opensearch-project / opensearch-project/security

[RFC] Opinion on audit logging default operation and settings

Open
#5,282 3 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

triaged
Dominant language
Java
Stars
252
Forks
395
Avg merge
1d 11h
Merged PRs (30d)
76

Description

I have been just testing a very basic setup with OpenSearch and Dashboards 2.19.1 (installed with the K8s operator).

After a bit of testing, I curiously looked into the automatically created security-auditlog-* indices.

Here is just one sample document from it:

{
  "_index": "security-auditlog-2025.04.19",
  "_id": "7vmmT5YBxGRgQgSnK05S",
  "_version": 1,
  "_score": null,
  "_source": {
    "audit_trace_task_parent_id": "s2jaO-lOTX-YikWiP6O9Kg:85470",
    "audit_cluster_name": "main-cluster",
    "audit_transport_headers": {
      "_opendistro_security_remote_address_header": "rO0ABXNyABpqYXZhLm5ldC5JbmV0U29ja2V0QWRkcmVzc0ZxlGFv+apFAwADSQAEcG9ydEwABGFkZHJ0ABZMamF2YS9uZXQvSW5ldEFkZHJlc3M7TAAIaG9zdG5hbWV0ABJMamF2YS9sYW5nL1N0cmluZzt4cgAWamF2YS5uZXQuU29ja2V0QWRkcmVzc0hh9mL0l51qAgAAeHAAAJCMc3IAFGphdmEubmV0LkluZXRBZGRyZXNzLZtXr5/j69sDAANJAAdhZGRyZXNzSQAGZmFtaWx5TAAIaG9zdE5hbWVxAH4AAnhwCvQABwAAAAJweHB4",
      "_opendistro_security_initial_action_class_header": "IndexRequest",
      "_opendistro_security_origin_header": "REST",
      "_opendistro_security_user_header": "rO0ABXNyACFvcmcub3BlbnNlYXJjaC5zZWN1cml0eS51c2VyLlVzZXKzqL2T65dH3AIABloACmlzSW5qZWN0ZWRMAAphdHRyaWJ1dGVzdAAPTGphdmEvdXRpbC9NYXA7TAAEbmFtZXQAEkxqYXZhL2xhbmcvU3RyaW5nO0wAD3JlcXVlc3RlZFRlbmFudHEAfgACTAAFcm9sZXN0AA9MamF2YS91dGlsL1NldDtMAA1zZWN1cml0eVJvbGVzcQB+AAN4cABzcgAlamF2YS51dGlsLkNvbGxlY3Rpb25zJFN5bmNocm9uaXplZE1hcBtz+QlLSzl7AwACTAABbXEAfgABTAAFbXV0ZXh0ABJMamF2YS9sYW5nL09iamVjdDt4cHNyABFqYXZhLnV0aWwuSGFzaE1hcAUH2sHDFmDRAwACRgAKbG9hZEZhY3RvckkACXRocmVzaG9sZHhwP0AAAAAAAAB3CAAAABAAAAAAeHEAfgAHeHQABG5pbHNwc3IAJWphdmEudXRpbC5Db2xsZWN0aW9ucyRTeW5jaHJvbml6ZWRTZXQGw8J5Au7fPAIAAHhyACxqYXZhLnV0aWwuQ29sbGVjdGlvbnMkU3luY2hyb25pemVkQ29sbGVjdGlvbiph+E0JnJm1AwACTAABY3QAFkxqYXZhL3V0aWwvQ29sbGVjdGlvbjtMAAVtdXRleHEAfgAGeHBzcgARamF2YS51dGlsLkhhc2hTZXS6RIWVlri3NAMAAHhwdwwAAAAQP0AAAAAAAAB4cQB+AA54c3EAfgALc3EAfgAPdwwAAAAQP0AAAAAAAAJ0AAtraWJhbmFfdXNlcnQAC2Jyb2tlbl9yb2xleHEAfgAReA==",
      "X-Opaque-Id": "344e512b-ff59-4245-9fa6-eac51a1c95f8",
      "_opendistro_security_remotecn": "main-cluster"
    },
    "audit_node_name": "main-cluster-masters-0",
    "audit_trace_task_id": "M8feAKKKSg-8IQ6qxtr64w:136146",
    "audit_transport_request_type": "PutMappingRequest",
    "audit_category": "INDEX_EVENT",
    "audit_request_origin": "REST",
    "audit_request_body": "{\"_doc\":{\"dynamic\":\"strict\",\"_meta\":{\"migrationMappingPropertyHashes\":{\"augment-vis\":\"88f930f6b43c089a12bfc276c359d1eb\",\"application_usage_daily\":\"43b8830d5d0df85a6823d290885fc9fd\",\"visualization\":\"f819cf6636b75c9e76ba733a0c6ef355\",\"observability-search\":\"638ae3ab28e5faf2e02f00dd8091abaf\",\"references\":\"7997cf5a56cc02bdc9c93361bde732b0\",\"integration-template\":\"9033ba0b281fe1c88c3c56d8fd9d089d\",\"type\":\"2f4316de49999235636386fe51dc06c1\",\"sample-data-telemetry\":\"7d3cfeb915303c9641c59681967ffeb4\",\"search\":\"43012c7ebc4cb57054e0a490e4b43023\",\"originId\":\"2f4316de49999235636386fe51dc06c1\",\"application_usage_totals\":\"3d1b76c39bfb2cc8296b024d73854724\",\"updated_at\":\"00da57df13e94