Send security events to your SIEM
Send Flowstate’s security events to a collector you control, such as Splunk, Datadog, a Microsoft Sentinel Logic App, or any service that accepts JSON over HTTPS.
You need to be a Flowstate admin.
What Flowstate sends
| Event | When |
|---|---|
| Effort report history viewed | Someone opens a person’s effort report history |
| Allocation review viewed | Someone opens a team’s allocation review |
| Weekly allocations viewed | Someone opens a team’s weekly allocations |
| AI assistant access approved or denied | Someone approves or denies an AI assistant’s access to their Flowstate account |
| AI assistant request | An AI assistant connected to Flowstate makes a request, including requests that fail or are rate limited |
The exact event names and severities are under For your technical team.
Before you start
- An HTTPS address in your SIEM that accepts JSON sent by
POST. - The credential that address needs, if any.
1. Add an endpoint
-
Go to Settings → Organisation → SIEM Integration.
-
Under Endpoints, select Add Endpoint.
-
Enter a Name, such as “Splunk Production”.
-
Enter the Endpoint URL. Use an
https://address. -
Choose an Endpoint Type. Every endpoint receives the same JSON over HTTPS.
-
Choose an Auth Type and fill in Credential:
Auth Type Enter in Credential Bearer Token The token Basic Auth username:passwordCustom Header The header name and value together, such as DD-API-KEY: <your key>None Nothing -
Under Event Categories, tick at least Data Access, Authentication and API Activity.
-
Leave Minimum Severity at Info (all events) unless you only want the more serious events.
-
Select Create Endpoint.
2. Check events arrive
- In Flowstate, open a team’s weekly allocations.
- In your SIEM, search for
effort.weekly_allocations_viewed.
Done when: the event is in your SIEM.
Pause, change or delete an endpoint
- To pause sending, turn off the switch on the endpoint’s row. Turn it back on to start again.
- To change an endpoint, open its menu and select Edit Endpoint. Leave Credential blank to keep the current one.
- To delete an endpoint, open its menu, select Delete Endpoint, then select Delete. Events stop going to it straight away. Deleting can’t be undone, so pause the endpoint instead if you might need it again.
If something’s not right
Nothing arrives. Check the endpoint’s switch is on, its Event Categories include the event’s category, and Minimum Severity isn’t set higher than the event. Then check your collector accepts the credential you entered.
Splunk rejects the events. Use Splunk’s raw collector address, as described below.
For your technical team
Event names
| Category | Event | Severity |
|---|---|---|
| Data Access | effort.report_history_viewed | info |
| Data Access | effort.allocation_review_viewed | info |
| Data Access | effort.weekly_allocations_viewed | info |
| Authentication | mcp_consent_approved | info |
| Authentication | mcp_consent_denied | info |
| API Activity | mcp_request | info |
| API Activity | mcp_request_error | high |
| API Activity | mcp_rate_limited | medium |
Event format
Each event is one JSON object, sent with Content-Type: application/json.
| Field | Contents |
|---|---|
eventId | Unique ID for the event |
timestamp | When it happened, ISO 8601 |
logType | Always siem |
category | authentication, api_activity or data_access |
eventType | The event name |
description | A readable sentence |
severity | info, low, medium, high or critical |
outcome | success, failure or unknown |
actor | userId, email, ipAddress and userAgent, where known |
target | type, id and name of what was acted on, where there is one |
detail | Fields for that event, such as teamId and weekStart |
organizationId | Your organisation’s ID, where known |
tenantId | Your account’s ID |
requestId | The request ID, where known |
service | name, version and environment of the Flowstate service that sent it |
Example:
{
"eventId": "<uuid>",
"timestamp": "<ISO 8601 time>",
"logType": "siem",
"category": "data_access",
"eventType": "effort.weekly_allocations_viewed",
"description": "User viewed weekly team allocations",
"severity": "info",
"outcome": "success",
"actor": { "userId": "<user id>", "email": "jane@example.com" },
"target": { "type": "team", "id": "<team id>" },
"detail": { "teamId": "<team id>", "weekStart": "<ISO 8601 time>" },
"organizationId": "<organisation id>",
"tenantId": "<account id>",
"service": { "name": "flowstate-app", "version": "<release>", "environment": "production" }
}
Vendor set-up
Check your vendor’s current documentation too.
- Splunk HTTP Event Collector: use the raw endpoint,
/services/collector/raw. Set Auth Type to Custom Header and Credential toAuthorization: Splunk <HEC token>. - Datadog: use Datadog’s HTTP log intake for your site. Set Auth Type to Custom Header and Credential to
DD-API-KEY: <API key>. - Microsoft Sentinel: point Flowstate at an HTTP-triggered Logic App or Azure Function that forwards events to your Log Analytics workspace.
Manage endpoints from a script
The API Keys section on the same page creates keys for managing your SIEM endpoints from a script. They don’t read events.
- Select Create Key.
- Enter a Name and choose an Expiration.
- Select Create API Key and copy the key. It’s only shown once.
A SIEM key can manage everything on this page, including other SIEM keys, so store it as carefully as an admin password. Send it as Authorization: Bearer fs_siem_….
| Method and path | Does |
|---|---|
GET /api/siem/config | List endpoints |
POST /api/siem/config | Create an endpoint |
PUT /api/siem/config/{id} | Change an endpoint, including switching it on or off |
DELETE /api/siem/config/{id} | Delete an endpoint |
GET /api/siem/keys | List SIEM keys |
POST /api/siem/keys | Create a SIEM key |
DELETE /api/siem/keys/{id} | Revoke a SIEM key |
Revoke a SIEM API key
Revoke a key when the script that uses it is retired, or if the key may have been seen by someone who shouldn’t have it.
- Go to Settings → Organisation → SIEM Integration.
- Under API Keys, open the key’s menu and select Revoke Key.
- Select Revoke.
Anything using the key loses access straight away, and the key leaves the list.