theauth-go ships an append-only async audit log. The default destination is the database (audit_events table). You can stream events to Splunk, a SIEM, or any external sink via AuditConfig.Sinks, a slice of theauth.AuditSink.
How the audit log works
Every state-changing handler calls EmitAudit(ctx, action, target, metadata). The call is non-blocking: the event is placed on a buffered channel. A background writer goroutine drains the channel in batches, writes them to the canonical storage layer, and then fans out each batch to every configured sink in a separate goroutine. If the channel is full, Stats.AuditDropped is incremented and the event is discarded (this is the documented tradeoff to protect authentication latency under spikes). A failing sink is logged, counted in Stats.AuditSinkFailed, and never blocks or delays storage writes.
Use the built-in Splunk HEC sink
theauth-go ships a ready-made Splunk HTTP Event Collector sink under audit/sinks/splunkhec, so writing your own is usually unnecessary:
splunkhec.New POSTs each batch to <endpoint>/services/collector/event with Authorization: Splunk <token>. Options: WithHTTPClient, WithTimeout (default 5s), WithRedactor (per-event transform applied on top of the canonical DefaultRedactor).
Other built-in sinks live under audit/sinks/: audit/sinks/otlp (OTLP/HTTP logs exporter) and audit/sinks/webhook (generic CloudEvents 1.0 POST).
Implementing a custom sink
If you need a destination other than Splunk, OTLP, or a generic webhook, implement theauth.AuditSink directly:
Example custom sink:
Wire it the same way, appending it to Sinks:
Audit event shape
Default redactor
DefaultRedactor masks values at any nesting depth whose key matches (case-insensitive): password, secret, token, code, refresh_token, access_token. Pass Config.Audit.Redactor to override.
Audit event catalog
See Audit Events Reference for the full list of emitted actions and their target types and metadata shapes.
Monitoring backpressure
Monitor theauth.Stats.AuditDropped and theauth.Stats.AuditFailed:
AuditDropped increments when the channel buffer is full. Reduce write latency (faster external sink, batching) or increase the buffer size to reduce drops. Last modified on October 7, 2026