Files
supabase/apps/docs/pages/guides/database/extensions/pgaudit.mdx
T
Greg Richardson 98c4103463 Docs: Switch tabs using query param (#17626)
* feat: switch tabs using url hash

* feat: switch tabs using query param
2023-09-22 11:29:25 -06:00

107 lines
3.0 KiB
Plaintext

import Layout from '~/layouts/DefaultGuideLayout'
export const meta = {
id: 'pgaudit',
title: 'PGAudit: Postgres Auditing',
description: 'Session and object auditing via PostgreSQL standard logging',
}
[PGAudit](https://www.pgaudit.org) is a PostgreSQL extension for logging session and object auditing over the standard PostgreSQL logging utility.
PGAudit grants fine grain control over which statements and objects are emitted to logs.
## Enable the extension
<Tabs
scrollable
size="small"
type="underlined"
defaultActiveId="dashboard"
queryGroup="database-method"
>
<TabPanel id="dashboard" label="Dashboard">
1. Go to the [Database](https://supabase.com/dashboard/project/_/database/tables) page in the Dashboard.
2. Click on **Extensions** in the sidebar.
3. Search for "pgaudit" and enable the extension.
</TabPanel>
<TabPanel id="sql" label="SQL">
{/* prettier-ignore */}
```sql
-- Enable the "pgaudit" extension
create extension pgaudit;
-- Disable the "pgaudit" extension
drop extension if exists pgaudit;
```
Even though the SQL code is `create extension`, this is the equivalent of "enabling the extension".
To disable an extension you can call `drop extension`.
</TabPanel>
</Tabs>
## Settings
The `pgaudit.log` setting controls which statements to log. Available values include:
- **read**: `SELECT` and `COPY` when the source is a relation or a query.
- **write**: `INSERT`, `UPDATE`, `DELETE`, `TRUNCATE`, and `COPY` when the destination is a relation.
- **function**: Function calls and `DO` blocks.
- **role**: Statements related to roles and privileges: `GRANT`, `REVOKE`, `CREATE/ALTER/DROP ROLE`.
- **ddl**: All `DDL` that is not included in the `ROLE` class.
- **misc**: Miscellaneous commands, e.g. `DISCARD`, `FETCH`, `CHECKPOINT`, `VACUUM`, `SET`.
- **misc_set**: Miscellaneous `SET` commands, e.g. `SET ROLE`.
- **all**: Include all of the above.
For a full list of available settings see [settings docs](https://github.com/pgaudit/pgaudit/blob/master/README.md#settings). Be aware that the `all` setting will generate a very large volume of logs.
## Example
Given a pgaudit setting
{/* prettier-ignore */}
```sql
set pgaudit.log = 'read, ddl';
```
The following create table, insert and select statements
{/* prettier-ignore */}
```sql
create table account (
id int primary key,
name text,
description text
);
insert into account (id, name, description)
values (1, 'Foo Barsworth', 'Customer account');
select * from account;
```
Results in the log output
```text
AUDIT: SESSION,1,1,DDL,CREATE TABLE,TABLE,public.account,create table account(
id int,
name text,
description text
);,<not logged>
AUDIT: SESSION,2,1,READ,SELECT,,,select * from account,,<not logged>
```
Note that the insert statement is not logged because we did not include the `write` option for `pgaudit.log`.
## Resources
- Official [`PGAudit` documentation](https://www.pgaudit.org)
export const Page = ({ children }) => <Layout meta={meta} children={children} />
export default Page