---
title: "Update an audit log export destination"
method: PATCH
path: "/audit-logs/export/destinations/{id}"
tags: ["Audit Logs"]
---

# Update an audit log export destination

`PATCH /audit-logs/export/destinations/{id}`

Applies a partial update. Returns 409 when the destination was changed concurrently, because the merged configuration this request validated is no longer the one that would be stored; retry against fresh state. Pausing prevents new delivery attempts, but an S3 upload already in progress may complete after the response.

## Request body

- UpdateAuditLogExportDestinationRequest
  - `region` string
  - `bucket` string
  - `prefix` string
  - `role_arn` string
  - `kms_key_id` string — KMS key ID, alias, or ARN. Set to an empty string to remove the configured KMS key; omit or send null to leave unchanged.
  - `status` 'active' | 'paused'

## Response `200`

Audit log export destination updated

- AuditLogExportDestination — An organization-scoped audit log export destination. Delivery is at-least-once for rows visible when their window is committed: a delivery that is retried rewrites the same object, and the same `event_id` can appear in more than one object, so consumers must deduplicate on `event_id`. Each event-time window is held for ten minutes before it commits; a row that becomes visible after its window is committed may not be delivered. Objects are written as `<prefix>/destination_id=<destination>/org_id=<org>/date=<YYYY-MM-DD>/hour=<HH>/<window>-<chunk>.jsonl.gz`, where `date` and `hour` are the UTC calendar hour that fully contains every row in the object, so the layout is safe to register as a Hive-partitioned table. The object name is derived from the rows it holds, so a retried delivery rewrites its own object.
  - `id` string, required
  - `type` 's3', required
  - `region` string, required
  - `bucket` string, required
  - `prefix` string, required
  - `role_arn` string, required
  - `external_id` string, required
  - `kernel_role_arn` string, required — The Kernel role that assumes `role_arn` in your account to deliver logs. Allow this role as the principal in your role's trust policy, and require `external_id` as the `sts:ExternalId` condition. Recreating a destination issues a new `external_id`, which the trust policy has to be updated to match.
  - `kms_key_id` string
  - `format` 'jsonl.gz', required
  - `status` 'active' | 'paused', required — Pausing prevents new delivery attempts. An S3 upload already in progress may complete after the pause response; its rows can appear again after the destination is resumed.
  - `last_exported_cursor` string — Opaque, versioned checkpoint for forward-only continuous export. This value is not compatible with audit-log list page tokens. Delivery starts at the moment the destination is activated, so events recorded before that are not delivered. Pausing stops delivery and resuming starts again from the time of the resume: events recorded while a destination was paused are never exported, and pausing is not a way to defer delivery.
  - `last_success_at` string, date-time
  - `last_error` string — Sanitized description of the most recent delivery failure.
  - `last_error_at` string, date-time
  - `consecutive_failures` integer, required
  - `next_attempt_at` string, date-time
  - `created_at` string, date-time, required
  - `updated_at` string, date-time, required

## Other responses

- `400` — Bad Request – invalid input
- `401` — Unauthorized – missing or invalid authorization token
- `403` — Forbidden – insufficient permissions or plan
- `404` — Resource not found
- `409` — Conflict – resource already exists
- `500` — Internal Server Error

---

[API](https://skmtc.net/kernel/apis/kernel-api.md) · [All operations](https://skmtc.net/kernel/apis/kernel-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/kernel/kernel-api/versions/9e8ce9fcf5e1/schema)
