heroui logo

Anthropic Compliance API Logging Disabled

Elastic Detection Rules

View Source
Summary
This rule detects when Anthropic Compliance API logging is disabled by identifying a configuration change event (org_compliance_api_settings_updated) in logs-anthropic.audit-* and evaluating anthropic.audit.compliance_api_logging_enabled == false. Disabling compliance logging creates a blind window during which subsequent administrative actions (e.g., role grants, API key creation, data exports, and SSO changes) may not be visible in the audit data. The rule surfaces the disable event to aid incident response and investigation, so responders can confirm re-enablement, assess the timing, and reconstruct activity via alternative data sources if needed. It also guides triage by correlating the actor (admin_api_key_id or user_email), organization, and source, and by flagging the breach window until logging resumes ingestion. If logging is later re-enabled, investigators should reassess for any compensating controls or related changes in other data sources to close the blind window.
Categories
  • Cloud
  • Application
Data Sources
  • Application Log
ATT&CK Techniques
  • T1562
  • T1562.008
Created: 2026-09-12