.
This article describes the steps to configure a Fortanix Armor account to send these audit log entries to an external logging system.
2.0 Audit Logging with Fortanix Armor
NOTE
Only users with the Account Administrator role can configure integrations between Fortanix Armor and external logging systems.
The maximum number of external logging integrations that can be configured for a Fortanix Armor account is five.
2.1 Log Management
Fortanix Armor supports integration with the following external logging systems:
Splunk
Azure Log Analytics
Syslog
Azure Log Ingestion – Azure Monitor Integration
Perform the following steps to configure a logging integration in the Fortanix Armor user interface (UI):
Navigate to an Armor account and click the MANAGE ACCOUNT drop down menu on the top-right corner of the page.
In the Account Log Management section, click MANAGE INTEGRATIONS.
On the Log management page, configure one of the integrations below to access all system activity and user login logs.
2.2 Sending Audit Logs to Splunk
You can configure Fortanix Armor to send audit log entries to a Splunk server using the HTTP Event Collector (HEC).
Perform the following steps to configure logging events to Splunk:
On the Log management page, click Splunk → INTEGRATE.
In the Add Splunk integration form:
Splunk server host: Enter the hostname or IP address of the Splunk server.
Enable HTTPS: Select this check box to communicate with the Splunk server over HTTPS (recommended). Also, select the Enable SSL check box in the Splunk Global Settings. Refer to Section 3.0: Appendix for a sample screenshot.
NOTE
If you are using an HTTP connection, then clear the Enable HTTPS check box in the Fortanix Armor Log Management screen for Splunk and clear the Enable SSL check box in the Splunk Global Settings. Refer to Section 3.0: Appendix for the screenshot.
When you select the Enable HTTPS option for alert integrations, the following settings are displayed and are enabled by default:
Validate hostname: The Validate host option, if selected, ensures that the hostname or IP address you entered matches the hostname on the server certificate, verifying that the connection is securely directed to the intended server.
Validate certificate:
Global Root CAs: Use this certificate if you are using a certificate that is signed by a well-known public Certificate Authority (CA).
Custom CA Certificate: Use this certificate if you, as an enterprise, want to self-sign the certificate using your own internal CA.
Click UPLOAD A FILE to upload the CA certificate. When Fortanix Armor, as a client, connects to the Splunk server and is presented with the server’s certificate, it validates the connection using the enrolled custom CA Certificate.
Run the following command to generate the CA certificate:
openssl s_client -connect <endpoint/ipaddress>:port -showcertsWhere,
ipaddress: Defines the IP address of the Splunk server.port: Defines the value of the Management port, under Server settings → General settings in the Splunk Server. Refer to Section 3.0: Appendix for a sample screenshot.
NOTE
In case the Custom CA Certificate has a Common Name (CN) that does not match the server on which Splunk is deployed, clear the Validate host check box, which prompts Fortanix Armor to ignore the hostname of the Splunk deployment instance. Only the certificate chain will be validated in this case.
Splunk service port number: Enter the port number for the Splunk service. The default is port 80, or if HTTPS was enabled above, the default is port 443. If a different port is in use, enter the applicable port number.
Splunk index: Enter the name of the Splunk index to submit events. Use the same index name configured in your Splunk instance. When you push the logs to Splunk, you must push them to a specific index. Fortanix Armor sends this value to the Splunk server. You can set the index name as needed to differentiate logs from various sources. For example, you can push Fortanix Armor logs to a Splunk index named SDKMS. Refer to Section 3.0: Appendix for a sample screenshot.
Authentication token: Enter a valid authentication token to authenticate Fortanix Armor with the HTTP Event Collector (HEC) of your Splunk instance. This token allows Fortanix Armor to push events to Splunk. For example, the logs from Fortanix Armor can be pushed to the Index source name fortanix_cloud. For more information about generating HEC authentication tokens, refer to the Splunk official documentation.
NOTE
For security reasons, the authentication token is not displayed in the interface when editing an existing configuration.
Click INTEGRATE to add the Splunk integration.
2.3 Sending Audit Logs to Azure Log Analytics
NOTE
Microsoft has announced the retirement of the legacy HTTP Data Collector API, which will stop functioning after September 14, 2026. Fortanix recommends migrating to the Azure Log Ingestion – Azure Monitor Integration as described in Section 2.5: Sending Audit Logs to Azure Log Ingestion. For more information, refer to the Microsoft official documentation.
You can configure Fortanix Armor to send audit log entries to Azure Log Analytics in the Azure Portal to write log queries and interactively analyse the Fortanix Armor log data.
Perform the following steps to configure logging events to Azure Log Analytics:
On the Log management page, click Azure Log Analytics → INTEGRATE.
In the Add Azure Log Analytics integration form:
In the Workspace ID field, enter the Workspace ID of the Log Analytics workspace in the Azure portal. The Workspace ID is a GUID that uniquely identifies the specific Log Analytics workspace in Azure. For more information to create a log-analytics workspace, refer to Create a Log Analytics workspace.
To obtain the Workspace ID:
In the Azure portal, open the Log Analytics workspace.
Click Agents management and copy the Workspace ID.

Figure 1: Workspace ID
The Custom Log Type for event logs published from Fortanix services to the Azure Log Analytics workspace is
fortanix_audit_v1_CL. This value is included in the HTTP POST request header for the logs published to the Azure Log Analytics workspace and is used to query Fortanix service logs in the workspace. For more information, refer to Use queries in Log Analytics.
Figure 2: Armor Event Log Query
In the Primary shared key field, enter the primary shared key of the Log Analytics workspace. Requests to the Azure Monitor HTTP Data Collector API must include an authorization header. Each event log sent from the logging service to the Azure Log Analytics workspace is authenticated by the Azure Monitor service, which validates the request and verifies that it is signed using either the primary or secondary key associated with the workspace.
To obtain the primary shared key:
In the Azure portal, open the Log Analytics workspace.
Click Agents management and copy the Primary key.

Figure 3: Primary shared key
Click INTEGRATE to add the Azure Log Analytics integration.
NOTE
For security reasons, the Primary Shared Key is not displayed in the interface when editing an existing shared key.
2.3.1 Azure Monitor References
For more information on creating a Log Analytics workspace, refer to the “Create a Workspace” section in the Microsoft Azure documentation.
For more information on creating a Log Analytics workspace using the Azure CLI, refer to the “Prerequisites” and “Create a Workspace” sections in the Microsoft Azure documentation.
For more information on monitoring logs, refer to the Microsoft Azure documentation.
For more information on querying logs, refer to the Microsoft Azure documentation.
2.4 Sending Audit Logs to Syslog
You can configure Fortanix Armor to send audit log entries to the Syslog server.
Perform the following steps to configure logging events to the Syslog:
On the Log management page, click SysLogs → INTEGRATE.
In the Add Syslog integration form:
Syslog server host: Enter the hostname or IP address of your Syslog server.
Enable TLS: Select this check box to communicate with the Syslog server over a secure connection using TLS.
Validate hostname: The Validate host option, if selected, ensures that the hostname or IP address you entered matches the hostname on the server certificate, verifying that the connection is securely directed to the intended server.
Validate certificate: You can connect to the Syslog server over a non-secure connection or a secure TLS connection.
Global Root CAs: Use this certificate if you are using a certificate that is signed by a well-known public Certificate Authority (CA).
Custom CA Certificate: Use this certificate if you, as an enterprise, want to self-sign the certificate using your own internal CA.
Click UPLOAD A FILE to upload the CA certificate. When Fortanix Armor, as a client, connects to the Splunk server and is presented with the server’s certificate, it validates the connection using the enrolled custom CA Certificate.
Syslog service port number: Enter the port number for the Syslog service. The default is port 514, or if you are using a different port, update the port number accordingly.
Facility: When you log an event in Syslog, you can choose to log it in different facilities. Use this setting to filter logs by a specific facility, such as User, Local0, Local1, and others that are well-defined in the Syslog protocol. For example, configure Fortanix Armor to use the Local0 facility to easily filter logs from a specific appliance.
Click INTEGRATE to add the Syslog integration.
2.5 Sending Audit Logs to Azure Log Ingestion
You can configure Fortanix Armor to send audit log entries to Azure Monitor using the Data Collection Rule (DCR)-based Log Ingestion API.
NOTE
Changes to the logging configuration may disrupt Azure Log Ingestion Logs.
Perform the following steps to configure logging events to Azure Log Ingestion – Azure Monitor Integration:
Ensure that you have already set up a Data Collection Rule and registered an Azure application in the Azure portal. For more information, refer to Send data to Azure Monitor Logs by using the Logs ingestion API (Azure portal).
Use the following sample
sample.jsonfile in the Parse and filter sample data section:{"action_type":"CRYPTOOPERATION","actor_type":"User","message":"User \"jane.doe@fortanix.com\" created key \"test sobject\"","client_provided_context":"","severity":"INFO","time":"2026-06-02T20:59:43Z","acct_id":"d8a53d93-1ff0-4064-80a7-fc22802b93b9","actor_id":"e9f915fe-4530-45cc-983c-2715ceb5727c","group_ids":["31d91eaf-e636-4a78-ba85-f676800740a5"],"object_id":"13f52831-95bc-470a-9bbd-f41f3005f76d","client_ip":"127.0.0.1","operation":"CreateKey","response_time":{"secs":0,"nanos":765056453}}The Tenant ID and Client ID are available on the Overview page of your registered Azure application under Microsoft Entra ID → App registrations.
.png?sv=2026-02-06&spr=https&st=2026-10-09T03%3A18%3A42Z&se=2026-10-09T03%3A39%3A42Z&sr=c&sp=r&sig=WmqyorczUhkDZ3prAhjfePA0wvLOtoLxEwloF49B2%2BI%3D)
Figure 4: Copy tenant and client id
The Logs Ingestion Endpoint URL is available on the Overview page of the linked Data Collection Endpoint.

