# Confusion about Audit\_log\_filter rules and excludes

**URL:** <https://forums.percona.com/t/confusion-about-audit-log-filter-rules-and-excludes/39388>\
**Category:** Percona Server for MySQL 8.0\
**Tags:** percona\
**Created:** [September 16, 2025, 12:00am UTC](https://forums.percona.com/t/confusion-about-audit-log-filter-rules-and-excludes/39388 "2025-09-16T00:00:03Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![Daniel\_Wake](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/daniel_wake/32/21100_2.png) [@Daniel\_Wake](https://forums.percona.com/u/Daniel_Wake)\
**Post date:** [September 16, 2025, 12:00am UTC](https://forums.percona.com/t/confusion-about-audit-log-filter-rules-and-excludes/39388/1 "2025-09-16T00:00:03Z")

</div>

Hi All,

I’m having trouble understanding the logic of the audit\_log\_filter. Even trying the simplest two filter system of log\_all and log\_none where a specific user or set of users is set to log\_none the system will still log their actions due to having log\_all as a the default rule with ‘%’

This was very easily achieved in the old audit\_log plugin where you could simply comma delimit write the user@hosts as they are listed in the mysql.users and it would exclude them from the audit\_log.

For example:

```sql
SET @filter = ‘{ “filter”: { “log”: true }}’;
SELECT audit_log_filter_set_filter(‘log_all’, @filter);
SELECT audit_log_filter_set_user(‘%’, ‘log_all’);

```

```sql
SET @filter = ‘{ “filter”: { “log”: false }}’;
SELECT audit_log_filter_set_filter(‘log_none’, @filter);
SELECT audit_log_filter_set_user(‘appuser@10.0.0.%’, ‘log_none’);

```

```auto
mysql> select * from mysql.audit_log_user;
±----------±-----------±-----------+
| username | userhost | filtername |
±----------±-----------±-----------+
| % | % | log_all |
| appuser | 10.0.0.% | log_none |
±----------±-----------±-----------+
2 rows in set (0.00 sec)

```

appuser connecting from 10.0.0.1 still gets logged.

How is this best achieved in audit\_log\_filter?

Also, side question: Does Percona 8.0.43’s audit\_log\_filter have all the same features and configuration available to it as Percona 8.4.x? The doco for the former is very sparse in comparison.

---

<div class="post-metadata">

**Author:** ![Wayne\_Leutwyler](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/wayne_leutwyler/32/20829_2.png) [@Wayne\_Leutwyler](https://forums.percona.com/u/Wayne_Leutwyler)\
**Post date:** [September 16, 2025, 11:37am UTC](https://forums.percona.com/t/confusion-about-audit-log-filter-rules-and-excludes/39388/2 "2025-09-16T11:37:38Z")

</div>

> [@Daniel\_Wake](#):
>
> ```auto
> SET @filter = ‘{ “filter”: { “log”: true }}’;
> SELECT audit_log_filter_set_filter(‘log_all’, @filter);
> SELECT audit_log_filter_set_user(‘%’, ‘log_all’);
> 
> ```
> 
> ```auto
> SET @filter = ‘{ “filter”: { “log”: false }}’;
> SELECT audit_log_filter_set_filter(‘log_none’, @filter);
> SELECT audit_log_filter_set_user(‘appuser@10.0.0.%’, ‘log_none’);
> 
> ```

The rules would break down like:

- **Most Users** : All actions by any user connecting from any host will be logged to the audit log.
- **Specific Exemption** : No actions by the user **`appuser`** will be logged, as long as they are connecting from an IP address within the `10.0.0.0/24` subnet.

Your understanding of the rules is correct. You dont happen to have appuser coming from somewhere out side of 10.0.0.%?

I would like to test this in my lab to see if I can duplicate the behavior can be duplicated. I will report back shortly.

