# audit plugin  audit\_log\_exclude\_accounts not working in 5.7.24-27

**URL:** <https://forums.percona.com/t/audit-plugin-audit-log-exclude-accounts-not-working-in-5-7-24-27/6849>\
**Category:** Other MySQL® Questions\
**Created:** [February 13, 2019, 3:43pm UTC](https://forums.percona.com/t/audit-plugin-audit-log-exclude-accounts-not-working-in-5-7-24-27/6849 "2019-02-13T15:43:30Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![grosenthal](https://avatars.discourse-cdn.com/v4/letter/g/e47c2d/32.png) [@grosenthal](https://forums.percona.com/u/grosenthal)\
**Post date:** [February 13, 2019, 3:43pm UTC](https://forums.percona.com/t/audit-plugin-audit-log-exclude-accounts-not-working-in-5-7-24-27/6849/1 "2019-02-13T15:43:30Z")

</div>

Just installed the Percona MySQL audit log plugin and trying to exclude a really chatty user but no matter what i put for exclusion the particular user is still updating the audit log. I’ve seen this was a bug in previous versions. Is it still a bug?

---

<div class="post-metadata">

**Author:** ![lorraine.pocklington](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/lorraine.pocklington/32/37_2.png) [@lorraine.pocklington](https://forums.percona.com/u/lorraine.pocklington)\
**Post date:** [February 13, 2019, 5:09pm UTC](https://forums.percona.com/t/audit-plugin-audit-log-exclude-accounts-not-working-in-5-7-24-27/6849/2 "2019-02-13T17:09:56Z")

</div>

Could you post your best example of an exclusion setting so that I can get someone to check it please? Are you getting any other symptoms? Don’t give any real examples, just use an example user so we can see the syntax.  
Thanks

---

<div class="post-metadata">

**Author:** ![grosenthal](https://avatars.discourse-cdn.com/v4/letter/g/e47c2d/32.png) [@grosenthal](https://forums.percona.com/u/grosenthal)\
**Post date:** [February 14, 2019, 9:01am UTC](https://forums.percona.com/t/audit-plugin-audit-log-exclude-accounts-not-working-in-5-7-24-27/6849/3 "2019-02-14T09:01:11Z")

</div>

Thanks. I’ve tried multiple syntax including  
set global audit\_log\_exclude\_accounts=‘user1@’  
set global audit\_log\_exclude\_accounts=“‘user1’@‘%’”  
set global audit\_log\_exclude\_accounts=‘user1@[ipaddress]’

---

<div class="post-metadata">

**Author:** ![Yuvi](https://avatars.discourse-cdn.com/v4/letter/y/ecb155/32.png) [@Yuvi](https://forums.percona.com/u/Yuvi)\
**Post date:** [February 14, 2019, 5:53pm UTC](https://forums.percona.com/t/audit-plugin-audit-log-exclude-accounts-not-working-in-5-7-24-27/6849/4 "2019-02-14T17:53:38Z")

</div>

Hi,

I am trying to install the Percona audit plugin on my MySQL server 5.5.38 but I am running into the below issue

mysql\> install plugin audit\_log soname ‘audit\_log.so’;

ERROR 1123 (HY000): Can’t initialize function ‘audit\_log’; Plugin initialization function failed.

I checked the MySQL error logs it is not showing me up any useful information

[ERROR] Plugin ‘audit\_log’ registration as a AUDIT failed.

[ERROR] Plugin ‘audit\_log’ init function returned error.

First I updated the my.cnf file with the required audit plugin variables like audit\_log\_format = csv , [audit\_log\_rotate\_on\_size](https://dev.mysql.com/doc/refman/5.5/en/audit-log-options-variables.html#sysvar_audit_log_rotate_on_size), [audit\_log\_strategy](https://dev.mysql.com/doc/refman/5.5/en/audit-log-options-variables.html#sysvar_audit_log_strategy) etc., and then tried to install the plugin (install plugin audit\_log soname ‘audit\_log.so’) on the MySQL server which is showing the above error

---

<div class="post-metadata">

**Author:** ![Yuvi](https://avatars.discourse-cdn.com/v4/letter/y/ecb155/32.png) [@Yuvi](https://forums.percona.com/u/Yuvi)\
**Post date:** [February 14, 2019, 5:57pm UTC](https://forums.percona.com/t/audit-plugin-audit-log-exclude-accounts-not-working-in-5-7-24-27/6849/5 "2019-02-14T17:57:29Z")

</div>

Hi ,

I tried to install the Percona Audit plugin for MySQL 5.5.38 and it is showing me the below error

mysql\> install plugin audit\_log soname ‘audit\_log.so’;

ERROR 1123 (HY000): Can’t initialize function ‘audit\_log’; Plugin initialization function failed.

