Uploaded image for project: 'Observability Documentation'
  1. Observability Documentation
  2. OBSDOCS-2537

Clarify why audit logs are not shown in installation examples for Logging 6.x

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • Logging 6.0, Logging 6.1, Logging 6.2, Logging 6.3, logging 6.4
    • Logging
    • False
    • Hide

      None

      Show
      None
    • False

      Both sections:

      1.2.2. Installing Red Hat OpenShift Logging Operator by using the CLI

      1.3.2. Installing Red Hat OpenShift Logging Operator by using the web console 

      show configuration examples that assign the necessary permissions to the service account for the collector to be able to collect and forward logs. In the examples, the collector is provided permissions to collect from both infrastructure and application logs, but not from audit logs.

      This is apparently confusing for the inexperienced user who reads the documentation, because Logging provides also audit among the built-in input types.

      The documentation in a different section describes how to define a ClusterRole that grants permissions to create audit logs in the Loki logging system. However in the installation examples the docs should explain why only infrastructure and application logs are considered by default. 

      This probably has to do with how the audit logs were handled in the previous Logging 5.x versions:
      Audit logs are not forwarded to the internal log store by default because this does not provide secure storage. You are responsible for ensuring that the system to which you forward audit logs is compliant with your organizational and governmental regulations, and is properly secured.

       

      This documentation bug is created to make sure that the new Logging 6.x documentation explains the rationale behind not having audit logs collected and stored by default in the Loki storage. The user should be warned that storing audit logs in the internal log store is not recommended, but should be given the opportunity to do so if they want by pointers to the relevant configuration sections.

              Unassigned Unassigned
              fminafra-redhat Francesco Minafra
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: