diff --git a/install_config/master_node_configuration.adoc b/install_config/master_node_configuration.adoc index 7e9f6ed85b04..a18b8e9ac8e9 100644 --- a/install_config/master_node_configuration.adoc +++ b/install_config/master_node_configuration.adoc @@ -1156,11 +1156,17 @@ stamp encoded in their filename. Defaults to 100MB. |=== +[IMPORTANT] +==== +Because the {product-name} master API now runs as static pod, you must define +the `auditFilePath` location in the *_/var/lib/origin_*, *_/var/log/origin_*, +or *_/etc/origin/master/_* file. +==== .Example Audit Configuration ---- auditConfig: - auditFilePath: "/var/lib/origin/audit-ocp.log" + auditFilePath: "/var/log/origin/audit-ocp.log" enabled: true maximumFileRetentionDays: 10 maximumFileSizeMegabytes: 10 @@ -1168,16 +1174,14 @@ auditConfig: ---- .Advanced Setup for the Audit Log -If you want more advanced setup for the audit log, you can use: ----- -openshift_master_audit_config={"enabled": true} ----- +The directory *_/var/log/origin_* will be created if it does not exist. -The directory in `auditFilePath` will be created if it does not exist. +You can specify advanced audit log parameters by using the following parameter +value format: ---- -openshift_master_audit_config={"enabled": true, "auditFilePath": "/var/lib/origin/openpaas-oscp-audit.log", "maximumFileRetentionDays": 14, "maximumFileSizeMegabytes": 500, "maximumRetainedFiles": 5} +openshift_master_audit_config={"enabled": true, "auditFilePath": "/var/log/origin/openpaas-oscp-audit.log", "maximumFileRetentionDays": 14, "maximumFileSizeMegabytes": 500, "maximumRetainedFiles": 5} ---- [[master-node-config-advanced-audit]] @@ -1190,7 +1194,7 @@ fine-grained events filtering and multiple output back ends. To enable the advanced audit feature, provide the following values in the `openshift_master_audit_config` parameter ---- -openshift_master_audit_config={"enabled": true, "auditFilePath": "/var/lib/origin/oscp-audit/-oscp-audit.log", "maximumFileRetentionDays": 14, "maximumFileSizeMegabytes": 500, "maximumRetainedFiles": 5, "policyFile": "/etc/security/adv-audit.yaml", "logFormat":"json"} +openshift_master_audit_config={"enabled": true, "auditFilePath": "/var/log/origin/oscp-audit.log", "maximumFileRetentionDays": 14, "maximumFileSizeMegabytes": 500, "maximumRetainedFiles": 5, "policyFile": "/etc/security/adv-audit.yaml", "logFormat":"json"} ---- [IMPORTANT]