<!-- CANARY: REQ=REQ-SERVER-STARTUP-INTEGRATION-001; FEATURE="Server Startup Integration Tests"; ASPECT=EndToEndServerTesting; STATUS=TESTED; OWNER=server; UPDATED=2025-10-05 -->
<h3 id="overview" class="position-relative d-flex align-items-center group">
<span>Overview</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="overview"
aria-haspopup="dialog"
aria-label="Share link: Overview">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h3><div id="headingShareModal" class="heading-share-modal" role="dialog" aria-modal="true" aria-labelledby="headingShareTitle" hidden>
<div class="hsm-dialog" role="document">
<div class="hsm-header">
<h2 id="headingShareTitle" class="h6 mb-0 fw-bold">Share this section</h2>
<button type="button" class="hsm-close" aria-label="Close">
<i class="fa-solid fa-xmark"></i>
</button>
</div>
<div class="hsm-body">
<label for="headingShareInput" class="form-label small text-muted mb-1 text-uppercase fw-bold" style="font-size: 0.7rem; letter-spacing: 0.5px;">Permalink</label>
<div class="input-group mb-4 hsm-url-group">
<input id="headingShareInput" type="text" class="form-control font-monospace" readonly aria-readonly="true" style="font-size: 0.85rem;" />
<button class="btn btn-primary hsm-copy" type="button" aria-label="Copy" title="Copy">
<i class="fa-duotone fa-clipboard" aria-hidden="true"></i>
</button>
</div>
<div class="small fw-bold mb-2 text-muted text-uppercase" style="font-size: 0.7rem; letter-spacing: 0.5px;">Share via</div>
<div class="hsm-share-grid">
<a id="share-twitter" class="btn btn-outline-secondary w-100" target="_blank" rel="noopener noreferrer">
<i class="fa-brands fa-twitter me-2"></i>Twitter
</a>
<a id="share-linkedin" class="btn btn-outline-secondary w-100" target="_blank" rel="noopener noreferrer">
<i class="fa-brands fa-linkedin me-2"></i>LinkedIn
</a>
<a id="share-facebook" class="btn btn-outline-secondary w-100" target="_blank" rel="noopener noreferrer">
<i class="fa-brands fa-facebook me-2"></i>Facebook
</a>
</div>
</div>
</div>
</div>
<style>
.heading-share-modal {
position: fixed;
inset: 0;
display: flex;
justify-content: center;
align-items: center;
background: rgba(0, 0, 0, 0.6);
z-index: 1050;
padding: 1rem;
backdrop-filter: blur(4px);
-webkit-backdrop-filter: blur(4px);
}
.heading-share-modal[hidden] { display: none !important; }
.hsm-dialog {
max-width: 420px;
width: 100%;
background: var(--bs-body-bg, #fff);
color: var(--bs-body-color, #212529);
border: 1px solid var(--bs-border-color, rgba(0,0,0,0.1));
border-radius: 1rem;
box-shadow: 0 25px 50px -12px rgba(0, 0, 0, 0.25);
overflow: hidden;
animation: hsm-fade-in 0.2s ease-out;
}
@keyframes hsm-fade-in {
from { opacity: 0; transform: scale(0.95); }
to { opacity: 1; transform: scale(1); }
}
[data-bs-theme="dark"] .hsm-dialog {
background: #1e293b;
border-color: rgba(255,255,255,0.1);
color: #f8f9fa;
}
.hsm-header {
display: flex;
justify-content: space-between;
align-items: center;
padding: 1rem 1.5rem;
border-bottom: 1px solid var(--bs-border-color, rgba(0,0,0,0.1));
background: rgba(0,0,0,0.02);
}
[data-bs-theme="dark"] .hsm-header {
background: rgba(255,255,255,0.02);
border-color: rgba(255,255,255,0.1);
}
.hsm-close {
background: transparent;
border: none;
color: inherit;
opacity: 0.5;
padding: 0.25rem 0.5rem;
border-radius: 0.25rem;
font-size: 1.2rem;
line-height: 1;
transition: opacity 0.2s;
}
.hsm-close:hover {
opacity: 1;
}
.hsm-body {
padding: 1.5rem;
}
.hsm-url-group {
display: flex !important;
align-items: stretch;
}
.hsm-url-group .form-control {
flex: 1;
min-width: 0;
margin: 0;
background: var(--bs-secondary-bg, #f8f9fa);
border-color: var(--bs-border-color, #dee2e6);
border-top-right-radius: 0;
border-bottom-right-radius: 0;
height: 42px;
}
.hsm-url-group .btn {
flex: 0 0 auto;
margin: 0;
margin-left: -1px;
border-top-left-radius: 0;
border-bottom-left-radius: 0;
height: 42px;
display: flex;
align-items: center;
justify-content: center;
padding: 0 1.25rem;
z-index: 2;
}
[data-bs-theme="dark"] .hsm-url-group .form-control {
background: #0f172a;
border-color: #334155;
color: #e2e8f0;
}
.hsm-share-grid {
display: flex;
flex-direction: column;
gap: 0.5rem;
}
.hsm-share-grid .btn {
display: flex;
align-items: center;
justify-content: center;
font-size: 0.9rem;
padding: 0.6rem;
border-color: var(--bs-border-color);
width: 100%;
}
[data-bs-theme="dark"] .hsm-share-grid .btn {
color: #e2e8f0;
border-color: #475569;
}
[data-bs-theme="dark"] .hsm-share-grid .btn:hover {
background: #334155;
border-color: #cbd5e1;
}
</style>
<script>
(function(){
const modal = document.getElementById('headingShareModal');
if(!modal) return;
const input = modal.querySelector('#headingShareInput');
const copyBtn = modal.querySelector('.hsm-copy');
const twitter = modal.querySelector('#share-twitter');
const linkedin = modal.querySelector('#share-linkedin');
const facebook = modal.querySelector('#share-facebook');
const closeBtn = modal.querySelector('.hsm-close');
let lastFocus=null;
let trapBound=false;
function buildUrl(id){ return window.location.origin + window.location.pathname + '#' + id; }
function isOpen(){ return !modal.hasAttribute('hidden'); }
function hydrate(id){
const url=buildUrl(id);
input.value=url;
const enc=encodeURIComponent(url);
const text=encodeURIComponent(document.title);
if(twitter) twitter.href=`https://twitter.com/intent/tweet?url=${enc}&text=${text}`;
if(linkedin) linkedin.href=`https://www.linkedin.com/sharing/share-offsite/?url=${enc}`;
if(facebook) facebook.href=`https://www.facebook.com/sharer/sharer.php?u=${enc}`;
}
function openModal(id){
lastFocus=document.activeElement;
hydrate(id);
if(!isOpen()){
modal.removeAttribute('hidden');
}
requestAnimationFrame(()=>{ input.focus(); });
trapFocus();
}
function closeModal(){
if(!isOpen()) return;
modal.setAttribute('hidden','');
if(lastFocus && typeof lastFocus.focus==='function') lastFocus.focus();
}
function copyCurrent(){
try{ navigator.clipboard.writeText(input.value).then(()=>feedback(true),()=>fallback()); }
catch(e){ fallback(); }
}
function fallback(){ input.select(); try{ document.execCommand('copy'); feedback(true);}catch(e){ feedback(false);} }
function feedback(ok){ if(!copyBtn) return; const icon=copyBtn.querySelector('i'); if(!icon) return; const prev=copyBtn.getAttribute('data-prev')||icon.className; if(!copyBtn.getAttribute('data-prev')) copyBtn.setAttribute('data-prev',prev); icon.className= ok ? 'fa-duotone fa-clipboard-check':'fa-duotone fa-circle-exclamation'; setTimeout(()=>{ icon.className=prev; },1800); }
function handleShareClick(e){ e.preventDefault(); const btn=e.currentTarget; const id=btn.getAttribute('data-share-target'); if(id) openModal(id); }
function bindShareButtons(){
document.querySelectorAll('.h-share').forEach(btn=>{
if(!btn.dataset.hShareBound){ btn.addEventListener('click', handleShareClick); btn.dataset.hShareBound='1'; }
});
}
bindShareButtons();
if(document.readyState==='loading'){
document.addEventListener('DOMContentLoaded', bindShareButtons);
} else {
requestAnimationFrame(bindShareButtons);
}
document.addEventListener('click', function(e){
const shareBtn=e.target.closest && e.target.closest('.h-share');
if(shareBtn && !shareBtn.dataset.hShareBound){ handleShareClick.call(shareBtn, e); }
}, true);
document.addEventListener('click', e=>{
if(e.target===modal) closeModal();
if(e.target.closest && e.target.closest('.hsm-close')){ e.preventDefault(); closeModal(); }
if(copyBtn && (e.target===copyBtn || (e.target.closest && e.target.closest('.hsm-copy')))) { e.preventDefault(); copyCurrent(); }
});
document.addEventListener('keydown', e=>{ if(e.key==='Escape' && isOpen()) closeModal(); });
function trapFocus(){
if(trapBound) return;
trapBound=true;
modal.addEventListener('keydown', f=>{ if(f.key==='Tab' && isOpen()){ const focusable=[...modal.querySelectorAll('a[href],button,input,textarea,select,[tabindex]:not([tabindex="-1"])')].filter(el=>!el.hasAttribute('disabled')); if(!focusable.length) return; const first=focusable[0]; const last=focusable[focusable.length-1]; if(f.shiftKey && document.activeElement===first){ f.preventDefault(); last.focus(); } else if(!f.shiftKey && document.activeElement===last){ f.preventDefault(); first.focus(); } } });
}
if(closeBtn) closeBtn.addEventListener('click', e=>{ e.preventDefault(); closeModal(); });
})();
</script><p>Geode provides a comprehensive, security-first audit logging and tracing subsystem designed for enterprise compliance and operational security. The system instruments authentication actions and database operations, emitting structured logs with tamper-evident guarantees through cryptographic hash chains and digital signatures.</p>
<h4 id="key-features" class="position-relative d-flex align-items-center group">
<span>Key Features</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="key-features"
aria-haspopup="dialog"
aria-label="Share link: Key Features">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p><strong>Security-First Design</strong>:</p>
<ul>
<li>Default-deny filtration with built-in sensitive data redaction</li>
<li>Tamper-evident logging with hash chains and Ed25519 signatures</li>
<li>Fail-closed security: drops events if redaction cannot guarantee safety</li>
<li>No SQL exposure: database adapter never logs query text or parameters</li>
</ul>
<p><strong>Enterprise Integration</strong>:</p>
<ul>
<li>RFC 5424 Syslog with UDP/TCP transport</li>
<li>CEF:0 (Common Event Format) payloads for SIEM compatibility</li>
<li>Structured JSON-Lines format with deterministic field ordering</li>
<li>File rotation with configurable retention and backup policies</li>
</ul>
<p><strong>Operational Excellence</strong>:</p>
<ul>
<li>Non-blocking operations with bounded queues</li>
<li>W3C distributed tracing support (trace_id and span_id propagation)</li>
<li>Automatic field detection and PII/PCI redaction</li>
<li><500μs append latency (excluding fsync)</li>
</ul>
<h3 id="architecture" class="position-relative d-flex align-items-center group">
<span>Architecture</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="architecture"
aria-haspopup="dialog"
aria-label="Share link: Architecture">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h3>
<h4 id="components" class="position-relative d-flex align-items-center group">
<span>Components</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="components"
aria-haspopup="dialog"
aria-label="Share link: Components">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><div class="highlight"><pre tabindex="0" class="chroma"><code class="language-fallback" data-lang="fallback"><span class="line"><span class="cl">AuditLogger
</span></span><span class="line"><span class="cl">├── EventBuffer - Bounded queue for non-blocking writes
</span></span><span class="line"><span class="cl">├── FileRotator - Size/time-based rotation with backups
</span></span><span class="line"><span class="cl">├── HashChain - SHA-256/BLAKE3 chain with prev_hash linking
</span></span><span class="line"><span class="cl">├── SignatureManager - Ed25519 signing for Merkle digest records
</span></span><span class="line"><span class="cl">├── RedactionEngine - Multi-layer sensitive data protection
</span></span><span class="line"><span class="cl">└── SyslogTransport - RFC 5424 UDP/TCP syslog integration
</span></span></code></pre></div>
<h4 id="data-flow" class="position-relative d-flex align-items-center group">
<span>Data Flow</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="data-flow"
aria-haspopup="dialog"
aria-label="Share link: Data Flow">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><div class="highlight"><pre tabindex="0" class="chroma"><code class="language-plaintext" data-lang="plaintext"><span class="line"><span class="cl">1. Application Event → AuditLogger.audit()
</span></span><span class="line"><span class="cl">2. Redaction Engine → Strip PII/PCI, apply default-deny filters
</span></span><span class="line"><span class="cl">3. Event Buffer → Non-blocking enqueue (drop on overflow)
</span></span><span class="line"><span class="cl">4. Hash Chain → Compute event_hash, link with prev_hash
</span></span><span class="line"><span class="cl">5. File Append → Write canonical JSON line (0600 permissions)
</span></span><span class="line"><span class="cl">6. Signature Manager → Every 100 events, compute Merkle digest + sign
</span></span><span class="line"><span class="cl">7. Syslog Transport → Send to remote syslog server (parallel)
</span></span><span class="line"><span class="cl">8. File Rotation → Rotate on size threshold, preserve chain continuity
</span></span></code></pre></div>
<h3 id="hash-chain--verification" class="position-relative d-flex align-items-center group">
<span>Hash Chain &amp; Verification</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="hash-chain--verification"
aria-haspopup="dialog"
aria-label="Share link: Hash Chain &amp; Verification">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h3>
<h4 id="tamper-evident-design" class="position-relative d-flex align-items-center group">
<span>Tamper-Evident Design</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="tamper-evident-design"
aria-haspopup="dialog"
aria-label="Share link: Tamper-Evident Design">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p>Geode’s audit stream is a canonical JSON Lines (JSONL) append-only log where each record carries:</p>
<ul>
<li><strong>seq_no</strong>: Monotonically increasing sequence number</li>
<li><strong>event_hash</strong>: SHA-256 hash of current event (excluding prev_hash)</li>
<li><strong>prev_hash</strong>: Hash of previous event’s event_hash</li>
<li><strong>signature</strong>: Ed25519 signature on Merkle digest (every 100 events)</li>
</ul>
<p>This creates a cryptographic chain: modifying any past event breaks the chain and invalidates all subsequent signatures.</p>
<h4 id="record-structure" class="position-relative d-flex align-items-center group">
<span>Record Structure</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="record-structure"
aria-haspopup="dialog"
aria-label="Share link: Record Structure">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p><strong>Canonical Key Order</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-json" data-lang="json"><span class="line"><span class="cl"><span class="p">[</span>
</span></span><span class="line"><span class="cl"> <span class="s2">"stream"</span><span class="p">,</span> <span class="s2">"seq_no"</span><span class="p">,</span> <span class="s2">"timestamp"</span><span class="p">,</span> <span class="s2">"event_type"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="s2">"actor"</span><span class="p">,</span> <span class="s2">"origin"</span><span class="p">,</span> <span class="s2">"resource"</span><span class="p">,</span> <span class="s2">"action"</span><span class="p">,</span> <span class="s2">"result"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="s2">"details"</span><span class="p">,</span> <span class="s2">"prev_hash"</span><span class="p">,</span> <span class="s2">"event_hash"</span><span class="p">,</span> <span class="s2">"signature"</span>
</span></span><span class="line"><span class="cl"><span class="p">]</span>
</span></span></code></pre></div><p><strong>Example Event</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-json" data-lang="json"><span class="line"><span class="cl"><span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"stream"</span><span class="p">:</span> <span class="s2">"geode-audit"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"seq_no"</span><span class="p">:</span> <span class="mi">42</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"timestamp"</span><span class="p">:</span> <span class="s2">"2026-01-24T10:30:15.123Z"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"event_type"</span><span class="p">:</span> <span class="s2">"auth.login"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"actor"</span><span class="p">:</span> <span class="s2">"[email protected]"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"origin"</span><span class="p">:</span> <span class="s2">"192.168.1.100"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"resource"</span><span class="p">:</span> <span class="s2">"database:geode"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"action"</span><span class="p">:</span> <span class="s2">"authenticate"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"result"</span><span class="p">:</span> <span class="s2">"success"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"details"</span><span class="p">:</span> <span class="p">{</span><span class="nt">"role"</span><span class="p">:</span> <span class="s2">"admin"</span><span class="p">,</span> <span class="nt">"session_id"</span><span class="p">:</span> <span class="s2">"ses-abc123"</span><span class="p">},</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"prev_hash"</span><span class="p">:</span> <span class="s2">"e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"event_hash"</span><span class="p">:</span> <span class="s2">"a3c7f1d2e5b4a8c9f0d1e2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"signature"</span><span class="p">:</span> <span class="kc">null</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span></code></pre></div><p><strong>Digest Record</strong> (every 100 events):</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-json" data-lang="json"><span class="line"><span class="cl"><span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"stream"</span><span class="p">:</span> <span class="s2">"geode-audit"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"seq_no"</span><span class="p">:</span> <span class="mi">100</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"timestamp"</span><span class="p">:</span> <span class="s2">"2026-01-24T10:35:00.000Z"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"event_type"</span><span class="p">:</span> <span class="s2">"system.digest"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"merkle_root"</span><span class="p">:</span> <span class="s2">"b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"signature"</span><span class="p">:</span> <span class="s2">"d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9..."</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span></code></pre></div>
<h4 id="hash-algorithm" class="position-relative d-flex align-items-center group">
<span>Hash Algorithm</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="hash-algorithm"
aria-haspopup="dialog"
aria-label="Share link: Hash Algorithm">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p><strong>Default</strong>: SHA-256 (widely supported, FIPS 140-2 compliant)</p>
<p><strong>Alternative</strong>: BLAKE3 (faster, modern cryptographic standard)</p>
<p><strong>Chain Logic</strong>:</p>
<ol>
<li>First event: <code>prev_hash = 0x00000000...</code> (32 zero bytes)</li>
<li>Subsequent events: <code>prev_hash = hash(previous_event.event_hash)</code></li>
<li>Digest events: Compute Merkle root over last N event_hashes</li>
<li>Sign Merkle root with Ed25519 private key</li>
</ol>
<h4 id="signing-configuration" class="position-relative d-flex align-items-center group">
<span>Signing Configuration</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="signing-configuration"
aria-haspopup="dialog"
aria-label="Share link: Signing Configuration">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p><strong>Production Requirements</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl"><span class="c1"># Generate Ed25519 key pair</span>
</span></span><span class="line"><span class="cl">openssl genpkey -algorithm ED25519 -out audit_private.pem
</span></span><span class="line"><span class="cl">openssl pkey -in audit_private.pem -pubout -out audit_public.pem
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># Convert to hex format for environment variables</span>
</span></span><span class="line"><span class="cl"><span class="nv">GEODE_AUDIT_PUB</span><span class="o">=</span><span class="k">$(</span>openssl pkey -in audit_public.pem -pubin -text <span class="p">|</span> grep -A4 pub <span class="p">|</span> tail -n +2 <span class="p">|</span> tr -d <span class="s1">':'</span> <span class="p">|</span> tr -d <span class="s1">'\n'</span><span class="k">)</span>
</span></span><span class="line"><span class="cl"><span class="nv">GEODE_AUDIT_SEC</span><span class="o">=</span><span class="k">$(</span>openssl pkey -in audit_private.pem -text <span class="p">|</span> grep -A4 priv <span class="p">|</span> tail -n +2 <span class="p">|</span> tr -d <span class="s1">':'</span> <span class="p">|</span> tr -d <span class="s1">'\n'</span><span class="k">)</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="nb">export</span> GEODE_AUDIT_PUB
</span></span><span class="line"><span class="cl"><span class="nb">export</span> GEODE_AUDIT_SEC
</span></span></code></pre></div><p><strong>Startup Validation</strong>:</p>
<ul>
<li>If keys missing in non-test builds: Exit with <code>CONFIG_ERROR SIGNING_KEYS_MISSING</code> (exit code 78)</li>
<li>Test builds: Derive deterministic key from fixed seed (for reproducible tests)</li>
</ul>
<p><strong>Key Rotation</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-json" data-lang="json"><span class="line"><span class="cl"><span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"event_type"</span><span class="p">:</span> <span class="s2">"system.key_rotation"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"details"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"old_key_fingerprint"</span><span class="p">:</span> <span class="s2">"sha256:abc123..."</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"new_key_fingerprint"</span><span class="p">:</span> <span class="s2">"sha256:def456..."</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"rotation_timestamp"</span><span class="p">:</span> <span class="s2">"2026-01-24T12:00:00.000Z"</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span></code></pre></div>
<h3 id="configuration" class="position-relative d-flex align-items-center group">
<span>Configuration</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="configuration"
aria-haspopup="dialog"
aria-label="Share link: Configuration">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h3>
<h4 id="json-configuration-schema" class="position-relative d-flex align-items-center group">
<span>JSON Configuration Schema</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="json-configuration-schema"
aria-haspopup="dialog"
aria-label="Share link: JSON Configuration Schema">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p><strong>Location</strong>: <code>config/logging.json</code></p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-json" data-lang="json"><span class="line"><span class="cl"><span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"version"</span><span class="p">:</span> <span class="mi">1</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"service"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"name"</span><span class="p">:</span> <span class="s2">"geode-server"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"host"</span><span class="p">:</span> <span class="s2">"prod-db-01"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"pid"</span><span class="p">:</span> <span class="mi">1234</span>
</span></span><span class="line"><span class="cl"> <span class="p">},</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"identity"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"cef"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"vendor"</span><span class="p">:</span> <span class="s2">"DEVNW"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"product"</span><span class="p">:</span> <span class="s2">"GEODE"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"version"</span><span class="p">:</span> <span class="s2">"0.2.18"</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"> <span class="p">},</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"sinks"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"file"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"enabled"</span><span class="p">:</span> <span class="kc">true</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"path"</span><span class="p">:</span> <span class="s2">"/var/log/geode/audit.jsonl"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"max_bytes"</span><span class="p">:</span> <span class="mi">104857600</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"backup_count"</span><span class="p">:</span> <span class="mi">10</span>
</span></span><span class="line"><span class="cl"> <span class="p">},</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"syslog"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"enabled"</span><span class="p">:</span> <span class="kc">true</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"protocol"</span><span class="p">:</span> <span class="s2">"udp"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"host"</span><span class="p">:</span> <span class="s2">"syslog.example.com"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"port"</span><span class="p">:</span> <span class="mi">514</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"rfc5424"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"facility"</span><span class="p">:</span> <span class="s2">"local4"</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"> <span class="p">},</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"filters"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"default_deny"</span><span class="p">:</span> <span class="kc">true</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"allow_fields"</span><span class="p">:</span> <span class="p">[</span>
</span></span><span class="line"><span class="cl"> <span class="s2">"actor_id"</span><span class="p">,</span> <span class="s2">"subject_id"</span><span class="p">,</span> <span class="s2">"request_id"</span><span class="p">,</span> <span class="s2">"session_id"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="s2">"source_ip"</span><span class="p">,</span> <span class="s2">"trace_id"</span><span class="p">,</span> <span class="s2">"span_id"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="s2">"category"</span><span class="p">,</span> <span class="s2">"action"</span><span class="p">,</span> <span class="s2">"outcome"</span><span class="p">,</span> <span class="s2">"severity"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="s2">"db.operation"</span><span class="p">,</span> <span class="s2">"db.table"</span><span class="p">,</span> <span class="s2">"db.rowCount"</span><span class="p">,</span> <span class="s2">"duration_ms"</span>
</span></span><span class="line"><span class="cl"> <span class="p">],</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"deny_key_patterns"</span><span class="p">:</span> <span class="p">[</span><span class="s2">"password"</span><span class="p">,</span> <span class="s2">"secret"</span><span class="p">,</span> <span class="s2">"token"</span><span class="p">,</span> <span class="s2">"key"</span><span class="p">],</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"pii_mode"</span><span class="p">:</span> <span class="s2">"mask"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"pci_mode"</span><span class="p">:</span> <span class="kc">true</span>
</span></span><span class="line"><span class="cl"> <span class="p">},</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"hash_chain"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"algorithm"</span><span class="p">:</span> <span class="s2">"sha256"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"digest_interval"</span><span class="p">:</span> <span class="mi">100</span>
</span></span><span class="line"><span class="cl"> <span class="p">},</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"signing"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"enabled"</span><span class="p">:</span> <span class="kc">true</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"algorithm"</span><span class="p">:</span> <span class="s2">"ed25519"</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span></code></pre></div>
<h4 id="configuration-options" class="position-relative d-flex align-items-center group">
<span>Configuration Options</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="configuration-options"
aria-haspopup="dialog"
aria-label="Share link: Configuration Options">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p><strong>Service Identity</strong>:</p>
<ul>
<li><code>name</code>: Service name for audit trail correlation</li>
<li><code>host</code>: Hostname for distributed deployment identification</li>
<li><code>pid</code>: Process ID (auto-populated at runtime)</li>
</ul>
<p><strong>File Sink</strong>:</p>
<ul>
<li><code>path</code>: Audit log file path (created with 0600 permissions)</li>
<li><code>max_bytes</code>: Rotation threshold (default: 100 MB)</li>
<li><code>backup_count</code>: Number of rotated files to keep (default: 10)</li>
</ul>
<p><strong>Syslog Sink</strong>:</p>
<ul>
<li><code>protocol</code>: “udp” or “tcp”</li>
<li><code>host</code>: Syslog server hostname</li>
