opensearch-project / opensearch-project/security
[RFC] Opinion on audit logging default operation and settings
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 252
- Forks
- 395
- Avg merge
- 1d 11h
- Merged PRs (30d)
- 76
Description
I have been just testing a very basic setup with OpenSearch and Dashboards 2.19.1 (installed with the K8s operator).
After a bit of testing, I curiously looked into the automatically created security-auditlog-* indices.
Here is just one sample document from it:
{
"_index": "security-auditlog-2025.04.19",
"_id": "7vmmT5YBxGRgQgSnK05S",
"_version": 1,
"_score": null,
"_source": {
"audit_trace_task_parent_id": "s2jaO-lOTX-YikWiP6O9Kg:85470",
"audit_cluster_name": "main-cluster",
"audit_transport_headers": {
"_opendistro_security_remote_address_header": "rO0ABXNyABpqYXZhLm5ldC5JbmV0U29ja2V0QWRkcmVzc0ZxlGFv+apFAwADSQAEcG9ydEwABGFkZHJ0ABZMamF2YS9uZXQvSW5ldEFkZHJlc3M7TAAIaG9zdG5hbWV0ABJMamF2YS9sYW5nL1N0cmluZzt4cgAWamF2YS5uZXQuU29ja2V0QWRkcmVzc0hh9mL0l51qAgAAeHAAAJCMc3IAFGphdmEubmV0LkluZXRBZGRyZXNzLZtXr5/j69sDAANJAAdhZGRyZXNzSQAGZmFtaWx5TAAIaG9zdE5hbWVxAH4AAnhwCvQABwAAAAJweHB4",
"_opendistro_security_initial_action_class_header": "IndexRequest",
"_opendistro_security_origin_header": "REST",
"_opendistro_security_user_header": "rO0ABXNyACFvcmcub3BlbnNlYXJjaC5zZWN1cml0eS51c2VyLlVzZXKzqL2T65dH3AIABloACmlzSW5qZWN0ZWRMAAphdHRyaWJ1dGVzdAAPTGphdmEvdXRpbC9NYXA7TAAEbmFtZXQAEkxqYXZhL2xhbmcvU3RyaW5nO0wAD3JlcXVlc3RlZFRlbmFudHEAfgACTAAFcm9sZXN0AA9MamF2YS91dGlsL1NldDtMAA1zZWN1cml0eVJvbGVzcQB+AAN4cABzcgAlamF2YS51dGlsLkNvbGxlY3Rpb25zJFN5bmNocm9uaXplZE1hcBtz+QlLSzl7AwACTAABbXEAfgABTAAFbXV0ZXh0ABJMamF2YS9sYW5nL09iamVjdDt4cHNyABFqYXZhLnV0aWwuSGFzaE1hcAUH2sHDFmDRAwACRgAKbG9hZEZhY3RvckkACXRocmVzaG9sZHhwP0AAAAAAAAB3CAAAABAAAAAAeHEAfgAHeHQABG5pbHNwc3IAJWphdmEudXRpbC5Db2xsZWN0aW9ucyRTeW5jaHJvbml6ZWRTZXQGw8J5Au7fPAIAAHhyACxqYXZhLnV0aWwuQ29sbGVjdGlvbnMkU3luY2hyb25pemVkQ29sbGVjdGlvbiph+E0JnJm1AwACTAABY3QAFkxqYXZhL3V0aWwvQ29sbGVjdGlvbjtMAAVtdXRleHEAfgAGeHBzcgARamF2YS51dGlsLkhhc2hTZXS6RIWVlri3NAMAAHhwdwwAAAAQP0AAAAAAAAB4cQB+AA54c3EAfgALc3EAfgAPdwwAAAAQP0AAAAAAAAJ0AAtraWJhbmFfdXNlcnQAC2Jyb2tlbl9yb2xleHEAfgAReA==",
"X-Opaque-Id": "344e512b-ff59-4245-9fa6-eac51a1c95f8",
"_opendistro_security_remotecn": "main-cluster"
},
"audit_node_name": "main-cluster-masters-0",
"audit_trace_task_id": "M8feAKKKSg-8IQ6qxtr64w:136146",
"audit_transport_request_type": "PutMappingRequest",
"audit_category": "INDEX_EVENT",
"audit_request_origin": "REST",
"audit_request_body": "{\"_doc\":{\"dynamic\":\"strict\",\"_meta\":{\"migrationMappingPropertyHashes\":{\"augment-vis\":\"88f930f6b43c089a12bfc276c359d1eb\",\"application_usage_daily\":\"43b8830d5d0df85a6823d290885fc9fd\",\"visualization\":\"f819cf6636b75c9e76ba733a0c6ef355\",\"observability-search\":\"638ae3ab28e5faf2e02f00dd8091abaf\",\"references\":\"7997cf5a56cc02bdc9c93361bde732b0\",\"integration-template\":\"9033ba0b281fe1c88c3c56d8fd9d089d\",\"type\":\"2f4316de49999235636386fe51dc06c1\",\"sample-data-telemetry\":\"7d3cfeb915303c9641c59681967ffeb4\",\"search\":\"43012c7ebc4cb57054e0a490e4b43023\",\"originId\":\"2f4316de49999235636386fe51dc06c1\",\"application_usage_totals\":\"3d1b76c39bfb2cc8296b024d73854724\",\"updated_at\":\"00da57df13e94e9d98437d13ace4bfe0