Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Reference: audit line vocabulary

Each audit line is an event of the audit target, one JSON line per event. Reading and filtering the trail: Audit. What an error means and where to fix it: Troubleshooting.

Actions

actionsourceWritten when
listsftp, apilisting of a directory
downloadsftp, apiend of the transfer
uploadsftp, apiend of the transfer
mkdirsftp, apione line per directory created, from outermost to innermost
deletesftp, apiSFTP REMOVE of a file; REST DELETE of a file or an empty directory
rmdirsftpRMDIR of an empty directory
delete_recursiveapiDELETE of a non-empty directory
rmdir_recursivesftpRMDIR of a non-empty directory
renamesftp, apirename or move
statsftp, apirefusals only; REST HEAD
setstatsftprefusals only
requestapirequest refused before the handler with no route for its method, or GET ?rights
connection_acceptedsftp, api, adminsuccessful authentication: one per SFTP session, one per REST request, one per 15 min admin window
connection_rejectedsftp, api, adminrefused authentication
connection_rejected_summarysftp, api, adminrepeated anonymous refusals, summarized at the end of the window
ip_bannedsftp, api, adminan address is banned, once per switch
session_endsftpan SFTP session leaves the registry
session_kickadminDELETE /admin/sessions/{id}
unbanadminDELETE /admin/bans/{protocol}/{ip}
logoutadminPOST /admin/logout under a JWT or the static token: nothing is revoked
session_revokeadminPOST /admin/revocations, POST /admin/logout under a session token: username the revoked account, admin the author
grant_add, grant_revokeadminPOST /admin/grants, DELETE /admin/grants/{id}: username the beneficiary, role, grant_id, until, grant_reason (the reason given), lift
audit_readadminreading of the trail by the console or its stream
get_status, get_config, get_resources, list_sessions, session_roles, logs_status, get_logs, events, stream_logs, list_bans, list_grants, grant_candidatesadmininsufficient permission refusal of a read route

Results

resultMeaning
successthe operation succeeded
deniedthe server refused it
errorthe storage made it fail, or nothing could be built for it, or it was interrupted
unknownthe server does not know what became of it (interrupted commit)

Fields

FieldLinesMeaning
sourceallthe door: sftp, api, admin; for ip_banned, the ban list
action, resultallabove
reasondenied, error, unknown; absent on successa fixed string, below
usernameall except summariesthe name presented; empty for an unverified token
remote_addrallthe client IP; with the port on SFTP connection_accepted and session_end
session_idSFTP operations, session_end, session_kickthe session identifier
pathoperationsthe path as the user sees it; the source of a rename
new_pathrenamethe destination
backendoperationsthe name of the mount’s backend; "" on a synthetic path
countupload, download, listbytes transferred, or entries listed; 0 elsewhere
replaceduploadyes, no, unknown: did the upload destroy existing content
removeddelete_recursive, rmdir_recursiveentries removed; unknown on a local backend
took_overuploadthe stalled upload of the same account that this one took over: its SFTP session_id, or its REST transfer_id; "" elsewhere
transfer_idREST uploadthe transfer identifier, the one the console shows; "" elsewhere
grant_idoperationsthe temporary access that brought the mount of the path (several: comma-separated); "" elsewhere
auth_methodconnection_*SFTP password, pubkey, jwt; API basic, bearer, ticket; admin jwt, static_token, session, password (console sign-in); none without credential
signature_algorithmSFTP connection_acceptedalgorithm of the key’s signature
suppressed, threshold, window_secs, overflowconnection_rejected_summaryrefusals not written, and the window settings
ban_duration_secs, expires_at_epochip_bannedduration and end of the ban
duration_secs, bytes_read, bytes_writtensession_endduration and volume of the session
admin, admin_addr, admin_auth_methodadmin actionsthe author
kicked_bysession_kickthe author of the kick
protocol, liftunbanthe list (sftp, api, admin); held, local_only, overruled, not_banned
liftsession_revokeheld, local_only
permissioninsufficient permission refusalsthe missing permission
lines, levels, since, until, q, fieldsaudit_readthe read performed; lines = 0 for a stream

A field that does not apply is empty ("", 0), not absent. No line carries a password, a token or the text of a storage error: that text goes to the application log, alongside.

reason values

File operations:

reasonresultMeaning
acldeniedthe ACL does not grant the right
acl subtreedenieddeletion of a tree that the ACL does not fully cover
synthetic pathdeniedwrite on a synthetic directory or a mount point
rename across mountsdeniedsource and destination under two mounts
invalid pathdeniedcontrol character, \, forbidden Windows form
reserved namedeniedname the server reserves for itself (upload lock)
rename into restricteddeniedrename that would drop content without write
range not satisfiabledeniedREST download whose Range starts after the end of the file (416)
symlink escapedeniedsymbolic link outside the local root
existsdeniedexisting destination, or exclusive creation on a taken name
is a directory, not a directorydeniedREMOVE of a directory, RMDIR of a file
upload in progressdenied, erroranother upload holds the destination
taken overerrorstalled upload taken over by a new upload of the same account (uploads.takeover_idle_secs)
quota exceeded (and , truncated file removed, , append not undone)deniedmax_file_mb exceeded
session killeddeniedsession cut during the operation
no roles, username not usable as home directorydeniedREST: no role, unusable name
role resolution, mount conflicterrorREST: roles not resolved, conflicting mounts
not found, permission denied, already exists, not a directory, is a directory, directory not empty, storage error, not implemented, unsupported, upload in progresserrorkind of the storage error
session ended: <cause>errorSFTP session ended during the operation; <cause> is the reason of the session_end
session endederrorREST client left during the request
upload idle timeout, upload below minimum rateerrorupload cut by the server
commit interruptedunknownclient left while an upload was being published

Authentication (connection_rejected, connection_rejected_summary):

reasonresultMeaning
absentdeniedwrong password, unknown name, SFTP key or JWT refused: nothing tells which accounts exist
no authorized key offereddeniedno offered key was authorized
signature algorithm not alloweddeniedsignature algorithm of the key not allowed
missing credential, empty credential, malformed credentialdeniedAuthorization header absent, empty, unreadable
invalid token, expired token, wrong issuer, wrong audiencedeniedtoken refused by the verifier
verifier unavailabledenied, errorno key matching the token, or nothing to verify it
no username claimdeniedverified token without a name
method disableddeniedauthentication method turned off
no matching roles, no matching admin rolesdeniedcredential accepted, no role
role resolution, mount conflict, backend initialization failederrorcredential accepted, session impossible to build
username not usable as home directorydeniedthe name cannot be a directory
session limitdeniedmax_sessions_per_user reached
banned, rate limitdeniedaddress banned, rate exceeded
password checks saturated, password checks saturated for address, shutting downerrorpassword not verified: pool full, address share reached, shutdown
invalid ticket, expired ticket, revoked ticketdenieddownload ticket refused
revoked tokendeniedadmin console session token whose account was removed or changed its password, or was revoked

Session end (session_end): closed, connection_ended, admin_kick, shutdown_idle, shutdown, banned, internal_error, grant_expired, grant_revoked (a temporary access that the connection used has ended: grant_id names it; a REST transfer cut this way says session ended: grant_expired or grant_revoked).

Admin actions: insufficient permission, session not found, no sessions, not banned, overruled, unknown protocol, invalid IP address, no ban manager.