Skip to main content

OpenTelemetry Audit Logs

Security and identity management

Last Updated: 1 minute read

Scoped identity enforcement: Services must be registered with the Identity Provider using a dedicated scope exclusive to services. The collector validates this scope before accepting logs, ensuring only trusted sources can emit audit data.

Backend-agnostic access control: The OpenTelemetry collector communicates with the log storage backend using credentials such as API keys or tokens. The credentials are associated with a user that has appropriate rights in the backend. This setup ensures that services emitting logs do not need to manage backend-specific authentication or access logic. Instead, the collector handles secure transmission and access control inde-pendently.

External user management: Most supported backends include their own user and client access control sys-tems. These systems are managed outside of XProtect, meaning that users’ permissions and access to stored logs are configured directly within the backend platform.