Skip to main content

Audit Logging

Gnok records a comprehensive audit trail of all data access and administrative operations for compliance and forensics. Audit logs are immutable and append-only.

Event Categories​

Audit events are organized into six categories. Each category covers a distinct area of system activity.

CategoryEventsExample
AuthenticationLoginSuccess, LoginFailure, TokenRefresh, SessionExpiredUser alice logged in via JWT
AuthorizationAccessDenied, PrivilegeCheck, RLSApplied, MaskingAppliedUser bob denied SELECT on orders
DataAccessQuery, Export, DataPreview, TimeTravelQuery Q-123 scanned 1.2M rows from orders
AdministrativeRoleChange, PolicyUpdate, ConfigChange, WarehouseResizeRole analyst granted to alice
SchemaCreateObject, AlterObject, DropObjectTable orders created by alice
SecurityGrant, Revoke, PolicyCreate, PolicyDropGRANT SELECT ON orders TO analyst

Authentication Events​

Authentication events capture every interaction with the identity layer:

  • LoginSuccess -- Recorded when a user authenticates successfully. Captures the authentication method (JWT, password, SSO) and the identity provider.
  • LoginFailure -- Recorded on failed authentication attempts. Captures the failure reason (invalid token, expired credentials, unknown user).
  • TokenRefresh -- Recorded when a session token is refreshed.
  • SessionExpired -- Recorded when a session times out or is explicitly terminated.

Authorization Events​

Authorization events track privilege checks at every level of the object hierarchy:

  • PrivilegeCheck -- Recorded for every privilege evaluation during query planning. Includes the object, requested privilege, and result.
  • AccessDenied -- Recorded when a query is rejected due to insufficient privileges.
  • RLSApplied -- Recorded when a row-level security policy filters rows from query results.
  • MaskingApplied -- Recorded when a column masking policy transforms column values.

Data Access Events​

Data access events provide a record of all queries and data movement:

  • Query -- Recorded for every SQL statement executed. Includes the SQL text (optionally truncated), tables accessed, rows scanned, rows returned, and execution duration.
  • Export -- Recorded when query results are exported or downloaded.

Audit Record Schema​

Every audit event conforms to a structured schema. The following fields are present on all records:

FieldTypeDescription
event_idUUIDUnique event identifier
timestampTIMESTAMPEvent time in UTC
categoryVARCHAREvent category (Authentication, Authorization, DataAccess, Administrative, Schema, Security)
event_typeVARCHARSpecific event type within the category
outcomeVARCHARSUCCESS, FAILURE, or DENIED
actor_idVARCHARUser ID from the identity provider
actor_nameVARCHARHuman-readable username
tenant_idVARCHARYour organization's identifier
session_idVARCHARSession identifier
client_ipVARCHARClient IP address
target_typeVARCHARObject type: TABLE, SCHEMA, CATALOG, ROLE, POLICY, WAREHOUSE
target_nameVARCHARFully qualified object name
statementVARCHARSQL statement text (truncated to 4096 characters by default)
detailsJSONAdditional event-specific details

Example Record​

{
"event_id": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
"timestamp": "2025-06-15T10:30:00Z",
"category": "DataAccess",
"event_type": "Query",
"outcome": "SUCCESS",
"actor_id": "user-abc123",
"actor_name": "alice@example.com",
"tenant_id": "acme-corp",
"session_id": "sess-abc123",
"client_ip": "10.0.1.42",
"target_type": "TABLE",
"target_name": "catalog.schema.orders",
"statement": "SELECT * FROM orders WHERE region = 'US'",
"details": {
"tables_accessed": ["catalog.schema.orders"],
"columns_accessed": ["order_id", "amount", "region"],
"rows_scanned": 5200000,
"rows_returned": 1042,
"duration_ms": 156,
"rls_policies_applied": ["region_filter"],
"masking_applied": ["email:mask_email"]
}
}

Configuration​

Audit storage and capture settings are managed by Gnok. Authorized administrators can inspect the audit information exposed to their account. Confirm the scope and retention required by your organization through your account arrangements.

Querying Audit Logs​

Via SQL​

Audit logs can be queried directly using the SHOW AUDIT EVENTS command:

-- Recent activity by a specific user
SHOW AUDIT EVENTS
WHERE actor_name = 'alice@example.com'
AND timestamp > '2025-06-01'
ORDER BY timestamp DESC
LIMIT 100;

-- Failed authentication attempts in the last 7 days
SHOW AUDIT EVENTS
WHERE category = 'Authentication'
AND outcome = 'FAILURE'
AND timestamp >= CURRENT_TIMESTAMP - INTERVAL '7 days'
ORDER BY timestamp DESC;

-- All privilege changes
SHOW AUDIT EVENTS
WHERE category = 'Security'
ORDER BY timestamp DESC;

-- Queries that accessed sensitive columns
SHOW AUDIT EVENTS
WHERE category = 'DataAccess'
AND details:columns_accessed::VARCHAR LIKE '%ssn%'
ORDER BY timestamp DESC;

Via Catalog Service REST API​

The Gnok Catalog exposes a REST endpoint for querying audit events programmatically:

curl -X GET 'https://catalog.example.com/v1/audit/events' \
-H 'Authorization: Bearer <TOKEN>' \
-H 'Content-Type: application/json' \
-d '{
"filter": {
"category": "DataAccess",
"actor_name": "alice@example.com",
"start_time": "2025-06-01T00:00:00Z",
"end_time": "2025-06-15T00:00:00Z"
},
"limit": 100
}'

Retention​

Confirm audit retention and export requirements for your account with Gnok. Engine defaults and examples are not a contractual retention guarantee.

Performance​

Audit capture and persistence are managed by the service. If records appear missing, provide the event time and query or account reference to support.

Compliance Templates​

Audit logs can support your organization's evidence and investigation processes. A logging feature alone does not establish SOC 2, HIPAA, PCI-DSS, or other compliance. Confirm the required access, retention, and controls with your compliance team and Gnok.