# Audit plugin excluded accounts still being logged

**URL:** <https://forums.percona.com/t/audit-plugin-excluded-accounts-still-being-logged/17596>\
**Category:** Other MySQL® Questions\
**Tags:** mysql, percona\
**Created:** [September 21, 2022, 9:31am UTC](https://forums.percona.com/t/audit-plugin-excluded-accounts-still-being-logged/17596 "2022-09-21T09:31:34Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hamza\_Fareed](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/hamza_fareed/32/5713_2.png) [@Hamza\_Fareed](https://forums.percona.com/u/Hamza_Fareed)\
**Post date:** [September 21, 2022, 9:31am UTC](https://forums.percona.com/t/audit-plugin-excluded-accounts-still-being-logged/17596/1 "2022-09-21T09:31:34Z")

</div>

Hi,

I am having issues excluding users from Percona’s audit plugin. Users are added to my.cnf via the audit\_log\_exclude\_accounts system variable but still show in the audit log.

```auto

audit_log_policy=ALL
audit_log_format=JSON
audit_log_file=/var/log/mysql/audit.log
audit_log_rotate_on_size=10M
audit_log_rotations=10
audit_log_exclude_accounts=''user_brand_stg'@'X.X.20.%','user_brand_stg'@'X.X.30.%','user_track_stg'@'X.X.20.%','user_track_stg'@'X.X.30.%','user@'X.X.%.%'....(19 TOTAL ACCOUNTS in a similar setup)''
audit_log_exclude_commands='show_status,show_processlist'

```

The users hosts and wildcards match what is in mysql.user for user

MySQL version :  
mysqld Ver 5.7.36-39-57 for debian-linux-gnu on x86\_64 (Percona XtraDB Cluster (GPL), Release rel39, Revision 5197785, WSREP version 31.55, wsrep\_31.55)

Output from variables show

 ![auditVariables](https://us1.discourse-cdn.com/flex019/uploads/percona1/original/2X/5/523d3f98a25071ee2b1a06d1bd61e18dd7855dbb.png)  
audit\_log\_include\_accounts shows as NULL as well from select @@Global.audit\_log\_include\_accounts

I also see the same issue on another similarly configured server :  
mysqld Ver 5.7.34-37-57 for debian-linux-gnu on x86\_64 (Percona XtraDB Cluster (GPL), Release rel37, Revision 99b8607, WSREP version 31.51, wsrep\_31.51)

Any ideas on what is going wrong here?  
Do I need to escape any characters, documentation only mentions comma and using the format ‘user’@‘host’

Regards

---

<div class="post-metadata">

**Author:** ![Denis\_Subbota](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/denis_subbota/32/23607_2.png) [@Denis\_Subbota](https://forums.percona.com/u/Denis_Subbota)\
**Post date:** [September 26, 2022, 1:13pm UTC](https://forums.percona.com/t/audit-plugin-excluded-accounts-still-being-logged/17596/2 "2022-09-26T13:13:43Z")

</div>

Hello Hamza,  
Thank you for your question.  
As far as I know you need to specify user and host same as you have in mysql.user.  
For example, if you have 2 users like:  
`'percona'@'10.10.%' and 'percona'@'10.11.%'`  
and you will try to exclude like below - it will not work for you  
`audit_log_exclude_accounts="'percona'@'10.%'"`

you need to provide exact user inside this variable

```auto
audit_log_exclude_accounts="'percona'@'10.10.%','percona'@'10.11.%'"

```

Regards,  
Denis Subbota.  
Managed Services, Percona.
