<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Audit logs theory in Log Analytics</title>
    <link>https://community.dynatrace.com/t5/Log-Analytics/Audit-logs-theory/m-p/115807#M818</link>
    <description>&lt;P&gt;Hey, &lt;/P&gt;&lt;P&gt;Each clustered node will have its own set of log files/Audit logs these are the same across all 3 clustered nodes.&lt;/P&gt;</description>
    <pubDate>Tue, 25 Aug 2020 15:50:29 GMT</pubDate>
    <dc:creator>ChadTurner</dc:creator>
    <dc:date>2020-08-25T15:50:29Z</dc:date>
    <item>
      <title>Audit logs theory</title>
      <link>https://community.dynatrace.com/t5/Log-Analytics/Audit-logs-theory/m-p/115804#M815</link>
      <description>&lt;P&gt;Hello there! I have some questions about auditr logs. Please share your ideas.&lt;/P&gt;&lt;P&gt;1. Are audit events duplicated in the API of different environments (for example, the login of a user who has access to multiple environments)?&lt;/P&gt;&lt;P&gt;2. How much does the load on the cluster change when enabling audit log?&lt;/P&gt;&lt;P&gt;3. Duplicate the audit logs on the nodes of the cluster?&lt;/P&gt;&lt;P&gt;4. What is the principle for choosing which cluster node to write audit logs on?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2020 10:36:53 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Log-Analytics/Audit-logs-theory/m-p/115804#M815</guid>
      <dc:creator>IvanVovk</dc:creator>
      <dc:date>2020-08-17T10:36:53Z</dc:date>
    </item>
    <item>
      <title>Re: Audit logs theory</title>
      <link>https://community.dynatrace.com/t5/Log-Analytics/Audit-logs-theory/m-p/115805#M816</link>
      <description>&lt;P&gt;In instances where multiple nodes make up a cluster, it is my understanding that:&lt;/P&gt;&lt;P&gt;1.) Log files are duplicated on each node in the event that a node goes offline. Much like monitoring metrics, the host syncs up with the other ones once it is back up and running. &lt;/P&gt;&lt;P&gt;2.) Dynatrace has allotted enough space for log files, i would recommend following their sizing chart: &lt;A rel="noopener noreferrer" href="https://www.dynatrace.com/support/help/setup-and-configuration/dynatrace-managed/installation/dynatrace-managed-hardware-and-system-requirements/" target="_blank"&gt;Requirements &lt;/A&gt;&lt;/P&gt;&lt;P&gt;3.) This is part of # 1&lt;/P&gt;&lt;P&gt;4.) I am not aware of the ability to point a single node as the "Log writer" the nodes should be redundant so if Node A goes down with all the data on it, that data is mirrored on Node B and Node C which will seamlessly take over with host metrics and log files. &lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 12:21:13 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Log-Analytics/Audit-logs-theory/m-p/115805#M816</guid>
      <dc:creator>ChadTurner</dc:creator>
      <dc:date>2020-08-20T12:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: Audit logs theory</title>
      <link>https://community.dynatrace.com/t5/Log-Analytics/Audit-logs-theory/m-p/115806#M817</link>
      <description>&lt;P&gt;Hello Chad. Thanks for your answer.&lt;/P&gt;&lt;P&gt;Can you a bit more explain the first point. &lt;/P&gt;&lt;P&gt;Are audit events duplicated in the different environment API in case of user login? &lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 12:11:38 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Log-Analytics/Audit-logs-theory/m-p/115806#M817</guid>
      <dc:creator>IvanVovk</dc:creator>
      <dc:date>2020-08-25T12:11:38Z</dc:date>
    </item>
    <item>
      <title>Re: Audit logs theory</title>
      <link>https://community.dynatrace.com/t5/Log-Analytics/Audit-logs-theory/m-p/115807#M818</link>
      <description>&lt;P&gt;Hey, &lt;/P&gt;&lt;P&gt;Each clustered node will have its own set of log files/Audit logs these are the same across all 3 clustered nodes.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 15:50:29 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Log-Analytics/Audit-logs-theory/m-p/115807#M818</guid>
      <dc:creator>ChadTurner</dc:creator>
      <dc:date>2020-08-25T15:50:29Z</dc:date>
    </item>
  </channel>
</rss>

