For AI agents: a documentation index is available at https://www.mongodb.com/docs/llms.txt — markdown versions of all pages are available by appending .md to any URL path.
Docs Menu

Export Activity Feed Events to External Tools

You can stream events from the Atlas Activity Feed to external tools, including Datadog, Splunk, customer-managed cloud storage, and any OpenTelemetry (OTel)-compatible destination. Exporting events enables centralized audit logging, long-term retention, and integration with your existing monitoring and observability tools.

You can configure event export at the following levels:

  • Project: exports events from the Project Activity Feed.

  • Organization: exports events from the Organization Activity Feed.

Unlike system log export, event export doesn't require an M10+ cluster. Event export supports clusters of all tiers, including free and shared-tier clusters.

The available destinations depend on whether you configure the integration for a project or an organization. Project event export supports all log export destinations. In the initial release, organization event export supports only OTel-compatible destinations.

Destination
Project Events
Organization Events

Yes

No

Yes

No

Yes

No

Yes

No

Yes

Yes

Yes

No

  • To configure event export for a project, you must have Project Owner access to the project.

  • To configure event export for an organization, you must have Organization Owner access to the organization.

To export project-level events, follow the configuration procedure for your destination and select Events under Log Type when prompted:

You can combine Events with system log types in the same integration, or create separate integrations for logs and events.

Organization-level integrations export events only and support only OTel-compatible destinations. To configure an organization-level integration, see Export Organization Activity Feed Events.

To configure event export programmatically, use the log integration endpoints of the Atlas Administration API. To export events, set logTypes to include EVENTS.

Method
Endpoint
Description

POST

/api/atlas/v2/groups/{groupId}/logIntegrations

Creates one project-level log integration.

GET

/api/atlas/v2/groups/{groupId}/logIntegrations

Returns all project-level log integrations.

GET

/api/atlas/v2/groups/{groupId}/logIntegrations/{id}

Returns one project-level log integration.

PUT

/api/atlas/v2/groups/{groupId}/logIntegrations/{id}

Updates one project-level log integration.

DELETE

/api/atlas/v2/groups/{groupId}/logIntegrations/{id}

Removes one project-level log integration.

POST

/api/atlas/v2/orgs/{orgId}/logIntegrations

Creates one organization-level log integration.

GET

/api/atlas/v2/orgs/{orgId}/logIntegrations

Returns all organization-level log integrations.

GET

/api/atlas/v2/orgs/{orgId}/logIntegrations/{id}

Returns one organization-level log integration.

PUT

/api/atlas/v2/orgs/{orgId}/logIntegrations/{id}

Updates one organization-level log integration.

DELETE

/api/atlas/v2/orgs/{orgId}/logIntegrations/{id}

Removes one organization-level log integration.

Note

The organization-level endpoints are available in the preview version of the Atlas Administration API. To use them, set the Accept header to application/vnd.atlas.preview+json.

Organization-level integrations support only the OTEL_LOG_EXPORT integration type and the EVENTS log type.

Responses redact header values. When you update an integration, sending a redacted value back unchanged leaves the stored value in place. Supply a header value in full only when you change it.

The following example creates a project-level OpenTelemetry integration that exports Activity Feed events:

curl --header "Authorization: Bearer {ACCESS-TOKEN}" \
--header "Content-Type: application/json" \
--header "Accept: application/vnd.atlas.2025-03-12+json" \
--include \
--request POST "https://cloud.mongodb.com/api/atlas/v2/groups/{PROJECT-ID}/logIntegrations?pretty=true" \
--data '{
"type": "OTEL_LOG_EXPORT",
"logTypes": ["EVENTS"],
"otelEndpoint": "https://otel-collector.example.com:4318/v1/logs",
"otelSuppliedHeaders": [
{
"name": "Authorization",
"value": "Bearer token123"
}
]
}'

The following example creates an organization-level OpenTelemetry integration that exports Activity Feed events:

curl --header "Authorization: Bearer {ACCESS-TOKEN}" \
--header "Content-Type: application/json" \
--header "Accept: application/vnd.atlas.preview+json" \
--include \
--request POST "https://cloud.mongodb.com/api/atlas/v2/orgs/{ORG-ID}/logIntegrations?pretty=true" \
--data '{
"type": "OTEL_LOG_EXPORT",
"logTypes": ["EVENTS"],
"otelEndpoint": "https://otel-collector.example.com:4318/v1/logs",
"otelSuppliedHeaders": [
{
"name": "Authorization",
"value": "Bearer token123"
}
]
}'

The endpoint returns the created integration:

{
"id": "66d9f3e1a2b3c4d5e6f70819",
"type": "OTEL_LOG_EXPORT",
"logTypes": ["EVENTS"],
"otelEndpoint": "https://otel-collector.example.com:4318/v1/logs",
"otelSuppliedHeaders": [
{
"name": "Authorization",
"value": "<redacted>"
}
]
}

Atlas delivers events to your destination as JSON payloads over OTLP/HTTP. Each exported event is an OTLP log record. The record's resource includes a service.name attribute set to mongodb-atlas-events, which identifies the Activity Feed event stream, so your OTel collector can route these events separately from other telemetry. Atlas omits attributes with null values from exported events.