e9d98437d13ace4bfe0\",\"dql-telemetry\":\"d12a98a6f19a2d273696597547e064ee\",\"search-telemetry\":\"3d1b76c39bfb2cc8296b024d73854724\",\"integration-instance\":\"17ab914d1f92a5b03bbb194651c23b1c\",\"observability-panel\":\"df07b1a361c32daf4e6842c1d5521dbe\",\"visualization-visbuilder\":\"7a6fadcdaaf97b2b8b65d290fd8a3ba7\",\"map\":\"32fcfaba6c580bf048359fcb48ad5301\",\"dashboard\":\"40554caf09725935e2c02e02563a2d07\",\"query\":\"531cf50c8e0b1c9f610e263f878d124c\",\"ui-metric\":\"0d409297dc5ebe1e3a1da691c6ee32e3\",\"application_usage_transactional\":\"3d1b76c39bfb2cc8296b024d73854724\",\"observability-visualization\":\"638ae3ab28e5faf2e02f00dd8091abaf\",\"url\":\"c7f66a0df8b1b52f17c28c4adb111105\",\"migrationVersion\":\"4a1746014a75ade3a714e1db5763276f\",\"index-pattern\":\"45915a1ad866812242df474eb0479052\",\"namespace\":\"2f4316de49999235636386fe51dc06c1\",\"observability-notebook\":\"638ae3ab28e5faf2e02f00dd8091abaf\",\"config\":\"c63748b75f39d0c54de12d12c1ccbc20\",\"tsvb-validation-telemetry\":\"3a37ef6c8700ae6fc97d5c7da00e9215\",\"namespaces\":\"2f4316de49999235636386fe51dc06c1\",\"homepage\":\"a8d79cfe4f79546aa5bbee73facc51dc\"}},\"properties\":{\"migrationVersion\":{\"dynamic\":\"true\",\"properties\":{\"observability-panel\":{\"type\":\"text\",\"fields\":{\"keyword\":{\"type\":\"keyword\",\"ignore_above\":256}}}}}}}}",
    "audit_node_id": "M8feAKKKSg-8IQ6qxtr64w",
    "audit_request_layer": "TRANSPORT",
    "@timestamp": "2025-04-19T20:03:32.304+00:00",
    "audit_format_version": 4,
    "audit_request_remote_address": "10.244.0.7",
    "audit_request_privilege": "indices:admin/mapping/auto_put",
    "audit_node_host_address": "10.244.0.50",
    "audit_request_effective_user": "nils",
    "audit_trace_resolved_indices": [
      ".kibana_1"
    ],
    "audit_node_host_name": "main-cluster-masters-0"
  },
  "fields": {
    "@timestamp": [
      "2025-04-19T20:03:32.304Z"
    ]
  },
  "sort": [
    1745093012304
  ]
}

Comments:

  • Logging the values of _opendistro_security_remote_address_header and _opendistro_security_user_header does not make a lot of sense to me. These are the base64 encoded serialized forms of the Java objects User and TransportAddress. For the wide majority of use cases, these will be not helpful. Rather, logging such large base64 encoded strings seems wasteful, it blows up index size and has a performance impact.
  • This seems to be logging the request body for all indices:admin/* related request, which in this case is also is an auto-generated mapping which is of large volume, but at the same time of little use.
  • On a high level, I am even wondering whether it makes sense to enable audit logging by default. I would guess that a significant amound of users are not aware that it is enabled by default and logs such large amounts of data.

Request for comments

What are other user's opinions on the default configuration of audit logging?

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

The issue names no source files, tests, or entry points. Begin by locating the audit-logging configuration and default settings in the security plugin, then compare the documented behavior with the sample audit records. Done means a maintainer-approved decision on audit defaults, request-body logging, and serialized header fields.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.