Documentación offline Docker main
por @raupulus

SIEM forwarding

main Documentación oficial Licencia Apache-2.0Descargado el 2026-09-15 Bundle .md (6.1 MB) ↓

En esta página

{{< summary-bar feature_name="AI Governance Audit Logs" >}}

Docker can forward audit events to your security information and event management (SIEM) system, letting you centralize Docker governance data alongside other security signals. Docker verifies the endpoint is reachable with the supplied credential before saving.

Supported destinations#

Destination Description
Splunk Cloud (HEC) Hosted Splunk using the HTTP Event Collector
Dynatrace Dynatrace Log Management using the Log Ingest API
Datadog Datadog Logs using the HTTP log intake API

Before you begin#

SIEM forwarding requires Docker Sandboxes 0.39.0 or later. Earlier versions don't deliver audit records to a SIEM destination, even when forwarding is configured. Update Docker Sandboxes before enabling a new destination.

SIEM forwarding requires Docker Cloud delivery to be enabled for your organization. If you haven't already, enable it under AI Platform > Audit logs > Audit delivery before configuring a SIEM destination. See Configure audit delivery.

Gather credentials from your SIEM before configuring forwarding:

Add a SIEM destination#

  1. Sign in to Docker Home.
  2. Open your organization.
  3. Go to AI Platform > Audit logs.
  4. Open Export & Connectors.
  5. Select Add destination.
  6. Select your destination and complete the form.
  7. Select Save.

If verification fails, check that the URL and credential are correct and that the endpoint is accessible from the internet.

Manage destinations#

From the SIEM forwarding list, select the menu next to a destination to edit or delete it. The edit form lets you update credentials and toggle forwarding on or off for that destination. Deleting a destination permanently removes the endpoint and its stored credential and cannot be undone.