mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 09:25:06 +03:00
107 lines
3.0 KiB
Plaintext
107 lines
3.0 KiB
Plaintext
import Layout from '~/layouts/DefaultGuideLayout'
|
|
|
|
export const meta = {
|
|
id: 'pgaudit',
|
|
title: 'PGAudit: Postgres Auditing',
|
|
description: 'Session and object auditing via PostgreSQL standard logging',
|
|
}
|
|
|
|
[PGAudit](https://www.pgaudit.org) is a PostgreSQL extension for logging session and object auditing over the standard PostgreSQL logging utility.
|
|
|
|
PGAudit grants fine grain control over which statements and objects are emitted to logs.
|
|
|
|
## Enable the extension
|
|
|
|
<Tabs
|
|
scrollable
|
|
size="small"
|
|
type="underlined"
|
|
defaultActiveId="dashboard"
|
|
queryGroup="database-method"
|
|
>
|
|
<TabPanel id="dashboard" label="Dashboard">
|
|
|
|
1. Go to the [Database](https://supabase.com/dashboard/project/_/database/tables) page in the Dashboard.
|
|
2. Click on **Extensions** in the sidebar.
|
|
3. Search for "pgaudit" and enable the extension.
|
|
|
|
</TabPanel>
|
|
<TabPanel id="sql" label="SQL">
|
|
|
|
{/* prettier-ignore */}
|
|
```sql
|
|
-- Enable the "pgaudit" extension
|
|
create extension pgaudit;
|
|
|
|
-- Disable the "pgaudit" extension
|
|
drop extension if exists pgaudit;
|
|
```
|
|
|
|
Even though the SQL code is `create extension`, this is the equivalent of "enabling the extension".
|
|
To disable an extension you can call `drop extension`.
|
|
|
|
</TabPanel>
|
|
</Tabs>
|
|
|
|
## Settings
|
|
|
|
The `pgaudit.log` setting controls which statements to log. Available values include:
|
|
|
|
- **read**: `SELECT` and `COPY` when the source is a relation or a query.
|
|
- **write**: `INSERT`, `UPDATE`, `DELETE`, `TRUNCATE`, and `COPY` when the destination is a relation.
|
|
- **function**: Function calls and `DO` blocks.
|
|
- **role**: Statements related to roles and privileges: `GRANT`, `REVOKE`, `CREATE/ALTER/DROP ROLE`.
|
|
- **ddl**: All `DDL` that is not included in the `ROLE` class.
|
|
- **misc**: Miscellaneous commands, e.g. `DISCARD`, `FETCH`, `CHECKPOINT`, `VACUUM`, `SET`.
|
|
- **misc_set**: Miscellaneous `SET` commands, e.g. `SET ROLE`.
|
|
|
|
- **all**: Include all of the above.
|
|
|
|
For a full list of available settings see [settings docs](https://github.com/pgaudit/pgaudit/blob/master/README.md#settings). Be aware that the `all` setting will generate a very large volume of logs.
|
|
|
|
## Example
|
|
|
|
Given a pgaudit setting
|
|
|
|
{/* prettier-ignore */}
|
|
```sql
|
|
set pgaudit.log = 'read, ddl';
|
|
```
|
|
|
|
The following create table, insert and select statements
|
|
|
|
{/* prettier-ignore */}
|
|
```sql
|
|
create table account (
|
|
id int primary key,
|
|
name text,
|
|
description text
|
|
);
|
|
|
|
insert into account (id, name, description)
|
|
values (1, 'Foo Barsworth', 'Customer account');
|
|
|
|
select * from account;
|
|
```
|
|
|
|
Results in the log output
|
|
|
|
```text
|
|
AUDIT: SESSION,1,1,DDL,CREATE TABLE,TABLE,public.account,create table account(
|
|
id int,
|
|
name text,
|
|
description text
|
|
);,<not logged>
|
|
AUDIT: SESSION,2,1,READ,SELECT,,,select * from account,,<not logged>
|
|
```
|
|
|
|
Note that the insert statement is not logged because we did not include the `write` option for `pgaudit.log`.
|
|
|
|
## Resources
|
|
|
|
- Official [`PGAudit` documentation](https://www.pgaudit.org)
|
|
|
|
export const Page = ({ children }) => <Layout meta={meta} children={children} />
|
|
|
|
export default Page
|