KeycloakPro

Security · Audit Logs

A clear record of who did what, and when

We configure Keycloak's login and admin events, set retention that matches your policies, and stream every record to the SIEM your security team already watches — so investigations start with evidence, not guesswork.

  • Login and admin events captured
  • Streamed via the Event Listener SPI
  • Runs on upstream Keycloak 26.x

Standards & integrations

  • Event Listener SPI
  • Splunk
  • Elastic
  • Datadog
  • Amazon CloudWatch
  • Apache Kafka
  • Syslog

Overview

What a useful Keycloak audit trail takes

Keycloak can record every sign-in, failed attempt, token refresh and admin change, but out of the box it doesn't save user or admin events, and whatever you do store sits in the same database as your sessions. A trail you can rely on needs the right event types enabled, admin changes captured with their payloads, sensible expiration, and a copy shipped somewhere your security team can search, alert on and keep for as long as policy requires. That's what we build.

What we deliver

  • Event capture and retention policy per realm
  • User and admin event settings applied as code
  • Event listener or log pipeline to your SIEM
  • Starter detection rules for authentication abuse
  • Audit dashboards and saved searches
  • Runbook for investigating account compromise

Capabilities

What Audit Logs covers

Configured, tested and documented on upstream Keycloak — then handed over or operated by us.

  • Login events that matter

    Choose which user event types to save — logins, failures, registrations, password updates, token exchanges — and leave out the noise nobody reads.

  • Admin changes with context

    Admin events record who changed a client, role or user and from which IP address — and, with representations enabled, what the new configuration looked like.

  • Retention you decide

    Expiration settings for user and admin events keep the Keycloak database lean, while the long-term record lives in storage you control.

  • Streaming to your SIEM

    A custom event listener or a structured log pipeline forwards events to Splunk, Elastic, Datadog, CloudWatch or Kafka as they happen.

  • Alerts on suspicious patterns

    Detection rules in your SIEM flag credential stuffing, repeated lockouts, sign-ins from unusual locations and unexpected admin role grants.

  • Evidence for reviews

    Saved searches and exports that answer auditor questions: who held admin access, when a client secret was regenerated, which account changed a flow.

How it works

From first call to production

  1. Define what you need to prove

    We work with your security and compliance owners to decide which events to capture, how long to keep them, and who needs to query them.

  2. Configure and ship

    Event settings are applied as code per realm, and a listener or log pipeline is deployed to deliver events to your SIEM, with delivery monitored.

  3. Build detections and reports

    We write the first set of alerts and dashboards, test them against simulated attacks in staging, and hand over guidance for tuning them.

Use cases

Where teams put it to work

  • Security operations

    Identity events land in the SOC's existing tooling, so failed-login spikes and lockouts sit alongside network and endpoint signals.

  • Customer and compliance audits

    Answer access and change-control questions from enterprise customers and auditors with records instead of screenshots.

  • Incident investigation

    Reconstruct a compromised account's activity — sign-ins, password changes, sessions and admin actions — across every connected application.

FAQ

Audit Logs questions, answered

Where does Keycloak store events by default?

Once saving is enabled, events are written to the Keycloak database and can be browsed in the admin console. That works for day-to-day checks; for long-term retention and alerting we forward them to a system built for it.

Can we see exactly what an admin changed?

Yes. With 'Include representation' turned on, admin events store the JSON body of each change, so you can see the new state of a client, role or user. We check what those payloads contain before they leave Keycloak.

Do we need a custom extension to stream events?

Not always. Keycloak's built-in logging listener can write events to the server log for a log shipper to pick up. For richer payloads or direct delivery to Kafka or a webhook, we build and maintain a small Event Listener SPI provider.

How long should we keep events?

That depends on your policies and contracts. We usually keep a short window in Keycloak through expiration settings and hold the long-term record in your SIEM or object storage, where retention and access are easier to control.

Ready to roll out Audit Logs?

Walk us through your requirements on a free strategy call. We'll come back with an architecture, a delivery plan and a fixed scope.

Browse all products