Understanding Slack Plans and Log Types in Panther

Last updated: October 1, 2025

QUESTION

Why can't I add additional schemas to my existing Slack log source, and what's the difference between Slack audit logs versus access and integration logs?

ANSWER

The available Slack schemas in Panther are determined by your Slack plan type:

  • Enterprise Grid Plan: Only supports Slack.AuditLogs schema. You cannot add additional schemas to the Slack log sources with the Plan Enterprise Grid.

  • Standard/Plus Plan: Supports Slack.AccessLogs and/or Slack.IntegrationLogs schemas, which can be ingested through the same log source.

Important notes about Slack log types:

  • Audit logs must be ingested through a separate Slack log source

  • Audit logs are typically sufficient for most use cases, as they are a superset that contains all actions represented by access and integration logs

  • You cannot modify the Slack Plan of an existing Slack log source

For more detailed information about Slack log types and setup instructions, refer to our documentation: