# Percona audit\_log\_filter component does not work on the slave server 8.4

**URL:** <https://forums.percona.com/t/percona-audit-log-filter-component-does-not-work-on-the-slave-server-8-4/39205>\
**Category:** Percona Server for MySQL 8.0\
**Created:** [August 26, 2025, 3:45pm UTC](https://forums.percona.com/t/percona-audit-log-filter-component-does-not-work-on-the-slave-server-8-4/39205 "2025-08-26T15:45:28Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mastervi](https://avatars.discourse-cdn.com/v4/letter/m/e495f1/32.png) [@Mastervi](https://forums.percona.com/u/Mastervi)\
**Post date:** [August 26, 2025, 3:45pm UTC](https://forums.percona.com/t/percona-audit-log-filter-component-does-not-work-on-the-slave-server-8-4/39205/1 "2025-08-26T15:45:28Z")

</div>

I’m testing the new `percona audit_log_filter` component and found a strange behavior when using it on the replica server.  
The component is installed, filter rules exist, and the user is added.  
On the master, I can see the query log, but on the replica, the log is empty.  
I can’t figure out if this is normal `audit_log_filter` behavior, if I’m making a mistake somewhere, or if I should file a bug report.

**Here’s what I did:**

- Installed `8.4.5-5 Percona Server (GPL), Release 5, Revision 3d3abca6` on both master and slave. Host OS is AlmaLinux release 8.10 (Cerulean Leopard).
- Installed the plugin on both master and replica using:

```bash
mysql < /usr/share/mysql/audit_log_filter_linux_install.sql

```

- Configured replication and set the replica server to read-only mode.
- Set up the filter on the master:

```sql
SELECT audit_log_filter_set_filter(
'log_dml_ddl',
'{
 "filter": {
   "class": [
     {
       "name": "query",
       "event": {
         "name": ["start"]
       }
     },
     {
       "name": "connection",
       "event": {
         "name": ["connect", "disconnect"]
       }
     }
   ]
 }
}');

```

- Added myself as a user:

```sql
SELECT audit_log_filter_set_user('dba@%','log_dml_ddl');

```

**Checked the configuration on both master and replica:**

```sql
  SELECT audit_log_filter_set_user('dba@%','log_dml_ddl');

```

**Checked that the filter is enabled on both master and replica:**

```sql
select @@audit_log_filter.disable;
+----------------------------+
| @@audit_log_filter.disable |
+----------------------------+
| 0 |
+----------------------------+
1 row in set (0.08 sec)

```

**Then, I ran this on the master:**

```sql
select audit_log_session_filter_id();
+-------------------------------+
| audit_log_session_filter_id() |
+-------------------------------+
| 1 |
+-------------------------------+
1 row in set (0.09 sec)

```

This shows that the filter with `filter_id=1` is active for my user.

**On the replica, the same query returns:**

```sql
select audit_log_session_filter_id();
+-------------------------------+
| audit_log_session_filter_id() |
+-------------------------------+
| 0 |
+-------------------------------+
1 row in set (0.09 sec)

```

This indicates that no filters are active for my user on the replica.

**The only way to make audit\_log\_filter work on the replica is:**

- Disable read-only mode: `SET GLOBAL read_only=OFF;`
- Reload the filter:`SELECT audit_log_filter_flush();`
- Enable read-only mode again:`SET GLOBAL read_only=ON;`

**When the replica is in read-only mode, adding a filter or user leads to this error:**

```sql
SELECT audit_log_filter_set_user('dba@%','log_dml_ddl');
+-------------------------------------------------------+
| audit_log_filter_set_user('dba@%','log_dml_ddl') |
+-------------------------------------------------------+
| ERROR: Failed to check filtering rule name existence |
+-------------------------------------------------------+
1 row in set (0.09 sec)

```

**Attempting to reload the component shows another error:**

```sql
SELECT audit_log_filter_flush();
+-------------------------------------------------+
| audit_log_filter_flush() |
+-------------------------------------------------+
| ERROR: Could not reinitialize audit log filters |
+-------------------------------------------------+
1 row in set (0.09 sec)

```

---

<div class="post-metadata">

**Author:** ![matthewb](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/matthewb/32/34_2.png) [@matthewb](https://forums.percona.com/u/matthewb)\
**Post date:** [August 26, 2025, 4:03pm UTC](https://forums.percona.com/t/percona-audit-log-filter-component-does-not-work-on-the-slave-server-8-4/39205/2 "2025-08-26T16:03:22Z")

</div>

Hello @Mastervi,

Firstly, the term ‘slave’ is no longer used. You may have noticed in MySQL 8.4 that all references to ‘slave’ have been removed, and replaced with ‘replica’. Secondly, to answer your post question, I believe what you are experiencing on the _replica_ is correct behavior. The audit plugin audits user-level actions within the database. The replication threads (SQL, and IO) are not user-level threads.

