Reference: audit line vocabulary
Each audit line is an event of the audit target, one JSON line per event.
Reading and filtering the trail: Audit. What an error
means and where to fix it: Troubleshooting.
Actions
action | source | Written when |
|---|---|---|
list | sftp, api | listing of a directory |
download | sftp, api | end of the transfer |
upload | sftp, api | end of the transfer |
mkdir | sftp, api | one line per directory created, from outermost to innermost |
delete | sftp, api | SFTP REMOVE of a file; REST DELETE of a file or an empty directory |
rmdir | sftp | RMDIR of an empty directory |
delete_recursive | api | DELETE of a non-empty directory |
rmdir_recursive | sftp | RMDIR of a non-empty directory |
rename | sftp, api | rename or move |
stat | sftp, api | refusals only; REST HEAD |
setstat | sftp | refusals only |
request | api | request refused before the handler with no route for its method, or GET ?rights |
connection_accepted | sftp, api, admin | successful authentication: one per SFTP session, one per REST request, one per 15 min admin window |
connection_rejected | sftp, api, admin | refused authentication |
connection_rejected_summary | sftp, api, admin | repeated anonymous refusals, summarized at the end of the window |
ip_banned | sftp, api, admin | an address is banned, once per switch |
session_end | sftp | an SFTP session leaves the registry |
session_kick | admin | DELETE /admin/sessions/{id} |
unban | admin | DELETE /admin/bans/{protocol}/{ip} |
logout | admin | POST /admin/logout under a JWT or the static token: nothing is revoked |
session_revoke | admin | POST /admin/revocations, POST /admin/logout under a session token: username the revoked account, admin the author |
grant_add, grant_revoke | admin | POST /admin/grants, DELETE /admin/grants/{id}: username the beneficiary, role, grant_id, until, grant_reason (the reason given), lift |
audit_read | admin | reading of the trail by the console or its stream |
get_status, get_config, get_resources, list_sessions, session_roles, logs_status, get_logs, events, stream_logs, list_bans, list_grants, grant_candidates | admin | insufficient permission refusal of a read route |
Results
result | Meaning |
|---|---|
success | the operation succeeded |
denied | the server refused it |
error | the storage made it fail, or nothing could be built for it, or it was interrupted |
unknown | the server does not know what became of it (interrupted commit) |
Fields
| Field | Lines | Meaning |
|---|---|---|
source | all | the door: sftp, api, admin; for ip_banned, the ban list |
action, result | all | above |
reason | denied, error, unknown; absent on success | a fixed string, below |
username | all except summaries | the name presented; empty for an unverified token |
remote_addr | all | the client IP; with the port on SFTP connection_accepted and session_end |
session_id | SFTP operations, session_end, session_kick | the session identifier |
path | operations | the path as the user sees it; the source of a rename |
new_path | rename | the destination |
backend | operations | the name of the mount’s backend; "" on a synthetic path |
count | upload, download, list | bytes transferred, or entries listed; 0 elsewhere |
replaced | upload | yes, no, unknown: did the upload destroy existing content |
removed | delete_recursive, rmdir_recursive | entries removed; unknown on a local backend |
took_over | upload | the stalled upload of the same account that this one took over: its SFTP session_id, or its REST transfer_id; "" elsewhere |
transfer_id | REST upload | the transfer identifier, the one the console shows; "" elsewhere |
grant_id | operations | the temporary access that brought the mount of the path (several: comma-separated); "" elsewhere |
auth_method | connection_* | SFTP password, pubkey, jwt; API basic, bearer, ticket; admin jwt, static_token, session, password (console sign-in); none without credential |
signature_algorithm | SFTP connection_accepted | algorithm of the key’s signature |
suppressed, threshold, window_secs, overflow | connection_rejected_summary | refusals not written, and the window settings |
ban_duration_secs, expires_at_epoch | ip_banned | duration and end of the ban |
duration_secs, bytes_read, bytes_written | session_end | duration and volume of the session |
admin, admin_addr, admin_auth_method | admin actions | the author |
kicked_by | session_kick | the author of the kick |
protocol, lift | unban | the list (sftp, api, admin); held, local_only, overruled, not_banned |
lift | session_revoke | held, local_only |
permission | insufficient permission refusals | the missing permission |
lines, levels, since, until, q, fields | audit_read | the read performed; lines = 0 for a stream |
A field that does not apply is empty ("", 0), not absent. No line carries
a password, a token or the text of a storage error: that text goes to the
application log, alongside.
