Understanding Slack Plans and Log Types in Panther
Last updated: October 1, 2025
QUESTION
Why can't I add additional schemas to my existing Slack log source, and what's the difference between Slack audit logs versus access and integration logs?
ANSWER
The available Slack schemas in Panther are determined by your Slack plan type:
Enterprise Grid Plan: Only supports Slack.AuditLogs schema. You cannot add additional schemas to the Slack log sources with the Plan Enterprise Grid.
Standard/Plus Plan: Supports Slack.AccessLogs and/or Slack.IntegrationLogs schemas, which can be ingested through the same log source.
Important notes about Slack log types:
Audit logs must be ingested through a separate Slack log source
Audit logs are typically sufficient for most use cases, as they are a superset that contains all actions represented by access and integration logs
You cannot modify the Slack Plan of an existing Slack log source
For more detailed information about Slack log types and setup instructions, refer to our documentation: