Sysdig receives the Authdog audit stream through the Sysdig Events API. Lidar still detects and triages inside Authdog. This channel copies the same events to the Sysdig region you already watch. Configuration belongs to one environment.

## Create the channel

In the [Authdog console](https://console.authdog.com):

1. Select the project and environment.
2. Open **Notifications > Channels**.
3. Select **Add Channel**.
4. Set **Channel Name** and **Channel Type** to **Sysdig**.
5. Paste a **Sysdig API Token**. This is the Secure or Monitor API token used for event ingestion.
6. Set **Region** to the SaaS region your account uses. The default is **US East (us1)**. Other regions are **US West (us2)**, **US4 (GCP)**, **EU (eu1)**, **AU (au1)**, and **India (in1)**.
7. Optionally set **Source** and comma-separated **Tags** (`key:value`, for example `team:security,product:authdog`).
8. Choose the event triggers. Leave the event list empty to drain every event. Build a narrower list from the [event catalog](/docs/events-webhooks).
9. Save, then send a test delivery.

The API token is stored as a secret. Later edits show it as redacted. Select **Change** only when you are replacing it.

## What lands in Sysdig

Deliveries use the Sysdig API token, not the `X-Authdog-Signature` header used by generic webhooks. A `2xx` from Sysdig is success. Failures retry with exponential backoff, starting at 60 seconds, for at most five attempts. Inspect delivery records if a test does not appear.

A token from the wrong region is rejected. Match **Region** to the account you copied the token from.

This is log intake, not a Lidar detector. Signals stay in the console under **Lidar**.

## Test it

1. Trigger a sign-in in the same environment.
2. Search Sysdig events for the source or tags you set.
3. Confirm a failed destination shows up in delivery records, then recovers after Sysdig accepts the retry.

Repeat the channel in production with a production token. Channels do not copy between environments.

## Related

| Read | To learn how to |
| --- | --- |
| [Events and webhooks](/docs/events-webhooks) | Channel fields, retries, and the event catalog |
| [Datadog](/marketplace/datadog/setup) | The same stream, sent to Datadog |
| [Marketplace](/marketplace/sysdig) | The listing for this integration |