---

<div class="post-metadata">

**Author:** ![Wayne\_Leutwyler](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/wayne_leutwyler/32/20829_2.png) [@Wayne\_Leutwyler](https://forums.percona.com/u/Wayne_Leutwyler)\
**Post date:** [September 16, 2025, 12:04pm UTC](https://forums.percona.com/t/confusion-about-audit-log-filter-rules-and-excludes/39388/3 "2025-09-16T12:04:45Z")

</div>

I was able to reproduce the exact behavior in my lab.  
You can see the appuser was logged when I had it drop a table:

```auto
    "timestamp": "2025-09-16 08:06:19",
    "id": 231,
    "class": "general",
    "event": "status",
    "connection_id": 37,
    "account": { "user": "appuser[appuser] @ pi8gb.lan [192.168.1.62]", "host": "pi8gb.lan" },
    "login": { "user": "appuser[appuser] @ pi8gb.lan [192.168.1.62]", "ip": "192.168.1.62", "proxy": "" },
    "general_data": { "status": 0 }
  },
  {
    "timestamp": "2025-09-16 08:06:19",
    "id": 232,
    "class": "command",
    "event": "command_end",
    "connection_id": 37,
    "command_data": {
      "name": "command_end",
      "status": 0,
      "command": "Field List"}
  },
  {
    "timestamp": "2025-09-16 08:06:37",
    "id": 233,
    "class": "command",
    "event": "command_start",
    "connection_id": 37,
    "command_data": {
      "name": "command_start",
      "status": 0,
      "command": "Query"}
  },
  {
    "timestamp": "2025-09-16 08:06:37",
    "id": 234,
    "class": "parse",
    "event": "query_rewritten",
    "connection_id": 37,
    "parse_data": {
      "flags": 0,
      "query": "drop table t1",
      "rewritten_query": ""}
  },

```

You may have found a bug. You can open a bug report here: [https://jira.percona.com](https://jira.percona.com)

---

<div class="post-metadata">

**Author:** ![Daniel\_Wake](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/daniel_wake/32/21100_2.png) [@Daniel\_Wake](https://forums.percona.com/u/Daniel_Wake)\
**Post date:** [September 16, 2025, 8:02pm UTC](https://forums.percona.com/t/confusion-about-audit-log-filter-rules-and-excludes/39388/4 "2025-09-16T20:02:52Z")

</div>

Hi Wayne,

Thanks for confirming my issue. I don’t seem able to resolve the address [https://jira.percona.com](https://jira.percona.com/) so can’t raise a bug report as you suggest. Is that URL correct?

Also, potential bug aside, do you know if Percona 8.0.43 implementation of audit\_log\_filter is the same as the component version that is a part of Percona 8.4.x?

---

<div class="post-metadata">

**Author:** ![Wayne\_Leutwyler](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/wayne_leutwyler/32/20829_2.png) [@Wayne\_Leutwyler](https://forums.percona.com/u/Wayne_Leutwyler)\
**Post date:** [September 16, 2025, 8:25pm UTC](https://forums.percona.com/t/confusion-about-audit-log-filter-rules-and-excludes/39388/5 "2025-09-16T20:25:14Z")

</div>

I’m so sorry about the link. This one should work for you: [Jira](https://perconadev.atlassian.net/jira/software/c/projects/PS/boards/98)

**If you still have issues let me know and I will put the bug report in.**

The **Audit Log Filter component** in **MySQL 8.4** is essentially the **same feature introduced in MySQL 8.0** , with only minor changes related to deprecations and the transition away from the old **audit log plugin**.

Here’s the breakdown:

### MySQL 8.0

- Introduced the **audit log filter component** to replace the older **audit log plugin** (which was marked as deprecated).
- Filters are defined using `audit_log_filter_set_filter()`, `audit_log_filter_set_user()`, etc.
- JSON-based filtering rules allow per-user and global filtering.
- Installed via `INSTALL COMPONENT 'file://component_audit_log_filter';`.

### MySQL 8.4

- Continues to use the **audit log filter component** (plugin-based auditing is fully deprecated/removed in MySQL 8.4).
- The **syntax and behavior** of filter rules (`audit_log_filter_set_user()`, `audit_log_filter_remove_filter()`, etc.) remain the same.
- Still JSON-based, same capabilities: filtering by event class, command class, SQL operation, table, etc.
- Default logging location and formats are unchanged.
- Biggest change: You can no longer rely on the **old audit log plugin** —the **component** is the only supported method.

### Key Point

If your audit log filter rules work in **MySQL 8.0 using the component** , they will work in **MySQL 8.4** without changes.  
The only difference is that in 8.4, the plugin path is gone, so **only the component method is supported**.

---

<div class="post-metadata">

**Author:** ![Daniel\_Wake](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/daniel_wake/32/21100_2.png) [@Daniel\_Wake](https://forums.percona.com/u/Daniel_Wake)\
**Post date:** [September 17, 2025, 12:30am UTC](https://forums.percona.com/t/confusion-about-audit-log-filter-rules-and-excludes/39388/6 "2025-09-17T00:30:29Z")

</div>

Thanks for the clarification re: functionality between 8.0.43 and 8.4.x. Good to know that should I get audit logging in audit\_log\_filter to a satisfactory state it’ll be easier to eventually migrate to 8.4.x.

Raised bug here: [Jira](https://perconadev.atlassian.net/browse/PS-10159?atlOrigin=eyJpIjoiNTdkNmQ4ZWVlNGM5NGU2ZGJlZTJmMWI1ODc3ZTQ3ODkiLCJwIjoiaiJ9)

Unsure if filled out correctly as there were many fields I didn’t have an answer too that seemed pertinent to internal percona staff.

---

<div class="post-metadata">

**Author:** ![Wayne\_Leutwyler](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/wayne_leutwyler/32/20829_2.png) [@Wayne\_Leutwyler](https://forums.percona.com/u/Wayne_Leutwyler)\
**Post date:** [September 17, 2025, 1:00am UTC](https://forums.percona.com/t/confusion-about-audit-log-filter-rules-and-excludes/39388/7 "2025-09-17T01:00:07Z")

</div>

The bug report looks great. Thank you!

---

<div class="post-metadata">

**Author:** ![Wayne\_Leutwyler](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/wayne_leutwyler/32/20829_2.png) [@Wayne\_Leutwyler](https://forums.percona.com/u/Wayne_Leutwyler)\
**Post date:** [September 18, 2025, 6:19pm UTC](https://forums.percona.com/t/confusion-about-audit-log-filter-rules-and-excludes/39388/8 "2025-09-18T18:19:44Z")

</div>

@Daniel_Wake

Please provide the output of the following query when connected as `appuser`:

```auto
select user(), current_user();

```

This will help confirm the authenticated account (USER()) versus the effective security context (CURRENT\_USER()), which is critical for understanding how privileges and audit log filters are being applied.

---

<div class="post-metadata">

**Author:** ![Daniel\_Wake](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/daniel_wake/32/21100_2.png) [@Daniel\_Wake](https://forums.percona.com/u/Daniel_Wake)\
**Post date:** [September 19, 2025, 12:43am UTC](https://forums.percona.com/t/confusion-about-audit-log-filter-rules-and-excludes/39388/9 "2025-09-19T00:43:00Z")

</div>

```auto
mysql> select user(), current_user();
+----------------------+----------------------+
| user() | current_user() |
+----------------------+----------------------+
| appuser@10.0.0.1 | appuser@10.0.0.% |
+----------------------+----------------------+
1 row in set (0.00 sec)

```

and

```auto
mysql> select User, Host from mysql.user where User = 'appuser';
+-----------+------------+
| User | Host |
+-----------+------------+
| appuser | 10.0.0.% |
+-----------+------------+
1 row in set (0.00 sec)

```

---

<div class="post-metadata">

**Author:** ![Wayne\_Leutwyler](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/wayne_leutwyler/32/20829_2.png) [@Wayne\_Leutwyler](https://forums.percona.com/u/Wayne_Leutwyler)\
**Post date:** [September 19, 2025, 11:24am UTC](https://forums.percona.com/t/confusion-about-audit-log-filter-rules-and-excludes/39388/10 "2025-09-19T11:24:57Z")

</div>

Could you try this rule:

```auto
select audit_log_filter_set_filter('log_connection', '{ "filter": { "class": { "name": "connection" } } } )';

```

---

<div class="post-metadata">

**Author:** ![Daniel\_Wake](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/daniel_wake/32/21100_2.png) [@Daniel\_Wake](https://forums.percona.com/u/Daniel_Wake)\
**Post date:** [September 21, 2025, 11:47pm UTC](https://forums.percona.com/t/confusion-about-audit-log-filter-rules-and-excludes/39388/11 "2025-09-21T23:47:59Z")

</div>

Any more context? From my understanding of the doco that would create a log all connections filter should I apply it to a user?

