Announced on Rollout on
August 13, 2026 August 13, 2026

Zendesk is releasing access log webhooks to make security information and event management (SIEM) integration easier. This feature is available exclusively for customers who have purchased the Advanced Data Privacy and Protection (ADPP) add-on.

This article includes the following sections:

  • What's changing?
  • Why is Zendesk making this change?
  • What do I need to do?

What's changing?

Zendesk is introducing access log webhooks, giving admins a way to receive access log events in near real time at a customer-configured HTTPS endpoint. This expands how access logs can be delivered, adding an event-driven option that fits directly into existing security workflows, including SIEM platforms such as Splunk, Datadog, Microsoft Sentinel, and QRadar.

Updates include:

  • Webhook subscriptions (Admin Center): Admins can create and manage access log webhook subscriptions, including the destination URL and authentication configuration.
  • Near real-time delivery: Access log events are pushed to the configured endpoint as they occur, instead of requiring customers to build and run their own polling collectors.
  • Batching: Delivery includes batching to handle traffic spikes and avoid overloading customer endpoints.
  • Retries and backoff: Transient delivery failures are automatically retried with backoff to reduce missed events.
  • Delivery receipts: By default, delivery receipts are recorded only for failed deliveries.

These improvements reduce the effort required to integrate access logs into a customer's security tooling, while helping security and compliance teams detect and respond to activity faster.

Why is Zendesk making this change?

Zendesk is introducing access log webhooks to remove a significant adoption blocker for security- and compliance-mature customers who rely on a SIEM for monitoring. Today, customers must build and maintain their own polling collectors to pull access log data into their SIEM, which is slow, reactive, and adds ongoing operational overhead.

Access log webhooks give customers a vendor-agnostic, near real-time delivery path that works with the SIEM platform they already use, without requiring Zendesk to build and maintain a native connector for every vendor. This allows for faster incident response and lowers the operational burden of keeping access log data in sync with existing security tooling.

What do I need to do?

No action is required to continue using access logs as-is; access log webhooks are an opt-in capability. To start using them, admins with the Advanced Data Privacy and Protection (ADPP) add-on with access logs enabled can create a webhook subscription in Admin Center by providing a destination URL and authentication details.

See the following resources for more information:

  • To learn more about access logs, see Using the access log to monitor agent activity.
  • For more information on creating webhooks in Zendesk, see Creating webhooks to interact with third-party systems.
  • For a description of the access log event data sent to your webhook endpoint, see Access log events in the developer docs.

If you have feedback or questions related to this announcement, visit our community forum where we collect and manage customer product feedback. For general assistance with your Zendesk products, contact Zendesk Customer Support.

 

Powered by Zendesk