First I modifed the my.cnf file with the follwoing variables like “[audit\_log\_policy](https://dev.mysql.com/doc/refman/5.5/en/audit-log-options-variables.html#sysvar_audit_log_policy)=All, [audit\_log\_rotate\_on\_size](https://dev.mysql.com/doc/refman/5.5/en/audit-log-options-variables.html#sysvar_audit_log_rotate_on_size)=1G, [audit\_log\_format](https://dev.mysql.com/doc/refman/5.5/en/audit-log-options-variables.html#sysvar_audit_log_format)=CSV,etc.,”. and then tried to install the plugin as above which is throwing the error.

Here are the errors from the MySQL error log file

[ERROR] Plugin ‘audit\_log’ registration as a AUDIT failed.

[ERROR] Plugin ‘audit\_log’ init function returned error.

---

<div class="post-metadata">

**Author:** ![Michael\_Coburn](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/michael_coburn/32/18_2.png) [@Michael\_Coburn](https://forums.percona.com/u/Michael_Coburn)\
**Post date:** [February 18, 2019, 11:05am UTC](https://forums.percona.com/t/audit-plugin-audit-log-exclude-accounts-not-working-in-5-7-24-27/6849/6 "2019-02-18T11:05:19Z")

</div>

Just FYI I moved this from PMM to MySQL channel

---

<div class="post-metadata">

**Author:** ![sergei.glushchenko](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/sergei.glushchenko/32/16887_2.png) [@sergei.glushchenko](https://forums.percona.com/u/sergei.glushchenko)\
**Post date:** [February 19, 2019, 9:17am UTC](https://forums.percona.com/t/audit-plugin-audit-log-exclude-accounts-not-working-in-5-7-24-27/6849/7 "2019-02-19T09:17:47Z")

</div>

Hi [grosenthal](https://percona.vanillacommunities.com/profile/x/x/42675) ,

Can you please post an example log record for this user? Also please share the output of “show variables like ‘audit\_log%’”.

---

<div class="post-metadata">

**Author:** ![sergei.glushchenko](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/sergei.glushchenko/32/16887_2.png) [@sergei.glushchenko](https://forums.percona.com/u/sergei.glushchenko)\
**Post date:** [February 19, 2019, 9:20am UTC](https://forums.percona.com/t/audit-plugin-audit-log-exclude-accounts-not-working-in-5-7-24-27/6849/8 "2019-02-19T09:20:54Z")

</div>

Hi [Yuvi](https://percona.vanillacommunities.com/profile/x/x/42677) ,  
Can you please post exact snippet which you have added to my.cnf, it could be that it has a syntax error.

---

<div class="post-metadata">

**Author:** ![grosenthal](https://avatars.discourse-cdn.com/v4/letter/g/e47c2d/32.png) [@grosenthal](https://forums.percona.com/u/grosenthal)\
**Post date:** [February 26, 2019, 8:25am UTC](https://forums.percona.com/t/audit-plugin-audit-log-exclude-accounts-not-working-in-5-7-24-27/6849/9 "2019-02-26T08:25:47Z")

</div>

mysql\> show variables like ‘%audit\_log%’;  
±----------------------------±---------------------------------------------+  
| Variable\_name | Value |  
±----------------------------±---------------------------------------------+  
| audit\_log\_buffer\_size | 1048576 |  
| audit\_log\_exclude\_accounts | someuser@ |  
| audit\_log\_exclude\_commands | |  
| audit\_log\_exclude\_databases | |  
| audit\_log\_file | /opt/sw/dbinstall/mysql/mysql-logs/audit.log |  
| audit\_log\_flush | OFF |  
| audit\_log\_format | OLD |  
| audit\_log\_handler | FILE |  
| audit\_log\_include\_accounts | |  
| audit\_log\_include\_commands | |  
| audit\_log\_include\_databases | |  
| audit\_log\_policy | ALL |  
| audit\_log\_rotate\_on\_size | 0 |  
| audit\_log\_rotations | 0 |  
| audit\_log\_strategy | ASYNCHRONOUS |  
| audit\_log\_syslog\_facility | LOG\_USER |  
| audit\_log\_syslog\_ident | percona-audit |  
| audit\_log\_syslog\_priority | LOG\_INFO |  
±----------------------------±---------------------------------------------+

