# Percona Audit Log

**URL:** <https://forums.percona.com/t/percona-audit-log/22010>\
**Category:** Percona Server for MySQL 8.0\
**Tags:** mysql, percona\
**Created:** [May 11, 2023, 12:44pm UTC](https://forums.percona.com/t/percona-audit-log/22010 "2023-05-11T12:44:03Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![buyuk\_basri](https://avatars.discourse-cdn.com/v4/letter/b/5fc32e/32.png) [@buyuk\_basri](https://forums.percona.com/u/buyuk_basri)\
**Post date:** [May 11, 2023, 12:44pm UTC](https://forums.percona.com/t/percona-audit-log/22010/1 "2023-05-11T12:44:03Z")

</div>

Hello;

I am using Percona’s Audit Log plugin and I have configured it, but it only logs user logins to the log file. However, I want to log all users’ DELETE, UPDATE, and INSERT operations, including both existing and newly created users. How can I achieve this?

@matthewb

---

<div class="post-metadata">

**Author:** ![matthewb](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/matthewb/32/34_2.png) [@matthewb](https://forums.percona.com/u/matthewb)\
**Post date:** [May 11, 2023, 2:49pm UTC](https://forums.percona.com/t/percona-audit-log/22010/2 "2023-05-11T14:49:20Z")

</div>

Please show the configuration, `SHOW GLOBAL variables LIKE 'audit%';`. Also, have you read through our [extensive documentation](https://docs.percona.com/percona-server/8.0/management/audit_log_plugin.html#install-the-plugin) for this plugin?

---

<div class="post-metadata">

**Author:** ![buyuk\_basri](https://avatars.discourse-cdn.com/v4/letter/b/5fc32e/32.png) [@buyuk\_basri](https://forums.percona.com/u/buyuk_basri)\
**Post date:** [May 12, 2023, 12:42pm UTC](https://forums.percona.com/t/percona-audit-log/22010/3 "2023-05-12T12:42:42Z")

</div>

mysql\> SHOW GLOBAL variables LIKE ‘audit%’;  
±----------------------------±---------------------+  
| Variable\_name | Value |  
±----------------------------±---------------------+  
| audit\_log\_buffer\_size | 1048576 |  
| audit\_log\_exclude\_accounts | mysql,sys |  
| audit\_log\_exclude\_commands | |  
| audit\_log\_exclude\_databases | |  
| audit\_log\_file | audit.log |  
| audit\_log\_flush | OFF |  
| audit\_log\_format | JSON |  
| audit\_log\_handler | FILE |  
| audit\_log\_include\_accounts | |  
| audit\_log\_include\_commands | INSERT,DELETE,UPDATE |  
| audit\_log\_include\_databases | |  
| audit\_log\_policy | ALL |  
| audit\_log\_rotate\_on\_size | 0 |  
| audit\_log\_rotations | 0 |  
| audit\_log\_strategy | ASYNCHRONOUS |  
| audit\_log\_syslog\_facility | LOG\_USER |  
| audit\_log\_syslog\_ident | percona-audit |  
| audit\_log\_syslog\_priority | LOG\_INFO |  
±----------------------------±---------------------+  
18 rows in set (0.01 sec)

Yes I have read and adjusted accordingly

---

<div class="post-metadata">

**Author:** ![matthewb](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/matthewb/32/34_2.png) [@matthewb](https://forums.percona.com/u/matthewb)\
**Post date:** [May 12, 2023, 2:51pm UTC](https://forums.percona.com/t/percona-audit-log/22010/4 "2023-05-12T14:51:21Z")

</div>

> [@buyuk\_basri](#):
>
> audit\_log\_exclude\_accounts

This looks incorrect as mysql and sys are both databases, not users accounts. Move these to `audit_log_exclude_databases`

Your values for `audit_log_include_commands` are incorrect. The values for this parameter are not SQL, they are the internal command calls.

Run this `SELECT name FROM performance_schema.setup_instruments WHERE name LIKE "statement/sql/%" ORDER BY name;` to see all the command names. Srip off the first part of ‘statement/sql/’ and use just the base part in the setting.