Each exported event includes the following fields:

Field
Description

timeUnixNano

Time when the event occurred, in nanoseconds since the Unix epoch.

severityText

Severity of the event as text, such as INFO. Corresponds to the event severity shown in the Activity Feed.

severityNumber

Severity of the event as an OTLP severity number enum, such as SEVERITY_NUMBER_INFO.

body.stringValue

JSON-encoded event object. Contains the event ID (_id), event type (eventType), creation time in milliseconds since the Unix epoch (createdDate), project ID (projectId, when applicable), and event-specific details (eventPayload). The source object identifies what initiated the event, such as a sourceType of USER and a sourceInfo object with the username.

mongodb.event.id attribute

Unique identifier for the event. Use this field to deduplicate events.

mongodb.event.type attribute

Activity Feed event type. For the list of event types, see Atlas Alert Event Types.

mongodb.event.payload.encoding attribute

Encoding of the event payload in body.stringValue, such as json.

mongodb.org.id attribute

ID of the organization where the event occurred. Always present for organization-level exports. Present on some project-level events.

mongodb.project.id attribute

ID of the project where the event occurred. Always present for project-level exports. Present on some organization-level events.

The following example shows an exported project event:

{
"timeUnixNano": "1788896817574000000",
"severityNumber": "SEVERITY_NUMBER_INFO",
"severityText": "INFO",
"body": {
"stringValue": "{\"_id\":\"6aa06631ba29fc2b0f206c32\",\"eventType\":\"/events/mms/alerts/alert_config_added_audit\",\"projectId\":\"62abb98d95a82610b74debc5\",\"createdDate\":1788896817574,\"resources\":[],\"eventPayload\":\"{\\\"targetAlertConfigId\\\": \\\"6aa06631ba29fc2b0f206c30\\\", \\\"targetAlertConfigEventType\\\": \\\"HOST_DOWN\\\", \\\"targetAlertConfigType\\\": \\\"HOST\\\"}\",\"source\":{\"sourceType\":\"USER\",\"sourceInfo\":{\"username\":\"Atlas Admin\"}}}"
},
"attributes": [
{
"key": "mongodb.event.id",
"value": { "stringValue": "6aa06631ba29fc2b0f206c32" }
},
{
"key": "mongodb.event.type",
"value": { "stringValue": "/events/mms/alerts/alert_config_added_audit" }
},
{
"key": "mongodb.project.id",
"value": { "stringValue": "62abb98d95a82610b74debc5" }
},
{
"key": "mongodb.event.payload.encoding",
"value": { "stringValue": "json" }
}
]
}
  • Near real time. Under normal conditions, Atlas delivers events in near real time. Batches flush approximately once per minute.

  • At-least-once delivery. Atlas might deliver the same event more than once. Deduplicate events by using the unique mongodb.event.id field.

  • Buffering during outages. If your destination is unavailable, Atlas buffers events and retries delivery. Atlas retains undelivered events for up to seven days. Events that remain undelivered after seven days are permanently deleted.

  • No automatic replay, backfill, or failure alerts. The initial release doesn't automatically replay events after persistent failures and doesn't backfill historical events that occurred before you configured the integration. To request redelivery of events after a persistent failure, contact MongoDB Support.

Destination
Limits

Datadog

Datadog accepts up to 5 MB and 1,000 events per request.

Splunk

Splunk ingests events in batches through the HTTP Event Collector (HEC). If one event in a batch is malformed, Splunk rejects the entire batch.

OpenTelemetry

Delivery depends on the availability and configuration of your OTel collector. Endpoints must use HTTPS with a certificate signed by a public Certificate Authority (CA). Endpoint URLs can be up to 2,048 characters. You can configure up to 10 headers with a combined size of up to 2 KB.

Event export has no separate SKU or per-feature charge. However, exporting events can incur data transfer charges, which vary by destination, region, and cloud provider. To learn more, see Data Transfer Costs.