a few audit log entries

\<AUDIT\_RECORD  
NAME=“Connect”  
RECORD=“2729\_2019-02-13T19:13:54”  
TIMESTAMP=“2019-02-13T19:36:37 UTC”  
CONNECTION\_ID=“5”  
STATUS=“0”  
USER=“someuser”  
PRIV\_USER=“someuser”  
OS\_LOGIN=“”  
PROXY\_USER=“”  
HOST=“”  
IP=“xxx.xxx.xxx.xxx”  
DB=“”  
/\>  
\<AUDIT\_RECORD  
NAME=“Connect”  
RECORD=“2730\_2019-02-13T19:13:54”  
TIMESTAMP=“2019-02-13T19:36:37 UTC”  
CONNECTION\_ID=“6”  
STATUS=“0”  
USER=“someuser”  
PRIV\_USER=“someuser”  
OS\_LOGIN=“”  
PROXY\_USER=“”  
HOST=“”  
IP=“xxx.xxx.xxx.xxx”  
DB=“”  
/\>  
\<AUDIT\_RECORD  
NAME=“Connect”  
RECORD=“2731\_2019-02-13T19:13:54”  
TIMESTAMP=“2019-02-13T19:36:37 UTC”  
CONNECTION\_ID=“4”  
STATUS=“0”  
USER=“someuser”  
PRIV\_USER=“someuser”  
OS\_LOGIN=“”  
PROXY\_USER=“”  
HOST=“”  
IP=“xxx.xxx.xxx.xxx”  
DB=“”

AUDIT Entries in my.cnf

audit\_log\_handler=FILE  
audit\_log\_file=/opt/sw/dbinstall/mysql/mysql-logs/audit.log  
audit\_log\_exclude\_accounts=‘someuser@’

---

<div class="post-metadata">

**Author:** ![Yuvi](https://avatars.discourse-cdn.com/v4/letter/y/ecb155/32.png) [@Yuvi](https://forums.percona.com/u/Yuvi)\
**Post date:** [March 25, 2019, 3:48pm UTC](https://forums.percona.com/t/audit-plugin-audit-log-exclude-accounts-not-working-in-5-7-24-27/6849/10 "2019-03-25T15:48:41Z")

</div>

Hi [sergei.glushchenko](https://www.percona.com/forums/member/2339-sergei-glushchenko), I didn’t received any update to my email when you asked me to post the "exact snippet from my.cnf"…here are the audit variables that I added in the my.cnf file

audit\_log\_policy = ALL  
audit\_log\_file = /opt/SNAP/mysql/data/current  
audit\_log\_rotate\_on\_size = 4096  
audit\_log\_rotations = 25

Please let me know if there are any systex issues.

Thanks and regards  
Yuvi

---

<div class="post-metadata">

**Author:** ![Yuvi](https://avatars.discourse-cdn.com/v4/letter/y/ecb155/32.png) [@Yuvi](https://forums.percona.com/u/Yuvi)\
**Post date:** [March 25, 2019, 3:50pm UTC](https://forums.percona.com/t/audit-plugin-audit-log-exclude-accounts-not-working-in-5-7-24-27/6849/11 "2019-03-25T15:50:40Z")

</div>

Hi [sergei.glushchenko](https://www.percona.com/forums/member/2339-sergei-glushchenko), I didn’t received any email notification when you asked me to post the audit variable settings in my.cnf file. Here are the settings below that I added in my.cnf file.

audit\_log\_policy = ALL  
audit\_log\_file = /opt/SNAP/mysql/data/current  
audit\_log\_rotate\_on\_size = 4096  
audit\_log\_rotations = 25

Please let me know, if you want anything else from my side.

Thanks and regards  
Yuvi

---

<div class="post-metadata">

**Author:** ![mosad](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/mosad/32/2871_2.png) [@mosad](https://forums.percona.com/u/mosad)\
**Post date:** [December 8, 2020, 4:44am UTC](https://forums.percona.com/t/audit-plugin-audit-log-exclude-accounts-not-working-in-5-7-24-27/6849/12 "2020-12-08T04:44:28Z")

</div>

If you want to exclude user with IP (not localhost) it is very difficulty. I resolve this problem after facebook chat.

It is necessary to make first audit\_log\_include\_accounts = NULL;

then added a list of excluded accounts

audit\_log\_exclude\_accounts = ‘user@1.1.1.1,user1@9.9.9.9’
