Audit Logs are Now Available on SonarQube Cloud

Hello Enterprise Admins :waving_hand:

We are thrilled to announce the public release of Audit Logs on SonarQube Cloud, a highly requested feature that is essential for compliance, security investigation, and maintaining governance across your organization.

Audit Logs provide the visibility and accountability required by major regulatory standards, giving your team a definitive record of security-sensitive actions within your SQC enterprise.

The Audit Logs feature is available starting today for all SonarQube Cloud Enterprise administrators.

  • API-Only Access: Access to the audit trail is provided exclusively through a dedicated API endpoint. This approach allows for seamless integration into your existing security information and event management (SIEM) tools and centralized log infrastructure.
  • Initial Event Coverage: We have prioritized logging key Identity and Access Management events, such as SSO login/logout, user creation, and projects permission changes. The full list of covered events can be found in our documentation.

Share Your Priorities:

This is just the beginning. We will be gradually adding support for more events, including quality gate and project configuration changes. We rely on your input to determine our roadmap. Please don’t hesitate to share which events are most important for your compliance and security needs.

Thank you for your commitment to security. We believe Audit Logs will significantly strengthen your governance posture on SonarQube Cloud.

1 Like