reason values
File operations:
reason | result | Meaning |
|---|---|---|
acl | denied | the ACL does not grant the right |
acl subtree | denied | deletion of a tree that the ACL does not fully cover |
synthetic path | denied | write on a synthetic directory or a mount point |
rename across mounts | denied | source and destination under two mounts |
invalid path | denied | control character, \, forbidden Windows form |
reserved name | denied | name the server reserves for itself (upload lock) |
rename into restricted | denied | rename that would drop content without write |
range not satisfiable | denied | REST download whose Range starts after the end of the file (416) |
symlink escape | denied | symbolic link outside the local root |
exists | denied | existing destination, or exclusive creation on a taken name |
is a directory, not a directory | denied | REMOVE of a directory, RMDIR of a file |
upload in progress | denied, error | another upload holds the destination |
taken over | error | stalled upload taken over by a new upload of the same account (uploads.takeover_idle_secs) |
quota exceeded (and , truncated file removed, , append not undone) | denied | max_file_mb exceeded |
session killed | denied | session cut during the operation |
no roles, username not usable as home directory | denied | REST: no role, unusable name |
role resolution, mount conflict | error | REST: roles not resolved, conflicting mounts |
not found, permission denied, already exists, not a directory, is a directory, directory not empty, storage error, not implemented, unsupported, upload in progress | error | kind of the storage error |
session ended: <cause> | error | SFTP session ended during the operation; <cause> is the reason of the session_end |
session ended | error | REST client left during the request |
upload idle timeout, upload below minimum rate | error | upload cut by the server |
commit interrupted | unknown | client left while an upload was being published |
Authentication (connection_rejected, connection_rejected_summary):
reason | result | Meaning |
|---|---|---|
| absent | denied | wrong password, unknown name, SFTP key or JWT refused: nothing tells which accounts exist |
no authorized key offered | denied | no offered key was authorized |
signature algorithm not allowed | denied | signature algorithm of the key not allowed |
missing credential, empty credential, malformed credential | denied | Authorization header absent, empty, unreadable |
invalid token, expired token, wrong issuer, wrong audience | denied | token refused by the verifier |
verifier unavailable | denied, error | no key matching the token, or nothing to verify it |
no username claim | denied | verified token without a name |
method disabled | denied | authentication method turned off |
no matching roles, no matching admin roles | denied | credential accepted, no role |
role resolution, mount conflict, backend initialization failed | error | credential accepted, session impossible to build |
username not usable as home directory | denied | the name cannot be a directory |
session limit | denied | max_sessions_per_user reached |
banned, rate limit | denied | address banned, rate exceeded |
password checks saturated, password checks saturated for address, shutting down | error | password not verified: pool full, address share reached, shutdown |
invalid ticket, expired ticket, revoked ticket | denied | download ticket refused |
revoked token | denied | admin console session token whose account was removed or changed its password, or was revoked |
Session end (session_end): closed, connection_ended, admin_kick,
shutdown_idle, shutdown, banned, internal_error, grant_expired,
grant_revoked (a temporary access that the connection used has ended:
grant_id names it; a REST transfer cut this way says
session ended: grant_expired or grant_revoked).
Admin actions: insufficient permission, session not found, no sessions,
not banned, overruled, unknown protocol, invalid IP address,
no ban manager.