Audit Logging
Record every query, detect intrusions, maintain compliance!
๐ The Story: Sarah's Silent Data Theft
Sarah's company got breached. 10 million customer records stolen over 2 weeks. When investigators asked "Who accessed what?", Sarah had NO ANSWER. No audit logs = no evidence. Attacker walked free. $5M fine for "inadequate security". Could have been prevented with audit logging.
๐ฑ The Breach Without Evidence
Timeline of the Attack:
The Investigation:
The Consequences:
- ๐ฐ Regulatory Fine: $5M for inadequate security
- โ๏ธ No Prosecution: Insufficient evidence
- ๐ฐ Public Shame: "Company couldn't even tell who stole data"
- ๐ฅ Customer Lawsuits: Class action for $20M
- ๐ Stock Crash: 60% drop
- ๐ผ Sarah Fired: "Gross negligence"
โ What Audit Logging Would Have Shown
With Audit Logs Enabled:
The Better Outcome:
- ๐ Alert on Day 2: SIEM caught suspicious 3am access
- ๐ Stopped on Day 3: Blocked IP + disabled account
- ๐ Full Evidence: Every query logged
- โ๏ธ Prosecution: Attacker identified and convicted
- ๐ฐ Minimal Fine: Demonstrated "reasonable security"
- ๐ Sarah Promoted: "Excellent security response"
Audit logging: $0 cost, $25M+ saved! ๐
๐ฏ Why Audit Logging?
The business case for tracking everything!
Detect Intrusions
- Catch unauthorized access
- Identify compromised accounts
- Spot data exfiltration
- Alert on suspicious queries
- Track attack patterns
Stop breaches early!
Legal Compliance
- GDPR requires audit trails
- HIPAA mandates logging
- PCI-DSS requirement
- SOX compliance
- Prove due diligence
Avoid massive fines!
Forensic Investigation
- Reconstruct attacks
- Timeline of events
- Identify patient zero
- Scope of breach
- Evidence for prosecution
Answer "what happened?"
Insider Threats
- Track employee access
- Detect privilege abuse
- Prevent data theft
- Monitor admins
- Accountability
Trust but verify!
Troubleshooting
- Debug application issues
- Find slow queries
- Track schema changes
- Performance analysis
- User behavior patterns
Operational visibility!
Analytics
- Usage patterns
- Peak access times
- Most queried tables
- User activity trends
- Capacity planning
Business intelligence!
Cost of NOT Having Audit Logs
| Scenario | Without Logs | With Logs |
|---|---|---|
| Data Breach | No evidence, $5M fine | Full forensics, $0 fine |
| Insider Theft | Can't prove who, lawsuit lost | Prosecution successful |
| Compliance Audit | Failed, operations halted | Passed with evidence |
| Performance Issue | Days to find root cause | Minutes with query logs |
โ๏ธ Setting Up Audit Logging
Enable comprehensive logging in 5 minutes!
Enable Full Query Logging
Log every CQL statement
Configure Log Categories
Choose what to track
Set Up Log Rotation
Prevent disk from filling up
Disk Space Planning
Estimate audit log size:
๐ What Gets Logged?
Every audit log entry includes:
1. Timestamp (When)
2. User (Who)
3. Source IP (Where From)
4. Operation Type (What Category)
5. Full CQL Statement (What Exactly)
6. Result (Success/Failure)
Complete Audit Log Entry Example
๐ Reading Audit Logs
Tools to query and analyze logs!
Method 1: auditlogviewer (Built-in Tool)
Method 2: Direct Log Analysis
Method 3: Real-Time Monitoring
๐ Log Analysis & Security Monitoring
Detect attacks and suspicious behavior!
Common Security Queries
1. Find Failed Login Attempts
2. Detect Data Exfiltration
3. Track Schema Changes
4. Find Unusual Access Patterns
5. Detect Privilege Abuse
Automated Alert Script
โ๏ธ Compliance Requirements
Meet regulatory standards!
GDPR
- Article 32: Security audit logs
- Track personal data access
- Log data exports
- Record deletion requests
- Retain logs 6+ months
Or โฌ20M fine!
HIPAA
- ยง164.312: Audit controls
- Track PHI access
- Log all queries
- 6 year retention
- Regular audits
Or $1.5M penalty!
PCI-DSS
- Requirement 10: Track access
- Log cardholder data
- Daily log review
- 1 year retention
- Tamper-proof logs
Or lose cert!
SOX
- Section 404: Internal controls
- Track financial data
- Audit trail required
- 7 year retention
- Annual audits
Or criminal charges!
Compliance Checklist
| Requirement | How to Achieve | Verify |
|---|---|---|
| Log all access | included_categories: ALL | auditlogviewer shows entries |
| Retain logs | max_log_size: adequate | Logs exist for required period |
| Tamper-proof | Read-only filesystem, SIEM export | chmod 400 on log files |
| Regular review | Automated monitoring scripts | Weekly security reports |
| Access tracking | Log user + IP + timestamp | Full audit trail available |
๐ก Audit Logging Best Practices
Do it right!
DO
- Enable on ALL nodes
- Log ALL categories
- Export to SIEM
- Automate monitoring
- Test log rotation
- Secure log storage
- Regular audits
- Alert on anomalies
DON'T
- Skip audit logs
- Exclude important categories
- Let logs fill disk
- Forget to monitor
- Make logs writable
- Delete too soon
- Ignore alerts
- Manual-only review
Log Retention Guidelines
| Industry | Minimum Retention | Recommended |
|---|---|---|
| General | 30 days | 90 days |
| Financial (SOX) | 7 years | 7 years |
| Healthcare (HIPAA) | 6 years | 6 years |
| E-commerce (PCI-DSS) | 1 year | 2 years |
| EU (GDPR) | 6 months | 1 year |
Performance Impact
Audit logging has minimal overhead:
- ๐ Latency: +0.5-2ms per query (negligible)
- ๐พ Storage: ~500 bytes per query
- โก Throughput: <1% impact
- ๐ป CPU: <5% additional
The benefit far outweighs the cost!
๐ Master Audit Logging!
You now know how to track everything in Cassandra!
๐ What You Learned:
- ๐ Why audit: Detect breaches, compliance, forensics
- โ๏ธ Setup: Enable in cassandra.yaml (5 minutes!)
- ๐ What's logged: User, IP, timestamp, query, result
- ๐ Reading logs: auditlogviewer + analysis scripts
- ๐ Security monitoring: Detect attacks, data theft
- โ๏ธ Compliance: GDPR, HIPAA, PCI-DSS, SOX
- ๐ก Best practices: Export to SIEM, automate alerts
๐ก Key Takeaways:
- Enable immediately - Don't wait for a breach!
- Log everything - Query, DML, DDL, DCL, AUTH
- Monitor actively - Automated alerts on suspicious activity
- Retain properly - Meet compliance requirements
- Analyze regularly - Weekly security reviews
- Export to SIEM - Centralized security monitoring
๐ Quick Setup (5 Minutes):
๐จ Security Alerts to Implement:
- ๐ด Failed logins (> 5 per hour)
- ๐ด Large data exports (LIMIT > 10K)
- ๐ด DROP/ALTER commands
- ๐ก Off-hours access (midnight-6am)
- ๐ก Access from unknown IPs
- ๐ก Sensitive table queries
๐ Remember Sarah: No logs = No evidence = $5M fine!
Audit logging = Your security insurance policy! ๐ก๏ธ
๐ฑ Responsive Ad ๐ฑ