Skip to content

Compliance Reports

On the Advanced tier and above, Log Processor generates automated compliance reports on a configurable schedule. Each report summarizes the past 7 days and is useful for organizations subject to SOC 2, HIPAA, PCI-DSS, or internal security audits — it provides documented evidence of what was processed, what was detected, and whether the pipeline was healthy.

Compliance report

What a report includes

  • Event volume — S3 objects processed, log events ingested, processing errors, and active subscription count.
  • Pattern detection summary — total patterns detected and events filtered across all log groups.
  • Detections by pattern type — per-pattern breakdown (e.g. SSN: 142 detected, email: 87 detected) from CloudWatch dimensioned metrics.
  • Top log groups by volume — the 10 busiest log groups by event count (from OpenSearch).
  • Pattern detections by log group — the 10 log groups with the most pattern hits (from OpenSearch).
  • System health — diagnostics with traffic-light status indicators across the pipeline: DLQ depth, Lambda errors, OpenSearch status, and Firehose lag.

Delivery

Reports are saved to the datalake S3 bucket under reports/, and a pre-signed download link is emailed via the alarm SNS topic.

Scheduling and on-demand generation

Configure which days to auto-generate (for example Monday and Friday) and set the lookback window in the Subscription Editor, or generate a report on demand with the Report button. Compliance reports show the generation time in your local timezone.