Audit Log Retention Changes for all Boomi Customers


As part of continuously strengthening Boomi’s security posture, we are revamping how long we store customer audit logs from indefinite retention towards the industry standard practice of 1-year retention. This policy applies to the following Boomi products:  Integration, Event Streams, and EDI Management. API Management, Master Data Hub, and Flow.

 

Previous communication had stated this change would take effect on April 30, 2024. To provide ample time for preparation and downloading of older logs, Boomi had decided to extend this deadline. The new final date for this change is: June 1, 2026


Here is some additional background on why we are making this change. 

 

1. Data Privacy Concerns: Keeping audit logs for an indefinite period may raise privacy concerns for certain customers in certain regions since these logs may contain elements of personal data or information about our customers' behaviors when using the Boomi platform. This is also an expression of the data minimization principle, since historical data loses its relevance over time and is therefore not required after a certain time.

 

2. Data Retention Risks: Retaining audit logs indefinitely increases the extent of access to this data in case of unauthorized access or misuse. 

 

3. Legal and Compliance Risks: Keeping audit logs for an indefinite period may expose organizations to legal and compliance risks. Data protection regulations, such as the GDPR, require organizations to have clear retention policies in place to ensure that data is not kept longer than necessary.

 

What is captured in audit logs will depend on the source application. Please see the list below for additional details.

 

Audit event types

 

If you are interested in downloading audit logs older than 1 year, you can do so via the AtomSphere API for Integration, EDI, APIM, Event Streams, and Master Data Hub.  Flow audit logs can be downloaded directly from the Flow user interface or via the Flow API.

 

Refer to the resources below for additional information on downloading audit logs.

 

Resources:

  1. AtomSphere API Audit Log Object - Details on what is included in the audit log API

  2. AtomSphere API Audit Log Query - Details on how to query the audit log API

  3. AtomSphere API Integration Recipe - Example integration process to download the audit logs using the audit log API

  4. Flow API Audit Log - Details on how to download logs using the Flow API

  5. Flow Audit Log UI Download - For more information about downloading audit logs for Flow using the UI

  6. Flow Audit API -  Via the built-in API Tool using /api/audit/1/csv.
    For external API access, please use the regional uURIas required before the API endpoint. An API key is needed for external API access