---
search:
  tags:
    - Audit
    - GET
seo:
  description: >-
    Admin-only pull export for SIEM / log pipeline backfill.… Reference for the
    GET /organizations/{organizationSlug}/audit/export endpoint in the Seal API.
sidebar:
  label: Export sealed audit entries as NDJSON for SIEM pull (SEA-67)
  badge: GET
title: Export sealed audit entries as NDJSON for SIEM pull (SEA-67)
type: openapi-operation
---
Admin-only pull export for SIEM / log pipeline backfill.
Returns one JSON object per line (`application/x-ndjson`), ordered by
sealed `sequence`. Pass `after_sequence` from the prior response's
`x-seal-next-sequence` header to page.

**Retention:** workspace audit entries (including IP when present via
Cloudflare connecting IP) are retained for the life of the organization
unless the org is deleted. Export to your SIEM for customer-controlled
retention.

**Push alternative:** create a webhook subscribed to `audit.entry.created`,
`audit.*`, or `*`. Seal fans sealed rows out on the */5 cron (and via
`POST .../audit/siem/flush`).

`GET /organizations/{organizationSlug}/audit/export`
