Open-Source AI

Docker AI Governance audit logs now stream to your existing SIEM

Docker AI Governance audit logs now stream to your existing SIEM

Docker AI Governance: Audit Logs, Now Where Your Security Team Already Works | Docker

Docker is shipping audit logs for AI Governance that go directly to the SIEM tools security teams already run. The feature, announced today, gives security leads a single searchable record of every policy decision triggered by AI agents in their organization.

Previously, Docker AI Governance only recorded events locally. Security teams had to pull JSON Lines files from individual hosts and assemble evidence across machines they don’t administer. That created friction when security teams needed to demonstrate compliance or answer questions about agent behavior after the fact. Now, audit events stream directly to tools like Splunk and Dynatrace via HTTPS, and the same records remain searchable in Docker Cloud with 90-day retention and CSV export. Both delivery modes can run simultaneously. (Docker Blog)

The logs capture metadata only: principal, action, target, decision, and timestamp. They never contain prompt content, agent output, or parameter values. Coverage currently includes Docker Sandboxes policy decisions and sandbox session events for users with an AI Governance license under an enforced organization policy. (Docker Docs)

Docker says the audit records matter because enforcement-point visibility captures denials that post-facto log collectors miss. A collector reading agent output never sees a tool call that was refused, a domain that was unreachable, or a credential that was requested and withheld. Those events leave no trace in output because the process that would have produced it never ran. A record of allowed actions shows agents are active. A record of denials shows whether controls are doing anything.

The streaming capability is live today for organizations on Docker AI Governance with an enforced organization policy. Docker plans to expand coverage as other Docker AI sources, such as MCP Gateway enforcement decisions, emit records through the same schema.

See also: Docker’s Case for Agentic AI Guardrails, Not Guesswork

Editorially independent: we accept no payment for coverage and currently use no affiliate links. Read our Editorial Standards and Corrections Policy. Published: Aug 9, 2026.
Jinultimate

Editor of ZBrandCo and the person accountable for what we publish — setting our sourcing standards, fact-checking claims against primary sources, and issuing corrections promptly across AI, open source, and gaming. Reach the desk at editorial@zbrandco.com.