Audit: Configuration Reference

Select an Audit Service Configuration Instance

Select from the following list of configuration instances to find the values in that category.

  • sas.audit.reporting.activities configures the copy of activity records from the audit service to CAS and sets their retention period.
  • sas.audit.archive.process configures the archive transfer job, retention in the CAS database audit service, and retention in the audit archive.
  • sas.audit.archive.system specifies the location of the audit archive and the available-storage limit.
  • sas.audit.purge enables purge and sets the audit purge schedule.
  • sas.audit.record determines whether READ actions create audit records and specifies the amount of information that is stored in activity records.
  • sas.audit.reporting configures the copy of records to the CAS server for reporting.
  • sas.audit.poller polls the pending audit data retrieval jobs list and sends the oldest for processing.

Audit Activities

sas.audit.reporting.activities

Definition

Description

Default

enabled

Enables the copying of records from the audit database to CAS for the creation of reports.

True

query.page.size

Specifies the number of records that are copied from the audit database to CAS for the creation of reports.

5,000

refresh.schedule

Schedules the job that copies records from the audit database to CAS.

*/30 * * * *

The default value uses standard cron syntax to refresh CAS every 30 minutes. A value of 0 */1 * * * refreshes CAS every hour.

retention

Specifies the length of time that activity records are retained in the SystemData database in CAS. The retention value must be equal to, or less than, the value of activity.retention in sas.audit.archive.process.

180d

sas.audit.archive.process

Definition

Description

Default Value

activity.retention

Specifies the length of time that activity records are retained in the audit database. The value of activity.retention must be greater than, or equal to, the retention value in sas.audit.reporting.activities.

365d

One year

activity.retention.in.archive

Specifies the length of time that activity records are retained in the audit archive.

1827d

Five years

audit.retention

Specifies the length of time that audit records are retained in the audit database. The value of audit.retention must be greater than, or equal to, the retention value in sas.audit.reporting.

IMPORTANT Increasing the value of audit.retention increases the volume of data in the audit database. The increased volume in the audit database leads to a decrease in system performance. Instead of increasing retention in the audit database, SAS recommends that you attach a persistent volume and set the property storageType to Local. The PV makes audit data available without increasing database volume.

7d

audit.retention.in.archive

Specifies the length of time that audit records are retained in the audit archive.

1827d

batchSize

Specifies the maximum number of audit and activity records that are processed in a single batch by an instance of the archive job. Also specifies the maximum number of records in a daily archive file.

1,000

enabled

Enables or disables the transfer of audit and activity records from the audit database to the audit archive.

On

scanSchedule

Schedules the job that transfers audit and activity records from the audit database to the audit archive.

0 0 * * *

Cron syntax transfers records to the archive each night at midnight. See also sas.audit.archive.system.

storageType

The default value none deletes expired records from the database without archiving. Use the value local to archive expired records to an attached PV. To attach a PV, see Initial Task: Enable the Optional Audit Archive.

none | local

Audit Entries

sas.audit.archive.system

Definition

Description

Default Value

storage.local.destination

Specifies the audit archive storage location.

/auditData

storage.local.remainingSpaceThreshold

Specifies the percentage of available storage in the archive PV that triggers a notification. For example, a value of 20 generates a notification in SAS Environment Manager when the size of the archive file system exceeds 80% of the PV. When the threshold is exceeded, transfers from the database to the archive continue as scheduled until PV storage reaches 100%. When the PV is full, transfers cease, timed-out records in the database are discarded, and another notification is generated.

25

sas.audit.archive.process

Definition

Description

Default Value

activity.retention

Specifies the length of time that activity records are retained in the audit database. The value of activity.retention must be greater than, or equal to, the retention value in sas.audit.reporting.activities.

365d

One year

activity.retention.in.archive

Specifies the length of time that activity records are retained in the audit archive.

1827d

Five years

batchSize

Specifies the maximum number of audit and activity records that are processed in a single batch by an instance of the archive job. Also specifies the maximum number of records in a daily archive file.

1,000

enabled

Enables or disables the transfer of audit and activity records from the audit database to the audit archive.

On

scanSchedule

Schedules the job that transfers audit and activity records from the audit database to the audit archive.

0 0 * * *

Cron syntax transfers records to the archive each night at midnight. See also sas.audit.archive.system.

storageType

The default value none deletes expired records from the database without archiving. Use the value local to archive expired records to an attached PV. To attach a PV, see Initial Task: Enable the Optional Audit Archive.

none | local

sas.audit.purge

Definition

Description

Default Value

enabled

Enables the purging of records from the audit archive.

On

purgeSchedule

Schedules the job that purges expired records from the audit archive.

0 0 * * *

Cron syntax purges the archive each night at midnight.

sas.audit.record

Definition

Description

Default

activities.exclusion list

Comma-separated list of service names for which activity events will not be recorded.

None

activity.recording.level

Specifies a value that determines the number of activity records that are created in response to incoming activity events. Valid values are low, medium, high, and disabled. Select disabled to prevent the creation of activity records. Select other values according to the number of activity records you need to collect.

high

audit.exclusion.list

Comma-separated list of service names for which resource-type audit events will not be recorded.

None

audit.recording.level

Specifies a value that determines the number of audit records that are created by incoming resource and security events. Valid values are low, medium, high, and disabled. Select disabled to prevent the creation of audit records. Select other values according to the number of audit records you need to collect.

IMPORTANT Do not set audit.recording.level to HIGH. The HIGH setting results in a large increase in new audit records, which can degrade system performance and overload the audit database. To generate audit records for READ events, use the following services.list configuration property to target a small subset of SAS Viya services.

To learn how resource and security events become audit records, see Configure the Creation of Audit Records.

Disabled

services.list

Specifies a comma-separated list of serviceNames. All READ events from each named service generate audit or activity records in the audit database. These READ-access records are created without regard to activity.recording.level or audit.recording.level. To return a list of valid serviceNames, use the following command:

kubectl -n viya exec -it sas-rabbitmq-server-0 
  -- /opt/sas/viya/home/bin/sas-bootstrap-config 
  catalog services | grep serviceName

None

sas.audit.reporting

Definition

Description

Default

app.list

Specifies the applications whose audit records are copied from the audit database into SystemData. The records in SystemData are read by CAS to generate the User Activity Report and other reports.

The value of this configuration instance is a comma-separated list of serviceNames. To return a list of available serviceNames, enter the following command:

kubectl -n viya exec -it sas-rabbitmq-server-0 
  -- /opt/sas/viya/home/bin/sas-bootstrap-config 
  catalog services | grep serviceName

reports, dataPlans, casManagement, casAccessManagement, SASLogon

enabled

Enables the copying of audit records from the audit database to CAS.

True

include.app.records

Determines whether audit records from SAS applications are copied from the audit database to CAS.

true

query.page.size

Specifies the maximum number of audit records that are copied from the audit database to CAS in a single job.

5,000

refresh.schedule

Schedules the job that copies audit records into CAS.

0 */2 * * *

The default value uses standard cron syntax to refresh the audit database every two hours. A value of */30 * * * * refreshes the database every 30 minutes.

retention

Specifies the length of time that audit records are retained in SystemData as source data for reports that are generated by CAS. The retention value must be equal to, or less than, the value of the audit.retention value in sas.audit.archive.process.

7d

sas.audit.poller

Definition

Description

Default

schedule

Schedules poller job to check for jobs that are in progress or eligible to be retried. Jobs that don't complete are rerun three times before being marked as failed.

0 */5 * * * *

The schedule uses 6-field cron format.

Last updated: September 14, 2026