I should test such a filter with ‘%’ and do the normal log false with my appuser?

---

<div class="post-metadata">

**Author:** ![Wayne\_Leutwyler](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/wayne_leutwyler/32/20829_2.png) [@Wayne\_Leutwyler](https://forums.percona.com/u/Wayne_Leutwyler)\
**Post date:** [September 22, 2025, 11:27am UTC](https://forums.percona.com/t/confusion-about-audit-log-filter-rules-and-excludes/39388/12 "2025-09-22T11:27:24Z")

</div>

Yes please test with you appuser@10.0.0.%

Sorry I should have been a bit more clear.

---

<div class="post-metadata">

**Author:** ![Daniel\_Wake](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/daniel_wake/32/21100_2.png) [@Daniel\_Wake](https://forums.percona.com/u/Daniel_Wake)\
**Post date:** [September 25, 2025, 5:08am UTC](https://forums.percona.com/t/confusion-about-audit-log-filter-rules-and-excludes/39388/13 "2025-09-25T05:08:50Z")

</div>

> [@Wayne\_Leutwyler](#):
>
> ```auto
> mysql> select audit_log_filter_set_filter('log_connection', '{ "filter": { "class": { "name": "connection" } } } ');
> +-------------------------------------------------------------------------------------------------------+
> | audit_log_filter_set_filter('log_connection', '{ "filter": { "class": { "name": "connection" } } } ') |
> +-------------------------------------------------------------------------------------------------------+
> | OK |
> +-------------------------------------------------------------------------------------------------------+
> 1 row in set (0.01 sec)
> 
> mysql> select audit_log_filter_set_user('appuser@10.0.0.%', 'log_connection');
> +---------------------------------------------------------------------+
> | audit_log_filter_set_user('appuser@10.0.0.%', 'log_connection') |
> +---------------------------------------------------------------------+
> | OK |
> +---------------------------------------------------------------------+
> 1 row in set (0.01 sec)
> 
> {
> "timestamp": "2025-09-25 15:03:00",
> "id": 9798,
> "class": "connection",
> "event": "connect",
> "connection_id": 64,
> "account": { "user": "appuser", "host": "" },
> "login": { "user": "appuser", "os": "", "ip": "10.0.0.11", "proxy": "" },
> "connection_data": {
> "connection_type": "tcp/ip",
> "status": 0,
> "db": "stellav_integration"
> },
> "connection_attributes": {
> "_runtime_version": "17.0.4.1",
> "_client_version": "8.0.33",
> "_client_license": "GPL",
> "_runtime_vendor": "Amazon.com Inc.",
> "_client_name": "MySQL Connector\/J"
> }
> },
> {
> "timestamp": "2025-09-25 15:03:00",
> "id": 9799,
> "class": "connection",
> "event": "connect",
> "connection_id": 65,
> "account": { "user": "appuser", "host": "" },
> "login": { "user": "appuser", "os": "", "ip": "10.0.0.15", "proxy": "" },
> "connection_data": {
> "connection_type": "tcp/ip",
> "status": 0,
> "db": "stellav_integration"
> },
> "connection_attributes": {
> "_runtime_version": "17.0.4.1",
> "_client_version": "8.0.33",
> "_client_license": "GPL",
> "_runtime_vendor": "Amazon.com Inc.",
> "_client_name": "MySQL Connector\/J"
> }
> },
> 
> ```

It logs the connections as expected? According to the doco in 8.0 and 8.4 if “log” is omitted then it defaults to true right?

