Apache Cassandra Audit Log
Apache Cassandra 4.1 FileAuditLogger records from one node for SIEM engineers who build database access and role-management detections, as ECS JSON with the raw log line in event.original and the pipe-delimited audit entry in message. About 38,000 records a day from applications, analysts, DBAs and DBA-created roles on UTC working hours. Recurring episodes show a DBA account creating a short-lived role that reads finance.payroll and is then dropped.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/database-apache-cassandra-audit/generator.yml \
--id cassandra \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| SELECT | Applications, analysts, DBA-created roles, DBA checks | 68.42% of records | QUERY |
| UPDATE | Applications and analysts (CQL INSERT is also logged as UPDATE) | 26.33% of records | DML |
| DELETE | billing_svc | 1.39% of records | DML |
| LOGIN_SUCCESS | Every connection | 1.22% of records | AUTH |
| PREPARE_STATEMENT | Applications after reconnecting | 1.09% of records | PREPARE |
| USE_KEYSPACE | Drivers (USE "finance") and some cqlsh sessions | 0.93% of records | OTHER |
| LIST_PERMISSIONS | DBAs, often before logging in as a role to check its access | 0.15% of records | DCL |
| LIST_ROLES | DBAs | 0.15% of records | DCL |
| GRANT | DBAs | 0.08% of records | DCL |
| CREATE_ROLE | DBAs | 0.05% of records | DCL |
| DROP_ROLE | DBAs | 0.05% of records | DCL |
| ALTER_ROLE | DBA password rotation for service roles | 0.03% of records | DCL |
| REVOKE | DBAs | 0.03% of records | DCL |
| ALTER_TABLE | DBAs | 0.02% of records | DDL |
| UNAUTHORIZED_ATTEMPT | Analysts reading finance.payroll, roles after a revoke | 0.02% of records | AUTH |
| LOGIN_ERROR | Mistyped passwords | 0.02% of records | AUTH |
| REQUEST_FAILURE | Queries against a misspelled table | 0.01% of records | ERROR |
Realism Features
- Four application roles on pooled driver connections log round the clock (0.25 records/s at night, up to 0.65/s from 08:00 to 18:00 UTC) and reconnect about every 40 minutes with a login, USE "finance" and re-prepared statements. Analysts open about 21 cqlsh sessions a day and DBAs about 47, nearly all between 08:00 and 17:00 UTC, and DBA-created roles are used from reporting hosts about 23 times a day. The mix is a synthetic training profile, not a measured production ratio.
- About 6% of logins by people and 2-4% by reporting roles fail with a wrong password, followed by a retry or a give-up; one failure in a row is more common than two. Applications fail about 0.3% of reconnects.
- CQL INSERT is logged as UPDATE, role passwords appear as *******, and prepared-statement bound values are never logged, as in Cassandra. All records run on the Native-Transport-Requests pool, as on a node with the default native_transport_max_auth_threads: 0, and the host field uses the IP-only /10.20.30.10:7000 form.
- At most eight of the ten role names exist at a time; usually one to three of the four scratch roles exist, and a role that takes the last free scratch name or brings the roles in use to eight is dropped again within an hour or so, often by another DBA. With anomaly_mode: true the number of scratch roles that exist at once is one higher for the length of an episode.
- In both modes DBAs create the same role names, grant finance.payroll or other tables, test new roles from their own host, read payroll themselves, and revoke and drop roles: per day about 5-7 roles are dropped within two hours of creation and about 8-10 new roles read payroll from a DBA host. hr_portal, reporting_etl and hr_lead_mora read payroll all day.
- Records a real node writes within milliseconds of each other (a driver's login, USE and re-prepared statements) are seconds apart: a median of 2 s by day and 5-6 s at night, 99% within about 30 s. The line layout is derived from Cassandra source and the shipped logback audit appender pattern; no raw audit.log from a production 4.1 node was available for byte comparison. The clock is UTC with no weekends, and one node is modelled. BATCH entries, TRUNCATE, keyspace and table DDL other than ALTER TABLE, and connection close are not generated. The ECS mapping is inferred; no Elastic integration exists for Cassandra audit logs.
Sample Output
{
"@timestamp": "2026-09-01T14:45:54.889Z",
"cassandra": {
"audit": {
"category": "DCL",
"host": "/10.20.30.10:7000",
"keyspace": "finance",
"operation": "GRANT SELECT ON TABLE finance.payroll TO migration_ro;",
"port": 54667,
"source": "/10.20.10.5",
"timestamp": 1788273954889,
"type": "GRANT",
"user": "ops_admin"
}
},
"ecs": {
"version": "8.17.0"
},
"event": {
"action": "grant",
"category": [
"iam"
],
"created": "2026-09-01T14:45:54.889Z",
"kind": "event",
"original": "INFO [Native-Transport-Requests-7] 2026-09-01 14:45:54,889 FileAuditLogger.java:51 - user:ops_admin|host:/10.20.30.10:7000|source:/10.20.10.5|port:54667|timestamp:1788273954889|type:GRANT|category:DCL|ks:finance|operation:GRANT SELECT ON TABLE finance.payroll TO migration_ro;",
"outcome": "success",
"type": [
"user",
"change"
]
},
"host": {
"ip": [
"10.20.30.10"
],
"name": "cassandra-01.example.test"
},
"log": {
"level": "INFO",
"logger": "org.apache.cassandra.audit.FileAuditLogger",
"origin": {
"file": {
"line": 51,
"name": "FileAuditLogger.java"
}
}
},
"message": "user:ops_admin|host:/10.20.30.10:7000|source:/10.20.10.5|port:54667|timestamp:1788273954889|type:GRANT|category:DCL|ks:finance|operation:GRANT SELECT ON TABLE finance.payroll TO migration_ro;",
"process": {
"thread": {
"name": "Native-Transport-Requests-7"
}
},
"related": {
"ip": [
"10.20.10.5",
"10.20.30.10"
],
"user": [
"ops_admin",
"migration_ro"
]
},
"source": {
"ip": "10.20.10.5",
"port": 54667
},
"user": {
"name": "ops_admin",
"target": {
"name": "migration_ro"
}
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Generate the recurring temporary-role payroll chain; false emits only background |
| anomaly_interval_hours | 24 | Hours between episode due times, from the previous actual start; 6 to 8,760 |
| host_name | cassandra-01.example.test | Node name in host.name |
| host_ip | 10.20.30.10 | Node broadcast address in the host audit field |
Related Generators
Microsoft SQL Server Audit
SQL Server Audit via Windows Event ID 33205 — login/logout lifecycle, DML queries (SELECT/INSERT/UPDATE/DELETE), stored procedure execution, schema changes (CREATE/ALTER/DROP), permission management (GRANT/DENY/REVOKE), role membership, backups, DBCC commands, and password changes.
MySQL Audit
MySQL Enterprise Audit Plugin events (ECS-compatible JSON) covering all four audit classes — connection, general, table_access, and audit. Generates connect/disconnect lifecycle, DML queries (SELECT/INSERT/UPDATE/DELETE), table access tracking, DDL schema changes, GRANT/REVOKE privileges, admin commands, query errors, and failed authentication attempts with realistic query statistics.
PostgreSQL Audit Logs
PostgreSQL with pgAudit — SELECT/INSERT/UPDATE/DELETE queries with parameterized statements, connection lifecycle, authentication failures, DDL operations, role management (GRANT/REVOKE), and database errors (deadlocks, constraint violations).