<li><code>port</code>: Syslog server port (514 for UDP, 6514 for TLS)</li>
<li><code>facility</code>: RFC 5424 facility (default: “local4”)</li>
</ul>
<p><strong>Filters</strong>:</p>
<ul>
<li><code>default_deny</code>: If true, only <code>allow_fields</code> are logged</li>
<li><code>allow_fields</code>: Explicit allowlist of field names</li>
<li><code>deny_key_patterns</code>: Regex patterns for sensitive keys</li>
<li><code>pii_mode</code>: “mask”, “redact”, or “allow”</li>
<li><code>pci_mode</code>: Enable PCI-DSS compliant credit card redaction</li>
</ul>
<p><strong>Hash Chain</strong>:</p>
<ul>
<li><code>algorithm</code>: “sha256” or “blake3”</li>
<li><code>digest_interval</code>: Events between Merkle digest records</li>
</ul>
<p><strong>Signing</strong>:</p>
<ul>
<li><code>enabled</code>: Generate Ed25519 signatures (default: true)</li>
<li><code>algorithm</code>: “ed25519” (currently only supported algorithm)</li>
</ul>
<h3 id="event-types" class="position-relative d-flex align-items-center group">
<span>Event Types</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="event-types"
aria-haspopup="dialog"
aria-label="Share link: Event Types">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h3>
<h4 id="authentication-events" class="position-relative d-flex align-items-center group">
<span>Authentication Events</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="authentication-events"
aria-haspopup="dialog"
aria-label="Share link: Authentication Events">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p><strong>Successful Login</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-json" data-lang="json"><span class="line"><span class="cl"><span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"event_type"</span><span class="p">:</span> <span class="s2">"auth.login"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"actor"</span><span class="p">:</span> <span class="s2">"[email protected]"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"action"</span><span class="p">:</span> <span class="s2">"authenticate"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"result"</span><span class="p">:</span> <span class="s2">"success"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"details"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"role"</span><span class="p">:</span> <span class="s2">"admin"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"session_id"</span><span class="p">:</span> <span class="s2">"ses-abc123"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"auth_method"</span><span class="p">:</span> <span class="s2">"password"</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span></code></pre></div><p><strong>Failed Login</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-json" data-lang="json"><span class="line"><span class="cl"><span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"event_type"</span><span class="p">:</span> <span class="s2">"auth.login"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"actor"</span><span class="p">:</span> <span class="s2">"[email protected]"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"action"</span><span class="p">:</span> <span class="s2">"authenticate"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"result"</span><span class="p">:</span> <span class="s2">"failure"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"details"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"reason"</span><span class="p">:</span> <span class="s2">"invalid_credentials"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"attempts"</span><span class="p">:</span> <span class="mi">3</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span></code></pre></div><p><strong>Logout</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-json" data-lang="json"><span class="line"><span class="cl"><span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"event_type"</span><span class="p">:</span> <span class="s2">"auth.logout"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"actor"</span><span class="p">:</span> <span class="s2">"[email protected]"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"action"</span><span class="p">:</span> <span class="s2">"terminate_session"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"result"</span><span class="p">:</span> <span class="s2">"success"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"details"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"session_id"</span><span class="p">:</span> <span class="s2">"ses-abc123"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"session_duration_ms"</span><span class="p">:</span> <span class="mi">3600000</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span></code></pre></div>
<h4 id="database-operations" class="position-relative d-flex align-items-center group">
<span>Database Operations</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="database-operations"
aria-haspopup="dialog"
aria-label="Share link: Database Operations">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p><strong>Query Execution</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-json" data-lang="json"><span class="line"><span class="cl"><span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"event_type"</span><span class="p">:</span> <span class="s2">"db.query"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"actor"</span><span class="p">:</span> <span class="s2">"[email protected]"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"resource"</span><span class="p">:</span> <span class="s2">"graph:main"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"action"</span><span class="p">:</span> <span class="s2">"execute"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"result"</span><span class="p">:</span> <span