---

<div class="post-metadata">

**Author:** ![Daniel\_Wake](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/daniel_wake/32/21100_2.png) [@Daniel\_Wake](https://forums.percona.com/u/Daniel_Wake)\
**Post date:** [September 25, 2025, 5:15am UTC](https://forums.percona.com/t/confusion-about-audit-log-filter-rules-and-excludes/39388/14 "2025-09-25T05:15:14Z")

</div>

Going further along that line of working:

```auto
mysql> select audit_log_filter_set_user('%', 'log_connection');
+--------------------------------------------------+
| audit_log_filter_set_user('%', 'log_connection') |
+--------------------------------------------------+
| OK |
+--------------------------------------------------+
1 row in set (0.00 sec)

mysql> select audit_log_filter_set_filter('log_connection_false', '{ "filter": { "class": { "name": "connection", "log": false } } } ');
+---------------------------------------------------------------------------------------------------------------------------+
| audit_log_filter_set_filter('log_connection_false', '{ "filter": { "class": { "name": "connection", "log": false } } } ') |
+---------------------------------------------------------------------------------------------------------------------------+
| OK |
+---------------------------------------------------------------------------------------------------------------------------+
1 row in set (0.00 sec)

mysql> select audit_log_filter_set_user('svintuser@10.39.45.%', 'log_connection_false');
+---------------------------------------------------------------------------+
| audit_log_filter_set_user('svintuser@10.39.45.%', 'log_connection_false') |
+---------------------------------------------------------------------------+
| OK |
+---------------------------------------------------------------------------+
1 row in set (0.00 sec)

  {
    "timestamp": "2025-09-25 15:12:33",
    "id": 65,
    "class": "connection",
    "event": "connect",
    "connection_id": 56,
    "account": { "user": "root", "host": "localhost" },
    "login": { "user": "root", "os": "", "ip": "", "proxy": "" },
    "connection_data": {
      "connection_type": "socket",
      "status": 0,
      "db": ""
    },
    "connection_attributes": {
      "_pid": "3360330",
      "_platform": "x86_64",
      "_os": "Linux",
      "_client_name": "libmysql",
      "os_sudouser": "omitted_user",
      "os_user": "root",
      "_client_version": "8.0.43-34"
    }
  },
  {
    "timestamp": "2025-09-25 15:12:41",
    "id": 66,
    "class": "connection",
    "event": "disconnect",
    "connection_id": 56,
    "account": { "user": "root", "host": "localhost" },
    "login": { "user": "root", "os": "", "ip": "", "proxy": "" },
    "connection_data": {
      "connection_type": "socket",
      "status": 0,
      "db": ""
    },
    "connection_attributes": {
      "_pid": "3360330",
      "_platform": "x86_64",
      "_os": "Linux",
      "_client_name": "libmysql",
      "os_sudouser": "omitted_user",
      "os_user": "root",
      "_client_version": "8.0.43-34"
    }
  }

```

Looks like it works for connection class if I make two filters with one log: false.

---

<div class="post-metadata">

**Author:** ![Daniel\_Wake](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/daniel_wake/32/21100_2.png) [@Daniel\_Wake](https://forums.percona.com/u/Daniel_Wake)\
**Post date:** [September 25, 2025, 5:39am UTC](https://forums.percona.com/t/confusion-about-audit-log-filter-rules-and-excludes/39388/15 "2025-09-25T05:39:40Z")

</div>

Works for table\_access as well. Matches the [Jira](https://perconadev.atlassian.net/browse/PS-10161) **pre\_authenticate and general log events are still generated even when user filter is set to {“filter”: {“log”: false}}** issue exactly where as soon as I add class General I get logs.

