Audit Logging — Complete Guide
Audit Logging — Complete Guide: free step-by-step lesson with examples, common mistakes, and interview tips — part of PostgreSQL Tutorial on Toolliyo Academy.
On this page
PostgreSQL Tutorial · Lesson 75 of 100
Audit Logging
SQL ✓ → Advanced
Advanced · 2 — Production · ~10 min · PostgreSQL — Security & Cloud
What is this?
Audit logging records database events — pgaudit extension for DDL/DML/read logging, log_connections, and CSV log analysis to SIEM.
Why should you care?
PostgresVerse bank must prove who ran DROP TABLE — pgaudit object audit feeds Splunk alerts.
See it live — copy this example
Run in pgAdmin or psql.
# postgresql.conf (conceptual)
shared_preload_libraries = 'pgaudit'
pgaudit.log = 'ddl, role'
pgaudit.log_relation = on
-- after reload, run:
CREATE TABLE audit_test (id int);
DROP TABLE audit_test;
Run Example »
This lesson uses terminal or setup steps. Run commands on your computer — the live editor appears on coding lessons.
What happened?
- pgaudit logs DDL like CREATE/DROP to server log with user and timestamp.
- log_relation adds table names.
- SIEM parses postgresql-*.log for compliance.
Practice next
- Install pgaudit if available on your build.
- Set config and reload postgres.
- Run DDL sample and tail log file.
- pgaudit.log_catalog off to reduce noise.
- Test alert on DROP TABLE pattern in log pipeline.
Remember
pgaudit extends standard logging for compliance. Filter classes: ddl, write, read, role. Correlate with pg_stat_activity session ids.
PostgresVerse SOC integration
DROP in production triggers PagerDuty from pgaudit log within 60s.
Outcome: Insider threat and compromised creds detected fast.
Interview prep for this lesson
Practice these questions aloud after reading—each links to a full structured answer.
Sign in to ask a question or upvote helpful answers.
No questions yet — be the first to ask!