class="s2">"success"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"details"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"db.operation"</span><span class="p">:</span> <span class="s2">"MATCH"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"db.rowCount"</span><span class="p">:</span> <span class="mi">42</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"duration_ms"</span><span class="p">:</span> <span class="mi">15</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"trace_id"</span><span class="p">:</span> <span class="s2">"trace-xyz789"</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span></code></pre></div><p><strong>Schema Modification</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-json" data-lang="json"><span class="line"><span class="cl"><span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"event_type"</span><span class="p">:</span> <span class="s2">"db.schema_change"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"actor"</span><span class="p">:</span> <span class="s2">"[email protected]"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"resource"</span><span class="p">:</span> <span class="s2">"index:user_email"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"action"</span><span class="p">:</span> <span class="s2">"create"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"result"</span><span class="p">:</span> <span class="s2">"success"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"details"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"index_type"</span><span class="p">:</span> <span class="s2">"btree"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"columns"</span><span class="p">:</span> <span class="p">[</span><span class="s2">"email"</span><span class="p">]</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span></code></pre></div><p><strong>Access Denied</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-json" data-lang="json"><span class="line"><span class="cl"><span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"event_type"</span><span class="p">:</span> <span class="s2">"db.access_denied"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"actor"</span><span class="p">:</span> <span class="s2">"[email protected]"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"resource"</span><span class="p">:</span> <span class="s2">"node:Person"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"action"</span><span class="p">:</span> <span class="s2">"create"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"result"</span><span class="p">:</span> <span class="s2">"failure"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"details"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"reason"</span><span class="p">:</span> <span class="s2">"insufficient_permissions"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"required_role"</span><span class="p">:</span> <span class="s2">"ReadWrite"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"actual_role"</span><span class="p">:</span> <span class="s2">"ReadOnly"</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span></code></pre></div>
<h4 id="system-events" class="position-relative d-flex align-items-center group">
<span>System Events</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="system-events"
aria-haspopup="dialog"
aria-label="Share link: System Events">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p><strong>Server Startup</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-json" data-lang="json"><span class="line"><span class="cl"><span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"event_type"</span><span class="p">:</span> <span class="s2">"system.startup"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"actor"</span><span class="p">:</span> <span class="s2">"system"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"action"</span><span class="p">:</span> <span class="s2">"initialize"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"result"</span><span class="p">:</span> <span class="s2">"success"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"details"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"version"</span><span class="p">:</span> <span class="s2">"0.2.18"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"config_file"</span><span class="p">:</span> <span class="s2">"/etc/geode/config.yaml"</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span></code></pre></div><p><strong>File Rotation</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-json" data-lang="json"><span class="line"><span class="cl"><span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"event_type"</span><span class="p">:</span> <span class="s2">"system.rotation"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"actor"</span><span class="p">:</span> <span class="s2">"system"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"action"</span><span class="p">:</span> <span class="s2">"rotate_audit_log"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"result"</span><span class="p">:</span> <span class="s2">"success"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"details"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"old_file"</span><span class="p">:</span> <span class="s2">"/var/log/geode/audit.jsonl"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"new_file"</span><span class="p">:</span> <span class="s2">"/var/log/geode/audit.jsonl.1"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"size_bytes"</span><span class="p">:</span> <span class="mi">104857600</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span></code></pre></div>
<h3 id="sensitive-data-redaction" class="position-relative d-flex align-items-center group">
<span>Sensitive Data Redaction</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="sensitive-data-redaction"
aria-haspopup="dialog"