Figure 5: Copy Logs Ingestion endpoint URL
The DCR Immutable ID is available on the Overview page of your Data Collection Rule under Monitor → Data Collection Rules.

Figure 6: Copy immutable ID
The Stream Name follows the format
Custom-{table name}, where the table name is the custom table created in your Log Analytics workspace..png?sv=2026-02-06&spr=https&st=2026-10-09T03%3A18%3A42Z&se=2026-10-09T03%3A39%3A42Z&sr=c&sp=r&sig=WmqyorczUhkDZ3prAhjfePA0wvLOtoLxEwloF49B2%2BI%3D)
Figure 7: copy stream name
OR
The Stream Name can also be found in the Data Collection Rule → JSON View → Data Flows → Streams.

Figure 8: Stream name in DCR JSON view
On the Log management page, click Azure Logs Ingestion → INTEGRATE.
In the Add Azure Logs Ingestion integration form:
Client ID: Enter the Client ID of your registered Azure application. This value is available on the app registration's Overview page in the Azure portal.
Tenant ID: Enter the Tenant ID of your registered Azure application. This is the Directory ID/Tenant ID associated with your Azure subscription.
Logs ingestion endpoint URL: Enter the endpoint URL from your Azure DCR.
Data Collection Rule (DCR) immutable ID: Enter the immutable ID of your Azure DCR.
Stream name: Enter the stream name configured in your Azure DCR.
In the Client credential section, select either of the following:
Client secret: Enter the client secret value of your registered Azure application. A client secret is a secret string that the registered application uses to prove its identity when requesting a token. It is also referred to as an application password. Enter the Value from the Client secrets section of your registered Azure application in the Azure portal.
Certificate: Upload a client certificate and private key or paste the values directly in the text box to allow Fortanix Armor to authenticate itself to Azure Monitor. Ensure that the certificate file is in
.cer,.pem, or.crtformat.Certificate: Click UPLOAD FILE to upload the client certificate.
Private Key: Click UPLOAD FILE to upload the private key.
Click INTEGRATE to add the Azure Log Ingestion integration.
NOTE
Ensure that the certificate and private key uploaded here match the certificate uploaded in the Azure registered application under Certificates & secrets.
Currently, only RSA asymmetric key is supported for Certificate Authentication.
3.0 Appendix
The following are the Splunk Server screenshots:
If you are using an HTTPS connection, then in the Global Settings:
Select the Enable SSL check box.
Select the Default Source Type as
sdkms_audit.
Figure 9: Enable SSL
Port number on the Splunk server used for generating the Custom CA Certificate.

Figure 10: Management port number
The index value in the Fortanix Armor Splunk Log Management Integration form should be the same as the Default Index value.

Figure 11: Fortanix Armor system events