# Audit plugin user filtering does not work

**URL:** <https://forums.percona.com/t/audit-plugin-user-filtering-does-not-work/5842>\
**Category:** Other MySQL® Questions\
**Created:** [September 5, 2017, 9:38pm UTC](https://forums.percona.com/t/audit-plugin-user-filtering-does-not-work/5842 "2017-09-05T21:38:02Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![keith](https://avatars.discourse-cdn.com/v4/letter/k/f05b48/32.png) [@keith](https://forums.percona.com/u/keith)\
**Post date:** [September 5, 2017, 9:38pm UTC](https://forums.percona.com/t/audit-plugin-user-filtering-does-not-work/5842/1 "2017-09-05T21:38:02Z")

</div>

Hello guys,  
I use the audit plugin to exclude a subset of users, but it does not work. The following two methods of setting are not working：

set global audit\_log\_exclude\_accounts= “‘yzk’@‘192.168.1.1’”;  
and show variables like ‘audit\_log\_exclude\_accounts’ result is  
audit\_log\_exclude\_accounts | ‘yzk’@‘192.168.1.1’

set global audit\_log\_exclude\_accounts= ‘yzk@192.168.1.1’;  
and show variables like ‘audit\_log\_exclude\_accounts’ result is  
audit\_log\_exclude\_accounts | ‘yzk@192.168.1.1’

Although I have re-logged in, but the log is still recorded in this account information on the 192.168.1.1.  
It makes me soon have hundreds of G size log files.

I hope someone can tell me the correct setting method.

Thank you very much!

---

<div class="post-metadata">

**Author:** ![eroomydna](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/eroomydna/32/941_2.png) [@eroomydna](https://forums.percona.com/u/eroomydna)\
**Post date:** [September 7, 2017, 4:51am UTC](https://forums.percona.com/t/audit-plugin-user-filtering-does-not-work/5842/2 "2017-09-07T04:51:41Z")

</div>

Hey Keith, what version of Percona Server are you currently using? Can you provide the output from `SHOW GLOBAL VARIABLES LIKE 'audit%';`

thanks in advance!

---

<div class="post-metadata">

**Author:** ![keith](https://avatars.discourse-cdn.com/v4/letter/k/f05b48/32.png) [@keith](https://forums.percona.com/u/keith)\
**Post date:** [September 8, 2017, 1:34am UTC](https://forums.percona.com/t/audit-plugin-user-filtering-does-not-work/5842/3 "2017-09-08T01:34:19Z")

</div>

> [@eroomydna;49563](#):
>
> Hey Keith, what version of Percona Server are you currently using? Can you provide the output from `SHOW GLOBAL VARIABLES LIKE 'audit%';`
> 
> thanks in advance!

Percona Server version is : 5.6.36-82.0-log  
And `SHOW GLOBAL VARIABLES LIKE '%audti%';` output is :  
±---------------------------±----------------------+  
| Variable\_name | Value |  
±---------------------------±----------------------+  
| audit\_log\_buffer\_size | 1048576 |  
| audit\_log\_exclude\_accounts | ‘yzk’@‘192.168.1.1’ |  
| audit\_log\_exclude\_commands | |  
| audit\_log\_file | audit.log |  
| audit\_log\_flush | OFF |  
| audit\_log\_format | OLD |  
| audit\_log\_handler | FILE |  
| audit\_log\_include\_accounts | |  
| audit\_log\_include\_commands | |  
| audit\_log\_policy | ALL |  
| audit\_log\_rotate\_on\_size | 0 |  
| audit\_log\_rotations | 0 |  
| audit\_log\_strategy | ASYNCHRONOUS |  
| audit\_log\_syslog\_facility | LOG\_USER |  
| audit\_log\_syslog\_ident | percona-audit |  
| audit\_log\_syslog\_priority | LOG\_INFO |  
±---------------------------±----------------------+  
16 rows in set (0.00 sec)

Unfortunately, `audit_log_exclude_accounts` doesn’t work.

Thanks!

---

<div class="post-metadata">

**Author:** ![keith](https://avatars.discourse-cdn.com/v4/letter/k/f05b48/32.png) [@keith](https://forums.percona.com/u/keith)\
**Post date:** [September 8, 2017, 1:36am UTC](https://forums.percona.com/t/audit-plugin-user-filtering-does-not-work/5842/4 "2017-09-08T01:36:19Z")

</div>

The configuration file /etc/my.cnf does not set any audit parameters.

---

<div class="post-metadata">

**Author:** ![eroomydna](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/eroomydna/32/941_2.png) [@eroomydna](https://forums.percona.com/u/eroomydna)\
**Post date:** [September 9, 2017, 7:39am UTC](https://forums.percona.com/t/audit-plugin-user-filtering-does-not-work/5842/5 "2017-09-09T07:39:00Z")

</div>

Hi Keith,

this is a known bug in Percona Server. It will require a major upgrade to fix this in lieu of a patch for 5.6.xx releases.

[url][https://bugs.launchpad.net/percona-server/5.6/+bug/1679316[/url]](https://bugs.launchpad.net/percona-server/5.6/+bug/1679316%5B/url%5D)

For more details.

BR

Andrew

---

<div class="post-metadata">

**Author:** ![eroomydna](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/eroomydna/32/941_2.png) [@eroomydna](https://forums.percona.com/u/eroomydna)\
**Post date:** [September 9, 2017, 7:43am UTC](https://forums.percona.com/t/audit-plugin-user-filtering-does-not-work/5842/6 "2017-09-09T07:43:56Z")

</div>

p.s. there is a workaround described in the bug report but that may not fit your use case. It’s also viable to use the McAfee audit plugin to produce a similarly formatted output for your audit trail.

---

<div class="post-metadata">

**Author:** ![keith](https://avatars.discourse-cdn.com/v4/letter/k/f05b48/32.png) [@keith](https://forums.percona.com/u/keith)\
**Post date:** [September 10, 2017, 7:45pm UTC](https://forums.percona.com/t/audit-plugin-user-filtering-does-not-work/5842/7 "2017-09-10T19:45:22Z")

</div>

OK.We will consider replacing the use of McAfee audit plugin.

Thank you again!
