Back to Infisical

Activity Logs

docs/documentation/platform/agent-proxy/activity-logs.mdx

0.162.134.5 KB
Original Source

Activity logs record what the agent proxy did with each request: which agent called which host, and which credential was applied. Together they form an audit trail of every credential your agents used, and a way to spot blocked or failed requests.

The proxy emits these records in its log output. To keep them, forward that output with a collector such as Fluent Bit or the OpenTelemetry Collector to your logging platform: Splunk, Datadog, Elastic, or anything else.

<Note> Only requests that reach the forwarding stage are logged. Requests rejected earlier (malformed proxy auth, an invalid `CONNECT` target, TLS failures) never reach it and aren't logged. A request whose identity can't be resolved at forwarding is still logged as an `error`, just with an empty agent. </Note>

What's in a record

Each request is logged with these fields (plus the standard time, level, and message):

FieldMeaning
eventAlways agent-proxy.request, so activity is easy to filter from other logs
decisionbrokered, passthrough, blocked, or error
agentId / agentNameThe agent that made the request, read from its access token
projectId / environment / secretPathThe folder the request was scoped to
serviceName / serviceIdThe matched proxied service (omitted when none matched)
method / host / port / pathThe request line, before substitution (so path shows the placeholder)
statusUpstream status on brokered / passthrough; 403 on blocked; 502 on error
credentialsWhat was injected: each entry's secret key (or, for a dynamic secret, its name and output field), and the header or surfaces it landed in
<Warning> A record never contains a real secret. Requests are logged as the agent sent them, before the swap, so `path` shows only the placeholder; `credentials` lists secret **names**, not values; header values and request bodies are never logged. </Warning>

Log levels

Each decision is logged at a level, so --log-level controls how much you see: the default info hides passthrough, debug shows everything, warn shows only blocked and errors.

decisionlevel
passthroughdebug
brokeredinfo
blockedwarn
errorerror

Log format

--log-format sets the shape of each record: console (the default, human-readable) or json for machines and SIEMs. Logs go to stderr (capture with 2> or 2>&1).

<Tabs> <Tab title="console"> ```text 2026-07-17T14:32:09 INF agent request event=agent-proxy.request decision=brokered agentName=claude-agent serviceName=github method=POST host=api.github.com path=/repos/acme/app/issues status=201 credentials=[{"key":"GITHUB_PAT","role":"header-rewrite","header":"Authorization"}] 2026-07-17T14:32:12 WRN agent request event=agent-proxy.request decision=blocked agentName=claude-agent host=evil.example.com method=GET status=403 ``` </Tab> <Tab title="json"> ```json {"level":"info","time":"2026-07-17T14:32:09+05:30","message":"agent request","event":"agent-proxy.request","decision":"brokered","agentId":"9c1e40cf-...","agentName":"claude-agent","projectId":"53c8b330-...","environment":"prod","secretPath":"/coding-agent","serviceName":"github","method":"POST","host":"api.github.com","port":443,"path":"/repos/acme/app/issues","status":201,"credentials":[{"key":"GITHUB_PAT","role":"header-rewrite","header":"Authorization"}]} ``` </Tab> </Tabs>

Log file

--log-file writes json records to a file, in addition to the console output. This lets you watch a readable stream in the terminal while persisting machine-readable logs for your collector.

Common setups

bash
# Watch live, readable (default)
infisical secrets agent-proxy start

# Watch the console and also persist json (e.g. for a SIEM)
infisical secrets agent-proxy start --log-file /var/log/infisical/agent-proxy.log

# Container: json on stderr for your platform to collect
infisical secrets agent-proxy start --log-format json

For rotation, containers let the platform rotate the stream; for --log-file, use logrotate with copytruncate (or restart the proxy).

Next steps

<CardGroup cols={2}> <Card title="agent-proxy CLI reference" icon="terminal" href="/cli/commands/agent-proxy"> Every flag for `start` and `connect`, including the logging options. </Card> <Card title="Audit Logs" icon="scroll" href="/documentation/platform/audit-logs"> Configuration changes to your proxied services are recorded in Infisical's own audit trail. </Card> </CardGroup>