Skip to main content
This page describes how Prophecy generates, stores, and shares audit logs for Prophecy deployments. Setting up audit logs requires collaboration with Prophecy. Contact Prophecy to:
  • Export audit logs on demand.
  • Configure automatic syncing to your own storage.
  • Set a custom retention period for stored logs.

Storage location

Prophecy stores audit logs in the same cloud platform as your deployment:
  • For AWS deployments, audit logs are stored in Amazon S3.
  • For Azure deployments, audit logs are stored in Azure Blob Storage.
  • For Google Cloud Platform deployments, audit logs are stored in Google Cloud Storage.

Audit event reference

When audit logs are enabled for your Prophecy deployment, they capture the following information:
  • User interactions with the Prophecy UI.
  • GraphQL API calls made to the control plane.
  • Actions performed directly on the execution plane, such as fabric, connection, deployment, pipeline run, and schedule operations.
The following tables list the audit events that Prophecy logs, organized by entity type.
Prophecy uses GraphQL for control plane API operations. Request and response parameters may vary depending on where you call the query.

Fabric

Project

Pipeline

Job

Dataset

Team

User

Git

Transpiler

Generic

Execution plane events

Prophecy audit logs also capture actions performed directly on the execution plane (the orchestrator service running in your environment), not just control plane GraphQL calls. These events are recorded locally on the execution plane first, then forwarded to the control plane in batches (every 30 minutes by default). As a result, there’s a short delay between an execution action occurring and its event appearing in the central audit log.
Execution plane events are identified by a fixed event type and category rather than a GraphQL query name.

Authentication and identity

Fabric

Connections and secrets

Deployment and pipeline runs

Schedules

Sync data to S3

If your Prophecy deployment is hosted on AWS, you can sync your Prophecy audit logs to your own Amazon S3 bucket. Follow these steps to configure your S3 bucket and grant Prophecy the required access.

1. Create the S3 bucket

  1. Open the Amazon S3 console and choose Create bucket.
  2. Enter a Bucket name, following the format prophecy-customer-audit-events-foo. Replace foo with an identifier for your organization.
  3. Choose a Region. Prophecy syncs to whichever region your bucket is created in — there’s no region you need to avoid or request special handling for.
  4. Complete the remaining setup options as needed, then create the bucket.
  5. Set Object Ownership to ACLs disabled (recommended). You can apply this setting during bucket creation or by editing bucket permissions after creation.
  6. If your bucket uses a customer-managed KMS key, grant the Prophecy role kms:Encrypt, kms:GenerateDataKey*, and kms:DescribeKey in your key policy. Without this, the sync will create successfully but fail when Prophecy tries to write objects.

2. Configure bucket permissions for Prophecy

  1. In the Amazon S3 console, open your bucket and choose the Permissions tab.
  2. Under Bucket policy, select Edit.
  3. Paste the following policy JSON, replacing the placeholders as described below.
To use this example JSON:
  • Replace all instances of prophecy-customer-audit-events-foo with your bucket ARN.
  • The two statements grant access for different purposes: the first lets Prophecy’s sync role read your bucket’s location and read/write objects at transfer time. The second — the DataSyncCreateS3Location statement — grants Prophecy’s s3access IAM user the s3:ListBucket permission it needs to register your bucket as a sync destination in the first place. Both are required.
  • After applying the policy, contact Prophecy and provide:
    • Your bucket ARN.
    • The AWS region.
Prophecy will complete the configuration and enable syncing for your environment.