Applies to: HealthPro
Summary
HealthPro can provide selected audit logs from a customer’s HealthPro organization (HP Org) as scheduled batch files for collection by, or delivery to, a customer-managed third-party platform. This service supports security monitoring, compliance evidence, and operational auditing.
This article explains how HealthPro license customers can request batch audit log integration with a third-party event, log collection, or analysis platform.
For more information about the integration, refer to How to Request Batch Audit Log Integration.
Supported Log Data
| Log Type | Availability | Examples |
| User logs | Required | User activity, configuration changes, role changes, firmware actions, and portal login or logout events where supported |
| Device logs | Required | Device-related activity and audit events |
| Task logs | Optional | Task execution and task status events |
| Health logs | Optional | Health monitoring and image-health-related events |
Delivery Methods
The standard service uses a daily batch. The schedule and delivery method may be adjusted when required by the customer’s operating environment and integration design.
Option 1: HealthPro-managed AWS S3
HealthPro creates the batch file in HealthPro-managed AWS S3 storage. The customer or third-party platform accesses the agreed location and downloads the file.
- Use this option when the customer’s platform can securely read from an external S3 location.
- Provide the required access configuration, AWS account details, and region information.
- For Panther or similar platforms, use an IAM role with a Trust Relationship instead of a pre-signed URL when supported by the customer’s security policy.
Option 2: Customer-managed Cloud Storage
HealthPro connects to the customer’s agreed cloud-storage location and uploads the batch file.
- Use this option when the customer requires logs to remain in its own cloud environment.
- Provide the target storage details and the required access configuration.
- Review security, network, and permission requirements before implementation.
Default Batch Schedule
The standard service uses the following daily batch schedule:
- Frequency: Once per day.
- Default Execution Time: 00:00, subject to the agreed service configuration.
- Default Data Range: Previous calendar day, from 00:00:00 through 23:59:59.
- Adjustments: Frequency, interval, and execution time may be adjusted based on the customer’s requirements and technical feasibility.
For example, a batch executed at 00:00 on September 4 retrieves the logs generated from 00:00:00 through 23:59:59 on September 3.
Data and Delivery Considerations
JSON is the preferred format for SIEM and event-platform integration when the target platform supports structured JSON ingestion.
The delivered data must be mapped to the target platform's parsing or schema requirements.
A single scheduled transfer may be limited by the agreed service implementation, including a maximum lookback period or record count. The applicable limit must be confirmed during request review.
Batch delivery is asynchronous and should not block normal HealthPro user operations.