Skip to content

Filter audit logs for transport layer authentication #32470

@joshbressers

Description

@joshbressers

Today we have the ability for the audit log to record all authentication successes including authentication success on the REST and transport layer. There are use cases where we see a large number of authentication messages being logged due to transport layer authentication. These messages cannot be filtered today without disabling the filtering of all authentication success events.

Disabling all authentication success events isn't a reasonable solution. A possible option is to allow the filtering of transport authentication messages.

There are of course drawbacks to filtering transport authentication messages, it could give an attacker a way to view cluster data without leaving any log messages.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions