启用数据面审计后,在 ES 实例的参数配置页面增加了AuditOpenDays
和AuditKeepDays
两个参数,用于控制数据面审计日志索引的打开天数和保存天数。
在 ES 实例的参数管理页面查看AuditOpenDays
和AuditKeepDays
两个参数配置情况。
通过配置AuditOpenDays
和AuditKeepDays
两个参数,就能控制审计日志索引的生命周期。您可以在 Kibana 的 Index Management > Index Policies 页面查看索引生命周期策略,默认已生成一个名为recycle_auditlog_policy
的策略。recycle_auditlog_policy
策略的内容如下:
.security-auditlog-*
,与索引模式匹配的索引都将适配该生命周期策略。{ "policy_id": "recycle_auditlog_policy", "description": "recycle auditlog index workflow", "last_updated_time": 1700449535942, "schema_version": 1, "error_notification": null, "default_state": "fresh", "states": [ { "name": "fresh", "actions": [], "transitions": [ { "state_name": "trash", "conditions": { "min_index_age": "7d" } } ] }, { "name": "trash", "actions": [ { "close": {} } ], "transitions": [ { "state_name": "delete", "conditions": { "min_index_age": "30d" } } ] }, { "name": "delete", "actions": [ { "delete": {} } ], "transitions": [] } ], "ism_template": { "index_patterns": [ ".security-auditlog-*" ], "priority": 100, "last_updated_time": 1700449535942 } }
修改AuditOpenDays
和AuditKeepDays
参数配置后,实例不会重启,修改参数配置需要隔天(UTC 时间零点后)生效。
AuditOpenDays
和AuditKeepDays
两个参数的取值,然后单击提交。