Hub
Database

Apache Cassandra Audit Log

Apache Cassandra 4.1 FileAuditLogger records from one node for SIEM engineers who build database access and role-management detections, as ECS JSON with the raw log line in event.original and the pipe-delimited audit entry in message. About 38,000 records a day from applications, analysts, DBAs and DBA-created roles on UTC working hours. Recurring episodes show a DBA account creating a short-lived role that reads finance.payroll and is then dropped.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/database-apache-cassandra-audit/generator.yml \
  --id cassandra \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
SELECTApplications, analysts, DBA-created roles, DBA checks68.42% of recordsQUERY
UPDATEApplications and analysts (CQL INSERT is also logged as UPDATE)26.33% of recordsDML
DELETEbilling_svc1.39% of recordsDML
LOGIN_SUCCESSEvery connection1.22% of recordsAUTH
PREPARE_STATEMENTApplications after reconnecting1.09% of recordsPREPARE
USE_KEYSPACEDrivers (USE "finance") and some cqlsh sessions0.93% of recordsOTHER
LIST_PERMISSIONSDBAs, often before logging in as a role to check its access0.15% of recordsDCL
LIST_ROLESDBAs0.15% of recordsDCL
GRANTDBAs0.08% of recordsDCL
CREATE_ROLEDBAs0.05% of recordsDCL
DROP_ROLEDBAs0.05% of recordsDCL
ALTER_ROLEDBA password rotation for service roles0.03% of recordsDCL
REVOKEDBAs0.03% of recordsDCL
ALTER_TABLEDBAs0.02% of recordsDDL
UNAUTHORIZED_ATTEMPTAnalysts reading finance.payroll, roles after a revoke0.02% of recordsAUTH
LOGIN_ERRORMistyped passwords0.02% of recordsAUTH
REQUEST_FAILUREQueries against a misspelled table0.01% of recordsERROR

Realism Features

  • Four application roles on pooled driver connections log round the clock (0.25 records/s at night, up to 0.65/s from 08:00 to 18:00 UTC) and reconnect about every 40 minutes with a login, USE "finance" and re-prepared statements. Analysts open about 21 cqlsh sessions a day and DBAs about 47, nearly all between 08:00 and 17:00 UTC, and DBA-created roles are used from reporting hosts about 23 times a day. The mix is a synthetic training profile, not a measured production ratio.
  • About 6% of logins by people and 2-4% by reporting roles fail with a wrong password, followed by a retry or a give-up; one failure in a row is more common than two. Applications fail about 0.3% of reconnects.
  • CQL INSERT is logged as UPDATE, role passwords appear as *******, and prepared-statement bound values are never logged, as in Cassandra. All records run on the Native-Transport-Requests pool, as on a node with the default native_transport_max_auth_threads: 0, and the host field uses the IP-only /10.20.30.10:7000 form.
  • At most eight of the ten role names exist at a time; usually one to three of the four scratch roles exist, and a role that takes the last free scratch name or brings the roles in use to eight is dropped again within an hour or so, often by another DBA. With anomaly_mode: true the number of scratch roles that exist at once is one higher for the length of an episode.
  • In both modes DBAs create the same role names, grant finance.payroll or other tables, test new roles from their own host, read payroll themselves, and revoke and drop roles: per day about 5-7 roles are dropped within two hours of creation and about 8-10 new roles read payroll from a DBA host. hr_portal, reporting_etl and hr_lead_mora read payroll all day.
  • Records a real node writes within milliseconds of each other (a driver's login, USE and re-prepared statements) are seconds apart: a median of 2 s by day and 5-6 s at night, 99% within about 30 s. The line layout is derived from Cassandra source and the shipped logback audit appender pattern; no raw audit.log from a production 4.1 node was available for byte comparison. The clock is UTC with no weekends, and one node is modelled. BATCH entries, TRUNCATE, keyspace and table DDL other than ALTER TABLE, and connection close are not generated. The ECS mapping is inferred; no Elastic integration exists for Cassandra audit logs.

Sample Output

{
  "@timestamp": "2026-09-01T14:45:54.889Z",
  "cassandra": {
    "audit": {
      "category": "DCL",
      "host": "/10.20.30.10:7000",
      "keyspace": "finance",
      "operation": "GRANT SELECT ON TABLE finance.payroll TO migration_ro;",
      "port": 54667,
      "source": "/10.20.10.5",
      "timestamp": 1788273954889,
      "type": "GRANT",
      "user": "ops_admin"
    }
  },
  "ecs": {
    "version": "8.17.0"
  },
  "event": {
    "action": "grant",
    "category": [
      "iam"
    ],
    "created": "2026-09-01T14:45:54.889Z",
    "kind": "event",
    "original": "INFO  [Native-Transport-Requests-7] 2026-09-01 14:45:54,889 FileAuditLogger.java:51 - user:ops_admin|host:/10.20.30.10:7000|source:/10.20.10.5|port:54667|timestamp:1788273954889|type:GRANT|category:DCL|ks:finance|operation:GRANT SELECT ON TABLE finance.payroll TO migration_ro;",
    "outcome": "success",
    "type": [
      "user",
      "change"
    ]
  },
  "host": {
    "ip": [
      "10.20.30.10"
    ],
    "name": "cassandra-01.example.test"
  },
  "log": {
    "level": "INFO",
    "logger": "org.apache.cassandra.audit.FileAuditLogger",
    "origin": {
      "file": {
        "line": 51,
        "name": "FileAuditLogger.java"
      }
    }
  },
  "message": "user:ops_admin|host:/10.20.30.10:7000|source:/10.20.10.5|port:54667|timestamp:1788273954889|type:GRANT|category:DCL|ks:finance|operation:GRANT SELECT ON TABLE finance.payroll TO migration_ro;",
  "process": {
    "thread": {
      "name": "Native-Transport-Requests-7"
    }
  },
  "related": {
    "ip": [
      "10.20.10.5",
      "10.20.30.10"
    ],
    "user": [
      "ops_admin",
      "migration_ro"
    ]
  },
  "source": {
    "ip": "10.20.10.5",
    "port": 54667
  },
  "user": {
    "name": "ops_admin",
    "target": {
      "name": "migration_ro"
    }
  }
}

Parameters

ParameterDefaultDescription
anomaly_modetrueGenerate the recurring temporary-role payroll chain; false emits only background
anomaly_interval_hours24Hours between episode due times, from the previous actual start; 6 to 8,760
host_namecassandra-01.example.testNode name in host.name
host_ip10.20.30.10Node broadcast address in the host audit field

Related Generators