\",\"dql-telemetry\":\"d12a98a6f19a2d273696597547e064ee\",\"search-telemetry\":\"3d1b76c39bfb2cc8296b024d73854724\",\"integration-instance\":\"17ab914d1f92a5b03bbb194651c23b1c\",\"observability-panel\":\"df07b1a361c32daf4e6842c1d5521dbe\",\"visualization-visbuilder\":\"7a6fadcdaaf97b2b8b65d290fd8a3ba7\",\"map\":\"32fcfaba6c580bf048359fcb48ad5301\",\"dashboard\":\"40554caf09725935e2c02e02563a2d07\",\"query\":\"531cf50c8e0b1c9f610e263f878d124c\",\"ui-metric\":\"0d409297dc5ebe1e3a1da691c6ee32e3\",\"application_usage_transactional\":\"3d1b76c39bfb2cc8296b024d73854724\",\"observability-visualization\":\"638ae3ab28e5faf2e02f00dd8091abaf\",\"url\":\"c7f66a0df8b1b52f17c28c4adb111105\",\"migrationVersion\":\"4a1746014a75ade3a714e1db5763276f\",\"index-pattern\":\"45915a1ad866812242df474eb0479052\",\"namespace\":\"2f4316de49999235636386fe51dc06c1\",\"observability-notebook\":\"638ae3ab28e5faf2e02f00dd8091abaf\",\"config\":\"c63748b75f39d0c54de12d12c1ccbc20\",\"tsvb-validation-telemetry\":\"3a37ef6c8700ae6fc97d5c7da00e9215\",\"namespaces\":\"2f4316de49999235636386fe51dc06c1\",\"homepage\":\"a8d79cfe4f79546aa5bbee73facc51dc\"}},\"properties\":{\"migrationVersion\":{\"dynamic\":\"true\",\"properties\":{\"observability-panel\":{\"type\":\"text\",\"fields\":{\"keyword\":{\"type\":\"keyword\",\"ignore_above\":256}}}}}}}}",
"audit_node_id": "M8feAKKKSg-8IQ6qxtr64w",
"audit_request_layer": "TRANSPORT",
"@timestamp": "2025-04-19T20:03:32.304+00:00",
"audit_format_version": 4,
"audit_request_remote_address": "10.244.0.7",
"audit_request_privilege": "indices:admin/mapping/auto_put",
"audit_node_host_address": "10.244.0.50",
"audit_request_effective_user": "nils",
"audit_trace_resolved_indices": [
".kibana_1"
],
"audit_node_host_name": "main-cluster-masters-0"
},
"fields": {
"@timestamp": [
"2025-04-19T20:03:32.304Z"
]
},
"sort": [
1745093012304
]
}
Comments:
- Logging the values of
_opendistro_security_remote_address_headerand_opendistro_security_user_headerdoes not make a lot of sense to me. These are the base64 encoded serialized forms of the Java objectsUserandTransportAddress. For the wide majority of use cases, these will be not helpful. Rather, logging such large base64 encoded strings seems wasteful, it blows up index size and has a performance impact. - This seems to be logging the request body for all
indices:admin/*related request, which in this case is also is an auto-generated mapping which is of large volume, but at the same time of little use. - On a high level, I am even wondering whether it makes sense to enable audit logging by default. I would guess that a significant amound of users are not aware that it is enabled by default and logs such large amounts of data.
Request for comments
What are other user's opinions on the default configuration of audit logging?
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
The issue names no source files, tests, or entry points. Begin by locating the audit-logging configuration and default settings in the security plugin, then compare the documented behavior with the sample audit records. Done means a maintainer-approved decision on audit defaults, request-body logging, and serialized header fields.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100