CEF export to SIEM¶
The customer's security team collects the events of all its systems in one SIEM and analyses them there, not in each system's own console. Agora serves the audit log in CEF (Common Event Format) — a text format, one line per event, fields separated by delimiters. ArcSight, KUMA, MaxPatrol SIEM and other corporate collectors accept it without any adaptation.
The export delivers the chosen window of the journal whole, as one file, oldest records first. It can be taken two ways:
- with the Export to CEF button in the Audit log section — the file is saved by the browser;
- with an API request — the way a SIEM collector takes the journal on a schedule.
The export is the same read of the journal as the feed in the console: the same permissions, the same licence option, the same records. Agora creates no files on the machine and opens no outgoing connections to a collector for it.
Exporting from the console¶
The Export to CEF button sits above the feed, next to Apply. It exports exactly what the feed shows:
- Resource type, Resource name and Actor narrow the export just as they narrow the feed;
- From and To set the time window;
- empty fields mean "do not filter" — the whole journal within its retention is exported.
The export takes the applied filters. If a field was edited after Apply but the feed was not re-read, the export uses the previous value: the file always matches what is on the screen.
The file is named audit-log.cef. It contains every record of the window, not only the pages the feed has loaded so far.
The button is visible to the same roles as the journal itself — security and superadmin. When the journal is not included in the licence, the button is disabled.
The file is assembled in the browser tab's memory. That is enough for a window of several days; the journal over a long retention period is better taken through the API.
Exporting through the API¶
GET /central/api-v4/audit-log/export?format=cef&from=2026-09-27T00:00:00Z&to=2026-09-27T12:00:00Z
Authorization is the same operator authorization as for the rest of the management API, and so are the roles: security and superadmin.
Parameters:
format— required; the only value at present iscef;from,to— the window boundaries in RFC 3339, both included in the window;resource_type,resource_name,actor,actor_type— the same filters as in the console;actor_typetakesadmin,staticandnode.
The response is text (text/plain), as an attachment named audit-log.cef. It is streamed: the first lines arrive at once, and the server keeps one page of the journal in memory, so the size of the window is not limited by anything.
Refusals:
- 400 — a window boundary is not in RFC 3339, or the format is missing or unknown. An invalid request never turns into an export of the whole journal;
- 403 — the role has no access to the journal;
- 404 — the audit log is not included in the licence.
If the export breaks off in the middle of the transfer — for instance, the database fails on the machine's side — the response ends as an incomplete transfer: curl reports a broken connection, the browser marks the download as failed. A file that arrived whole contains the whole window.
Without to the window is open forward: records made while the export is running are included too. For a fixed boundary, set to.
The CEF line¶
Each event is one line:
CEF:0|Flussonic|agora|26.09|stream_config.patch|stream_config.patch|3|rt=1790590530250 externalId=0f6b8a1e-6a3c-5d7e-9b1a-2c3d4e5f6a7b dvchost=11111111-2222-3333-4444-555555555555 suid=admin suser=ivanov outcome=success src=10.20.1.11 cs1=stream cs1Label=resourceType cs2=conference-a cs2Label=resourceName cs3=9c1f07e2 cs3Label=sessionId cs4=4bf92f3577b34da6a3ce929d0e0e4736 cs4Label=traceId cs5={"fields":["labels"],"role":"admin","src_ip":"10.20.1.11","version":7} cs5Label=details cn1=3672 cn1Label=auditId cn2=1 cn2Label=schemaVersion
The header, up to the seventh vertical bar:
- Device Vendor —
Flussonic; - Device Product —
agora: the SIEM picks its parsing rules by it; - Device Version — the version of the installed Agora;
- Device Event Class ID and Name — the action, the same machine name as in the feed's Action column:
stream_config.patch,admin.create,auth.login_failed; - Severity — the event's severity, described below.
Then come the fields, as key=value:
| CEF field | What it holds |
|---|---|
rt |
the time of the event, milliseconds since the epoch |
externalId |
the global event identifier — the SIEM drops duplicates by it |
dvchost |
the identifier of the Agora installation: events of two installations in one SIEM do not mix |
suid |
the kind of actor: admin, static (static key) or node (registration of a cluster machine) |
suser |
the administrator's login; a static key has none |
outcome |
success for an action that happened, failure for a failed login |
src |
the address the request came from |
cs1, cs2 |
resource type and name (cs1Label=resourceType, cs2Label=resourceName) |
cs3 |
the administrator's session identifier (cs3Label=sessionId): it ties a login to everything done in that session |
cs4 |
the request's tracing identifier (cs4Label=traceId) — it matches the event against the logs |
cs5 |
the record's details in JSON (cs5Label=details): role, document version, list of edited fields |
cn1 |
the record number in the installation's journal (cn1Label=auditId) |
cn2 |
the event schema version (cn2Label=schemaVersion) |
Fields an event does not have are left out of the line entirely: an empty key would read to the SIEM as an empty value. An action by the static key, for instance, has neither suser nor cs3.
Special characters are escaped as the CEF specification requires: in the header, the backslash and the vertical bar; in the fields, the backslash and the equals sign; line breaks become \n. One event therefore always takes exactly one line, whatever its values contain.
Event severity¶
Severity is not stored in the journal — it is derived from the event at export time, by one and the same table:
- 7 — a failed action; at present, a failed login attempt (
auth.login_failed); -
5 — an action the security team expects above the general flow:
- deletion of anything, revocation of a machine, reissue of intra-cluster tickets, revealing the join token;
- any action on administrator accounts;
- editing the access settings and the settings of the control installation itself;
- opening and closing the join window;
- any action by the static key — a login with the break-glass credentials deserves attention in itself;
-
3 — everything else: editing streams, templates, delivery zones, an administrator's login.
The rules rely on the shape of the action rather than on a list drawn up in advance, so actions added in future versions get their severity by the same rules.
Scheduled collection into a SIEM¶
A SIEM collector takes the journal in windows on a schedule: each request sets from to the previous request's to. Both boundaries belong to the window, so a record falling exactly on the seam arrives twice — the SIEM drops the duplicate by externalId. A window repeated after a broken transfer is carried over without loss the same way.
A window must not reach beyond the journal's retention — seven days by default (the audit_log_ttl_secs setting, see Retention and protection). A collector that has fallen behind for longer finds only what has not been deleted yet.
A collector that reads JSON can also use the journal feed with a cursor, described in the SIEM export section of the journal page. The event fields there are the same; only the form differs.