Identity Data Store Documentation Index
Configuration Reference Home

JDBC Based Access Log Publisher

JDBC Based Access Log Publishers store access log information using a JDBC database connection.

JDBC Based Access Log Publishers store filtered access log information to a database table using a JDBC connection. There are two additional configuration items to complete for a JDBC Based Access Log Publisher. First, you will need to decide what fields to log. You can use or copy one of the provided Log Field Mapping configurations. Any field that has a database column specified will be logged. If no field is specified, then it will not be logged. To aid in database table creation, an example database DDL is written to a file at the root of the server installation directory under 'logs/ddls'. Second, you will need to specify the connection parameters to a database using the JDBC External Server configuration.

Parent Component
Relations To this Component
Properties
dsconfig Usage

Parent Component

The JDBC Based Access Log Publisher component inherits from the Log Publisher

Relations from This Component

The following components have a direct aggregation relation from JDBC Based Access Log Publishers:

Properties

The properties supported by this managed object are as follows:


Basic Properties: Advanced Properties:
↓ description ↓ queue-size
↓ enabled
↓ suppress-internal-operations
↓ suppress-replication-operations
↓ log-connects
↓ log-disconnects
↓ log-security-negotiation
↓ log-client-certificates
↓ log-requests
↓ log-results
↓ log-search-entries
↓ log-search-references
↓ log-intermediate-responses
↓ connection-criteria
↓ request-criteria
↓ result-criteria
↓ search-entry-criteria
↓ search-reference-criteria
↓ correlate-requests-and-results
↓ server
↓ log-field-mapping
↓ log-table-name

Basic Properties

description

Description
A description for this Log Publisher
Default Value
None
Allowed Values
A string
Multi-Valued
No
Required
No
Admin Action Required
None. Modification requires no further action

enabled

Description
Indicates whether the Log Publisher is enabled for use.
Default Value
None
Allowed Values
true
false
Multi-Valued
No
Required
Yes
Admin Action Required
None. Modification requires no further action

suppress-internal-operations

Description
Indicates whether internal operations (for example, operations that are initiated by plugins) should be logged along with the operations that are requested by users.
Default Value
true
Allowed Values
true
false
Multi-Valued
No
Required
No
Admin Action Required
None. Modification requires no further action

suppress-replication-operations

Description
Indicates whether access messages that are generated by replication operations should be suppressed.
Default Value
false
Allowed Values
true
false
Multi-Valued
No
Required
No
Admin Action Required
None. Modification requires no further action

log-connects

Description
Indicates whether to log information about connections established to the server.
Default Value
true
Allowed Values
true
false
Multi-Valued
No
Required
No
Admin Action Required
None. Modification requires no further action

log-disconnects

Description
Indicates whether to log information about connections that have been closed by the client or terminated by the server.
Default Value
true
Allowed Values
true
false
Multi-Valued
No
Required
No
Admin Action Required
None. Modification requires no further action

log-security-negotiation

Description
Indicates whether to log information about the result of any security negotiation (e.g., SSL handshake) processing that has been performed.
Default Value
false
Allowed Values
true
false
Multi-Valued
No
Required
No
Admin Action Required
None. Modification requires no further action

log-client-certificates

Description
Indicates whether to log information about any client certificates presented to the server.
Default Value
true
Allowed Values
true
false
Multi-Valued
No
Required
No
Admin Action Required
None. Modification requires no further action

log-requests

Description
Indicates whether to log information about requests received from clients.
Default Value
true
Allowed Values
true
false
Multi-Valued
No
Required
No
Admin Action Required
None. Modification requires no further action

log-results

Description
Indicates whether to log information about the results of client requests.
Default Value
true
Allowed Values
true
false
Multi-Valued
No
Required
No
Admin Action Required
None. Modification requires no further action

log-search-entries

Description
Indicates whether to log information about search result entries sent to the client.
Default Value
false
Allowed Values
true
false
Multi-Valued
No
Required
No
Admin Action Required
None. Modification requires no further action

log-search-references

Description
Indicates whether to log information about search result references sent to the client.
Default Value
false
Allowed Values
true
false
Multi-Valued
No
Required
No
Admin Action Required
None. Modification requires no further action

log-intermediate-responses

Description
Indicates whether to log information about intermediate responses sent to the client.
Default Value
false
Allowed Values
true
false
Multi-Valued
No
Required
No
Admin Action Required
None. Modification requires no further action

