# Audit Logging via Firehose

Wallet-as-a-Service streams audit and access logs to an **AWS Data Firehose** delivery stream in your own AWS account, so you can route them to Amazon S3, a SIEM such as Splunk or Datadog, or any other destination Firehose supports.

You create the delivery stream and an IAM role that Ripple assumes to write to it, then enter the stream name, role ARN, and region in **Settings** > **Audit logs**. Wallet-as-a-Service uploads records in batches approximately every 15 seconds.

Where the details moved
The record format, IAM trust and permission policies, decode examples, and delivery guarantees now live in [Firehose audit log reference](/pt-br/products/wallet/admin-guide/firehose-audit-log-reference). For setting up and managing the connection, see [Configure audit logging](/pt-br/products/wallet/admin-guide/configure-audit-logging).

For the change to compressed payloads and the deprecation of `jsonData`, see [Transaction and wallet audit records, compressed payloads, and `jsonData` deprecation](/pt-br/products/wallet/changelogs/firehose-audit-payload-compression).