key.delete or 5xx gateway responses.
Every plan starts with a
Log drains limit of 0, so Settings > Log Drains won’t let you create one yet. Ask support@unkey.com to raise the limit for your workspace.Streams
Each drain sends exactly one stream. Create another drain if you need a second stream or destination.
Leave a filter empty to send every value for that filter, including ones added later. When you set more than one filter on a stream, an event must match all of them.
For audit logs, Specific event types opens a category tree (for example
key). Expanding a category lists full names such as key.create. Checking a category selects every listed action under it.
For gateway requests and runtime logs, All sources includes current and future resources in the workspace. Specific sources limits to the projects, apps, and environments you pick. A selection of whole projects or apps also covers environments added later under those resources; mixed environment IDs do not.
Filter changes apply from the drain’s current position. They do not replay events that an earlier filter skipped.
How delivery works
Unkey sends events in batches after they happen. Your destination must accept the whole batch (HTTP: a2xx within 30 seconds) before delivery counts as successful. Failures retry the same batch.
Delivery is at least once, so retries can send an event more than once. Deduplicate in your system: use id for audit logs, request_id for key verifications and gateway requests, and log_id for runtime logs. Rate-limit checks in one multi-limit request share request_id, so that field alone does not uniquely identify each decision.
A drain starts when you create it. Earlier events are not backfilled. After a pause or failure, delivery resumes from the last committed position, as long as the events are still within retention. Verification logs are kept for 90 days, gateway requests for seven days, and audit logs for your plan’s audit log retention (up to 90 days).
Destinations
destination
Unkey posts batches to an HTTPS URL you provide. Don’t put a username or password in the URL. Use a header instead. Under Encoding, pick JSON (an array of events per request), NDJSON (one event per line), or HEC (Splunk HTTP Event Collector and compatible sinks such as CrowdStrike NG-SIEM). HEC wraps each event as
time, source (unkey), sourcetype (the stream name), and event, and treats the delivery as successful only when the response is 2xx with HEC code 0. Add up to 32 unique headers, such as an Authorization header your endpoint checks. Names can be up to 256 characters and values up to 8192. Header values are stored encrypted and never shown again after you save.destination
Unkey sends events to an Axiom dataset you name, using an Axiom API token you provide. The token is stored encrypted.
Create a drain
Name it and pick a stream
Give it a name (shown in the list and on the drain page). Under Stream, choose Audit logs, Key verifications, Gateway HTTP requests, Runtime logs, or Rate limits. Optionally set that stream’s filters.
Enter destination settings
For HTTP, set the URL, encoding (JSON, NDJSON, or HEC), and optional headers. For Axiom, set the dataset and API token. Then create the drain.
Pause a drain, or fix a failing one
A drain shows one of three states:- Running: it’s delivering.
- Paused (
paused_by_user): you clicked Pause deliveries. Click Resume deliveries to pick up where it stopped, including events that arrived in between (within retention). - Failing (
paused_by_failure): 50 deliveries in a row failed and Unkey stopped trying. Fix the destination, then click Resume deliveries.