Overview
Audit Log Streaming continuously delivers your organization’s audit log to a cloud storage destination that you own and control. Instead of exporting the audit log by hand, Mixpanel pushes new entries to your destination as they are recorded — ready to be picked up by your security monitoring tooling, a log pipeline, or a compliance archive. A stream is configured once for the whole organization and carries every audit log entry for it, including entries scoped to individual projects. Entries typically arrive at your destination within five minutes of the action that produced them.Requirements
- An Enterprise plan.
- Organization Owner or Admin. Only Owners and Admins can create, edit, pause, resume, or delete a stream.
- A cloud storage destination you control, and the access to grant Mixpanel permission on it.
What Gets Streamed
Every audit log entry recorded for your organization is streamed. This is the same set of events listed in the Audit Log Reference, covering both organization-level events (logins, service account management, two-factor changes, role changes) and project-level events (report and board changes, data governance changes, exports, and more).Set Up a Stream
Open the stream configuration
Select your destination type
Grant Mixpanel access to the destination
Enter the destination details and save
Delivered Files
All destinations receive batches as gzipped NDJSON files.Record Shape
Each line contains one complete audit log entry. See the Audit Log Reference for the record schema and field definitions. In particular, consumers should useid to deduplicate entries and created to order them.
Object Path
Files use this path:Destinations
AWS S3
Mixpanel delivers each batch of audit log entries as a gzipped NDJSON object into an S3 bucket you own. Mixpanel assumes a cross-account IAM role in your AWS account to write the objects. The role must trust the Mixpanel export user and require the external ID shown while you configure the stream in Mixpanel. The external ID is unique to your Mixpanel organization and has this format:Set Up the Bucket and IAM Role
Start configuring the stream in Mixpanel
Create or choose an S3 bucket
Create an S3 write policy
<BUCKET_NAME> with the name of your bucket:<KMS_KEY_ARN> with the key’s ARN:kms:GenerateDataKey.Create an IAM role with a custom trust policy
<EXTERNAL_ID_FROM_MIXPANEL> with the value you copied from the stream configuration:Finish configuring the stream in Mixpanel
- Bucket: The name of the destination S3 bucket.
- Region: The AWS region containing the bucket.
- Role ARN: The ARN of the IAM role Mixpanel should assume.
- Path prefix: An optional path under which Mixpanel should write the audit log objects.
Confirm delivery
How Mixpanel Verifies Access
When you create, update, or resume a stream, Mixpanel writes a zero-byte probe object named_mixpanel_healthcheck under your configured prefix. The probe is rewritten in place on every check, so only one ever exists and it is safe to leave in your bucket.
Google Cloud Storage
Mixpanel delivers each batch of audit log entries as a gzipped NDJSON object into a Cloud Storage bucket you own, writing as a Mixpanel-owned service account that you grant access to on your bucket. There is no key exchange in either direction: you never give Mixpanel a service account key, and Mixpanel never stores credentials for your Google Cloud project. The same service account is used regardless of your organization’s data residency (US, EU, or India).Required Permissions
Grant this service account:roles/storage.objectUser) role on the destination bucket.
Storage Object User is required because delivery overwrites objects: retried batches rewrite the same object name, and the access-verification probe is rewritten in place. Cloud Storage requires delete permission to overwrite an existing object, so object-creation permission alone is not sufficient.
Set Up the Bucket
Start configuring the stream in Mixpanel
Create a bucket
Grant Mixpanel access on the bucket
Configure the stream in Mixpanel
Confirm delivery
How Mixpanel Verifies Access
When you create, update, or resume a stream, Mixpanel writes a zero-byte probe object named_mixpanel_healthcheck under your configured prefix. The probe is rewritten in place on every check, so only one ever exists and it is safe to leave in your bucket.
Bucket Configuration Notes
- Bucket name must be a valid Cloud Storage bucket name (3–63 characters; lowercase letters, numbers, dots, hyphens, underscores).
- Path prefix is optional. Leading and trailing slashes are normalized, so
audit-logs,/audit-logs, andaudit-logs/are equivalent. - Retention locks and object holds that prevent overwriting an existing object will fail the access check and break retried deliveries. Use a bucket or prefix without an overwrite-blocking retention lock.
- Customer-managed encryption keys work normally. Mixpanel writes through the bucket’s default encryption settings.
Managing a Stream
Pausing and Log Retention
Pausing is safe for short periods, but it is not an indefinite hold — Mixpanel does not archive an unbounded backlog on your behalf.- While paused, Mixpanel keeps collecting your audit logs and holds the undelivered batches, ready to ship when you resume.
- On resume, Mixpanel delivers up to the last 7 days of held logs. Held logs older than that have aged out and will not be delivered. A stream paused for 3 days and resumed loses nothing; a stream paused for 12 days and resumed receives roughly the most recent 7 days, and the earlier part of the pause is a permanent gap in your destination.
- A stream paused for more than 3 weeks stops collecting altogether. At that point Mixpanel treats the stream as abandoned: it stops holding new logs, and any still-held logs are discarded. When you resume such a stream, delivery restarts from the point of resume — only actions that occur after you resume are streamed. Nothing from during the pause is delivered, regardless of the 7-day window.
- Deleting a stream discards held logs immediately. There is no grace period and no resume path; delete is not a long pause.
Filling a Gap
Any entry that was never delivered — whether from before the stream existed, or from a pause that exceeded the retention window above — remains available in Mixpanel until the end of the audit log retention period. To backfill it in the same format as streamed entries, export the audit log as NDJSON from Organization Settings → Audit Log for the affected time range. Streaming and the audit log read the same underlying records, so a backfilled export reconciles cleanly with streamed files.Delivery Failures and Automatic Pausing
Mixpanel retries failed deliveries automatically, so a brief problem at your destination resolves itself with no action from you. If Mixpanel fails to deliver to your destination too many times in a row, the stream is paused automatically. Your organization’s Owners and Admins receive a notification email, and the stream shows as Paused in Mixpanel along with when it was paused and why. Fix the underlying problem, then click Resume — Mixpanel re-verifies the destination before restarting delivery. An automatic pause that goes unnoticed will quietly become a gap in your destination once it crosses the retention window above, so act on the notification email promptly.Troubleshooting
FAQ
Is there an API for exporting audit logs?
Is there an API for exporting audit logs?
What if my destination isn't supported?
What if my destination isn't supported?
Can I stream to more than one destination?
Can I stream to more than one destination?
Can the same entry arrive twice?
Can the same entry arrive twice?
id.Are entries delivered in order?
Are entries delivered in order?
created timestamp after ingestion.Can I recover the logs held by a stream I deleted?
Can I recover the logs held by a stream I deleted?
Does streaming change how long Mixpanel keeps my audit log?
Does streaming change how long Mixpanel keeps my audit log?