---

<div class="post-metadata">

**Author:** ![Mastervi](https://avatars.discourse-cdn.com/v4/letter/m/e495f1/32.png) [@Mastervi](https://forums.percona.com/u/Mastervi)\
**Post date:** [August 26, 2025, 4:19pm UTC](https://forums.percona.com/t/percona-audit-log-filter-component-does-not-work-on-the-slave-server-8-4/39205/3 "2025-08-26T16:19:34Z")

</div>

Hello @matthewb  
I wasn’t talking about replication threads. I’m connecting to the master via the MySQL client from the console, running: `select 'master2';`  
And I can see this query in the log:

```sql
# tail -f audit_filter.log  
</AUDIT_RECORD>
<AUDIT_RECORD>
<NAME>Query Start</NAME>
<RECORD_ID>2_2025-08-22T10:33:15</RECORD_ID>
<TIMESTAMP>2025-08-22T10:33:15</TIMESTAMP>
<STATUS>0</STATUS>
<CONNECTION_ID>15196</CONNECTION_ID>
<COMMAND_CLASS>select</COMMAND_CLASS>
<SQLTEXT>select 'master2'</SQLTEXT>
</AUDIT_RECORD>

```

When I connect to the replica via the MySQL client from the console and run: `select 'replica2';`  
the log on replica remains empty.

```sql
cat audit_filter.log
<?xml version="1.0" encoding="utf-8"?>
<AUDIT>
<AUDIT_RECORD>
<NAME>Audit</NAME>
<RECORD_ID>0_2025-08-22T12:14:07</RECORD_ID>
<TIMESTAMP>2025-08-22T12:14:07</TIMESTAMP>
<COMMAND_CLASS>Audit</COMMAND_CLASS>
<SERVER_ID>2</SERVER_ID>
</AUDIT_RECORD>

```

---

<div class="post-metadata">

**Author:** ![Mastervi](https://avatars.discourse-cdn.com/v4/letter/m/e495f1/32.png) [@Mastervi](https://forums.percona.com/u/Mastervi)\
**Post date:** [September 18, 2025, 12:34pm UTC](https://forums.percona.com/t/percona-audit-log-filter-component-does-not-work-on-the-slave-server-8-4/39205/4 "2025-09-18T12:34:23Z")

</div>

It`s a bug  
Ticket here [Jira](https://perconadev.atlassian.net/browse/PS-10137)

---

<div class="post-metadata">

**Author:** ![Dhivya\_Arumugam](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/dhivya_arumugam/32/21210_2.png) [@Dhivya\_Arumugam](https://forums.percona.com/u/Dhivya_Arumugam)\
**Post date:** [March 27, 2026, 9:51am UTC](https://forums.percona.com/t/percona-audit-log-filter-component-does-not-work-on-the-slave-server-8-4/39205/5 "2026-03-27T09:51:54Z")

</div>

Hi @matthewb  
I am facing similar issue on replica nodes. I am using 3-node Innodb cluster on MySQL Community Edition 8.4.7 and configured audit log filter component from Percona MySQL 8.4.7 version.

The bug report shows the status as resolved in 8.4.6 but the issue still appears.

> **[Jira](https://perconadev.atlassian.net/browse/PS-10137)**

---

<div class="post-metadata">

**Author:** ![matthewb](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/matthewb/32/34_2.png) [@matthewb](https://forums.percona.com/u/matthewb)\
**Post date:** [March 27, 2026, 4:47pm UTC](https://forums.percona.com/t/percona-audit-log-filter-component-does-not-work-on-the-slave-server-8-4/39205/6 "2026-03-27T16:47:03Z")

</div>

Hi @Dhivya_Arumugam,  
I suggest opening a new JIRA on this as I can reproduce the issue on 8.4.7

```auto
Server version: 8.4.7-7 Percona Server (GPL), Release 7, Revision 9a19f1fd

mysql [localhost:8417] {msandbox} (imdb) > INSTALL COMPONENT 'file://component_audit_log_filter';
Query OK, 0 rows affected (0.13 sec)

mysql [localhost:8417] {msandbox} (imdb) > SET read_only=1;
ERROR 1229 (HY000): Variable 'read_only' is a GLOBAL variable and should be set with SET GLOBAL
mysql [localhost:8417] {msandbox} (imdb) > SET GLOBAL read_only=1;
Query OK, 0 rows affected (0.00 sec)

mysql [localhost:8417] {msandbox} (imdb) > SELECT audit_log_filter_flush();
+-------------------------------------------------+
| audit_log_filter_flush() |
+-------------------------------------------------+
| ERROR: Could not reinitialize audit log filters |
+-------------------------------------------------+
1 row in set (0.00 sec)

```

---

<div class="post-metadata">

**Author:** ![Dhivya\_Arumugam](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/dhivya_arumugam/32/21210_2.png) [@Dhivya\_Arumugam](https://forums.percona.com/u/Dhivya_Arumugam)\
**Post date:** [March 28, 2026, 2:04am UTC](https://forums.percona.com/t/percona-audit-log-filter-component-does-not-work-on-the-slave-server-8-4/39205/7 "2026-03-28T02:04:58Z")

</div>

Hi @matthewb

As suggested, I have filed a new bug report ([Jira](https://perconadev.atlassian.net/browse/PS-10988)) on this. However, I am unable to edit the description of this jira so i have posted the details in the comment section.  
If you have access to edit the description, could you please post the details in the right place.

> **[Jira](https://perconadev.atlassian.net/browse/PS-10988)**