Unfortunately the general log might be the one I most need as it seems the closest to how the old audit\_log\_filter used to work?:

```auto
{“audit_record”:{“name”:“Connect”,“record”:“3667_2025-09-24T04:16:08”,“timestamp”:“2025-09-25T05:36:47Z”,“connection_id”:“46592”,“status”:0,“user”:“root”,“priv_user”:“root”,“os_login”:“”,“proxy_user”:“”,“host”:“localhost”,“ip”:“”,“db”:“”}}
{“audit_record”:{“name”:“Query”,“record”:“3668_2025-09-24T04:16:08”,“timestamp”:“2025-09-25T05:36:47Z”,“command_class”:“select”,“connection_id”:“46592”,“status”:0,“sqltext”:“select @@version_comment limit 1”,“user”:“root[root] @ localhost ”,“host”:“localhost”,“os_user”:“”,“ip”:“”,“db”:“”}}
{“audit_record”:{“name”:“Query”,“record”:“3669_2025-09-24T04:16:08”,“timestamp”:“2025-09-25T05:36:59Z”,“command_class”:“select”,“connection_id”:“46592”,“status”:0,“sqltext”:“select * from app_schema.app_table.skin”,“user”:“root[root] @ localhost ”,“host”:“localhost”,“os_user”:“”,“ip”:“”,“db”:“”}}
{“audit_record”:{“name”:“Quit”,“record”:“3670_2025-09-24T04:16:08”,“timestamp”:“2025-09-25T05:37:01Z”,“connection_id”:“46592”,“status”:0,“user”:“root”,“priv_user”:“root”,“os_login”:“”,“proxy_user”:“”,“host”:“localhost”,“ip”:“”,“db”:“”}}

```

Is there any combination of Class and deeper key/vals that can replicate this simple connection of user to query?

---

<div class="post-metadata">

**Author:** ![Wayne\_Leutwyler](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/wayne_leutwyler/32/20829_2.png) [@Wayne\_Leutwyler](https://forums.percona.com/u/Wayne_Leutwyler)\
**Post date:** [September 25, 2025, 11:08am UTC](https://forums.percona.com/t/confusion-about-audit-log-filter-rules-and-excludes/39388/16 "2025-09-25T11:08:37Z")

</div>

This rule will get table\_access, connection and general. Is this what your looking for?

```auto
select audit_log_filter_set_filter('log_table_access', '{ "filter": { "class": { "name": ["table_access", "connection", "general"] } } } ');

```

---

<div class="post-metadata">

**Author:** ![Wayne\_Leutwyler](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/wayne_leutwyler/32/20829_2.png) [@Wayne\_Leutwyler](https://forums.percona.com/u/Wayne_Leutwyler)\
**Post date:** [October 13, 2025, 12:04pm UTC](https://forums.percona.com/t/confusion-about-audit-log-filter-rules-and-excludes/39388/17 "2025-10-13T12:04:37Z")

</div>

@Daniel_Wake

Please checkout my latest blog: [Audit Log Filters Part II | Percona Community](https://percona.community/blog/2025/10/08/audit-log-filters-part-ii/)

---

<div class="post-metadata">

**Author:** ![Daniel\_Wake](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/daniel_wake/32/21100_2.png) [@Daniel\_Wake](https://forums.percona.com/u/Daniel_Wake)\
**Post date:** [April 14, 2026, 5:20am UTC](https://forums.percona.com/t/confusion-about-audit-log-filter-rules-and-excludes/39388/18 "2026-04-14T05:20:29Z")

</div>

Hi Wayne,

Thanks for the great blog post and apologies for the long silence. I was hit by a car at the end of October and it’s been a long road to recovery.

Anyway, looking back at the Percona JIRA issues I rose and your blog post theres no 1:1 fix for what I was encountering but at least with your blog post I can move forward with the audit\_log\_filter plugin if I approach it purely as a whitelist i.e. “Audit log these specific users" and just not even apply a filter to unimportant users then it can work for me.

I desperately wanted the lazy approach to work where I could set a log events for all users, then set no audit logging for users with wildcards/regex.

Unfortunately the fix that audit\_log\_filter now supports wildcard hostnames is abit disingenuous. It supports it as the literal user, host field combination in the mysql.user table only. Most people would assume in reality that applying a filter to ‘user’@’%’ would capture events for users defined as ‘user’@’10.0.0.1’, ‘user’@’172.20.0.%’ etc. but no. Need to apply to each mysql.user definition.

Thank you for the information with writing filters all the same. Just means I can’t be lazy anymore in dealing with my company’s exhaustive legacy.