connection-criteria

Description
Specifies a set of connection criteria that must match the associated client connection in order for a connect, disconnect, request, or result message to be logged.
Default Value
None
Allowed Values
The DN of any Connection Criteria.
Multi-Valued
No
Required
No
Admin Action Required
None. Modification requires no further action

request-criteria

Description
Specifies a set of request criteria that must match the associated operation request in order for a request or result to be logged by this Log Publisher.
Default Value
None
Allowed Values
The DN of any Request Criteria.
Multi-Valued
No
Required
No
Admin Action Required
None. Modification requires no further action

result-criteria

Description
Specifies a set of result criteria that must match the associated operation result in order for that result to be logged by this Log Publisher.
Default Value
None
Allowed Values
The DN of any Result Criteria.
Multi-Valued
No
Required
No
Admin Action Required
None. Modification requires no further action

search-entry-criteria

Description
Specifies a set of search entry criteria that must match the associated search result entry in order for that it to be logged by this Log Publisher.
Default Value
None
Allowed Values
The DN of any Search Entry Criteria.
Multi-Valued
No
Required
No
Admin Action Required
None. Modification requires no further action

search-reference-criteria

Description
Specifies a set of search reference criteria that must match the associated search result reference in order for that it to be logged by this Log Publisher.
Default Value
None
Allowed Values
The DN of any Search Reference Criteria.
Multi-Valued
No
Required
No
Admin Action Required
None. Modification requires no further action

correlate-requests-and-results

Description
Indicates whether to automatically log result messages for any operation in which the corresponding request was logged. In such cases, the result, entry, and reference criteria will be ignored, although the log-responses, log-search-entries, and log-search-references properties will be honored.
Default Value
true
Allowed Values
true
false
Multi-Valued
No
Required
No
Admin Action Required
None. Modification requires no further action

server

Description
The JDBC-based Database Server to use for a connection.
Default Value
None
Allowed Values
The DN of any JDBC External Server.
Multi-Valued
No
Required
Yes
Admin Action Required
None. Modification requires no further action

log-field-mapping

Description
The log field mapping associates loggable fields to database column names. The table name is not part of this mapping. You will need to decide what fields to log to the JDBC Based Access Log Publisher. You can use or copy one of the provided Log Field Mapping configurations. Any field that has a database column specified will be logged. If no field is specified, then it will not be logged. To aid in database table creation, an example database DDL is written to a file at the root of the server installation directory under 'logs/ddls'.
Default Value
None
Allowed Values
The DN of any Access Log Field Mapping.
Multi-Valued
No
Required
Yes
Admin Action Required
None. Modification requires no further action

log-table-name

Description
The table name to log entries to the database server.
Default Value
access_log
Allowed Values
A string
Multi-Valued
No
Required
Yes
Admin Action Required
None. Modification requires no further action


Advanced Properties

queue-size (Advanced Property)

Description
The maximum number of log records that can be stored in the asynchronous queue. The server will continuously flush messages from the queue to the log. That is, it does not wait for the queue to fill up before flushing to the log. Lowering this value can impact performance.
Default Value
10000
Allowed Values
An integer value. Lower limit is 1000. Upper limit is 100000 .
Multi-Valued
No
Required
No
Admin Action Required
The JDBC Based Access Log Publisher must be restarted if this property is changed and the asynchronous property is set to true.


dsconfig Usage

To list the configured Log Publishers:

dsconfig list-log-publishers
     [--property {propertyName}] ...

To view the configuration for an existing Log Publisher:

dsconfig get-log-publisher-prop
     --publisher-name {name}
     [--tab-delimited]
     [--script-friendly]
     [--property {propertyName}] ...

To update the configuration for an existing Log Publisher:

dsconfig set-log-publisher-prop
     --publisher-name {name}
     (--set|--add|--remove) {propertyName}:{propertyValue}
     [(--set|--add|--remove) {propertyName}:{propertyValue}] ...

To create a new JDBC Based Access Log Publisher:

dsconfig create-log-publisher
     --publisher-name {name}
     --type jdbc-based
     --set enabled:{propertyValue}
     --set server:{propertyValue}
     --set log-field-mapping:{propertyValue}
     [--set {propertyName}:{propertyValue}] ...

To delete an existing Log Publisher:

dsconfig delete-log-publisher
     --publisher-name {name}