Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 12 additions & 8 deletions install_config/master_node_configuration.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -1162,28 +1162,32 @@ stamp encoded in their filename.
Defaults to 100MB.
|===

[IMPORTANT]
====
Because the {product-name} master API now runs as static pod, you must define
the `auditFilePath` location in the *_/var/lib/origin_*, *_/var/log/origin_*,
or *_/etc/origin/master/_* file.
====

.Example Audit Configuration
----
auditConfig:
auditFilePath: "/var/lib/origin/audit-ocp.log"
auditFilePath: "/var/log/origin/audit-ocp.log"
enabled: true
maximumFileRetentionDays: 10
maximumFileSizeMegabytes: 10
maximumRetainedFiles: 10
----

.Advanced Setup for the Audit Log
If you want more advanced setup for the audit log, you can use:

----
openshift_master_audit_config={"enabled": true}
----
The directory *_/var/log/origin_* will be created if it does not exist.

The directory in `auditFilePath` will be created if it does not exist.
You can specify advanced audit log parameters by using the following parameter
value format:

----
openshift_master_audit_config={"enabled": true, "auditFilePath": "/var/lib/origin/openpaas-oscp-audit.log", "maximumFileRetentionDays": 14, "maximumFileSizeMegabytes": 500, "maximumRetainedFiles": 5}
openshift_master_audit_config={"enabled": true, "auditFilePath": "/var/log/origin/openpaas-oscp-audit.log", "maximumFileRetentionDays": 14, "maximumFileSizeMegabytes": 500, "maximumRetainedFiles": 5}
----

[[master-node-config-advanced-audit]]
Expand All @@ -1196,7 +1200,7 @@ fine-grained events filtering and multiple output back ends.
To enable the advanced audit feature, provide the following values in the `openshift_master_audit_config` parameter

----
openshift_master_audit_config={"enabled": true, "auditFilePath": "/var/lib/origin/oscp-audit/-oscp-audit.log", "maximumFileRetentionDays": 14, "maximumFileSizeMegabytes": 500, "maximumRetainedFiles": 5, "policyFile": "/etc/security/adv-audit.yaml", "logFormat":"json"}
openshift_master_audit_config={"enabled": true, "auditFilePath": "/var/log/origin/oscp-audit.log", "maximumFileRetentionDays": 14, "maximumFileSizeMegabytes": 500, "maximumRetainedFiles": 5, "policyFile": "/etc/security/adv-audit.yaml", "logFormat":"json"}
----

[IMPORTANT]
Expand Down