For the complete documentation index, see llms.txt. This page is also available as Markdown.

Cursor Logs (Beta)

Connecting Cursor logs to your Panther Console

Overview

Cursor Audit log ingestion is in open beta starting with Panther version 1.126, and is available to all customers. Please share any bug reports and feature requests with your Panther support team.

Panther supports ingesting Cursor logs by configuring a Cursor webhook to post events to an HTTP endpoint in Panther.

How to onboard Cursor logs to Panther

Prerequisites

  • An active Cursor Enterprise subscription with administrative access

Step 1: Create a new Cursor source in Panther

  1. In the left-side navigation bar of your Panther Console, click Log Sources.

  2. Click Create New.

  3. Search for “Cursor” then click its tile.

  4. In the upper-right corner, click Start Setup.

  5. Follow Panther's instructions for configuring an HTTP Source, beginning at Step 5.

    • When setting the Auth method, you will be required to use Bearer.

    • Payloads sent to this source are subject to the payload requirements for all HTTP sources.

    • Do not proceed to the next step until the creation of your HTTP endpoint has completed.

Step 2: Enable Streaming Audit Logs in Cursor

Once your Panther HTTP endpoint is ready, contact the Cursor support team at hi@cursor.com from an administrative email address and request activation of streaming audit logs for your account.

Include the following information in your request:

  1. Your Enterprise team information (team name or admin contact)

  2. Your Panther HTTP webhook URL (from Step 1)

  3. Your Bearer token value used in Panther configuration (you can use whichever secure method your team prefers, for example, a password manager share link or an encrypted file).

Once Cursor support confirms that streaming has been enabled, return to your Panther Console and verify that audit log events are being received successfully.

Supported log types

Cursor.Audit

Audit logs provide a record of security events and administrative actions that can help you meet compliance requirements and investigate security incidents.

For more information, see the Cursor Compliance and Monitoring page.

Last updated

Was this helpful?