aria-label="Share link: Sensitive Data Redaction">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h3>
<h4 id="multi-layer-protection" class="position-relative d-flex align-items-center group">
<span>Multi-Layer Protection</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="multi-layer-protection"
aria-haspopup="dialog"
aria-label="Share link: Multi-Layer Protection">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p>Geode employs five layers of protection against sensitive data leakage:</p>
<ol>
<li>
<p><strong>Key Pattern Detection</strong></p>
<ul>
<li>Automatic detection of sensitive key names</li>
<li>Patterns: <code>password</code>, <code>secret</code>, <code>token</code>, <code>key</code>, <code>credential</code>, <code>ssn</code>, <code>card</code></li>
</ul>
</li>
<li>
<p><strong>Value Analysis</strong></p>
<ul>
<li>Credit card number detection (Luhn algorithm)</li>
<li>Social Security Number patterns</li>
<li>Email address masking</li>
<li>IP address anonymization</li>
</ul>
</li>
<li>
<p><strong>Default-Deny Filtering</strong></p>
<ul>
<li>Only <code>allow_fields</code> are logged</li>
<li>Unknown fields automatically dropped</li>
<li>Explicit opt-in required for new fields</li>
</ul>
</li>
<li>
<p><strong>Fail-Closed Behavior</strong></p>
<ul>
<li>If redaction cannot guarantee safety, drop entire event</li>
<li>Log warning: <code>AUDIT_REDACTION_FAILED</code></li>
<li>Never log potentially sensitive data</li>
</ul>
</li>
<li>
<p><strong>Database Adapter Restriction</strong></p>
<ul>
<li>SQL text and parameters <strong>never</strong> accepted</li>
<li>Only metadata logged: operation type, row count, duration</li>
<li>Prevents accidental query parameter exposure</li>
</ul>
</li>
</ol>
<h4 id="redaction-examples" class="position-relative d-flex align-items-center group">
<span>Redaction Examples</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="redaction-examples"
aria-haspopup="dialog"
aria-label="Share link: Redaction Examples">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p><strong>Original Event</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-json" data-lang="json"><span class="line"><span class="cl"><span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"user"</span><span class="p">:</span> <span class="s2">"[email protected]"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"password"</span><span class="p">:</span> <span class="s2">"SecurePassword123!"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"credit_card"</span><span class="p">:</span> <span class="s2">"4111-1111-1111-1111"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"ssn"</span><span class="p">:</span> <span class="s2">"123-45-6789"</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span></code></pre></div><p><strong>Redacted Event</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-json" data-lang="json"><span class="line"><span class="cl"><span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"user"</span><span class="p">:</span> <span class="s2">"[email protected]"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"password"</span><span class="p">:</span> <span class="s2">"***REDACTED***"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"credit_card"</span><span class="p">:</span> <span class="s2">"***REDACTED***"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"ssn"</span><span class="p">:</span> <span class="s2">"***REDACTED***"</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span></code></pre></div><p><strong>PII Mode: Mask</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-json" data-lang="json"><span class="line"><span class="cl"><span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"email"</span><span class="p">:</span> <span class="s2">"a***@e*****.com"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"ip_address"</span><span class="p">:</span> <span class="s2">"192.168.xxx.xxx"</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span></code></pre></div><p><strong>PII Mode: Redact</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-json" data-lang="json"><span class="line"><span class="cl"><span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"email"</span><span class="p">:</span> <span class="s2">"***REDACTED***"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"ip_address"</span><span class="p">:</span> <span class="s2">"***REDACTED***"</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span></code></pre></div>
<h3 id="file-management" class="position-relative d-flex align-items-center group">
<span>File Management</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="file-management"
aria-haspopup="dialog"
aria-label="Share link: File Management">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h3>
<h4 id="rotation-strategy" class="position-relative d-flex align-items-center group">
<span>Rotation Strategy</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="rotation-strategy"
aria-haspopup="dialog"
aria-label="Share link: Rotation Strategy">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p><strong>Size-Based Rotation</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-plaintext" data-lang="plaintext"><span class="line"><span class="cl">/var/log/geode/audit.jsonl (current, <100 MB)
</span></span><span class="line"><span class="cl">/var/log/geode/audit.jsonl.1 (100 MB, yesterday)
</span></span><span class="line"><span class="cl">/var/log/geode/audit.jsonl.2 (100 MB, 2 days ago)
</span></span><span class="line"><span class="cl">...
</span></span><span class="line"><span class="cl">/var/log/geode/audit.jsonl.10 (100 MB, 10 days ago)
</span></span></code></pre></div><p><strong>Rotation Process</strong>:</p>
<ol>
<li>Current file reaches <code>max_bytes</code> threshold</li>
<li>Close current file</li>
<li>Rename: <code>audit.jsonl</code> → <code>audit.jsonl.1</code></li>
<li>Rotate existing: <code>.1</code> → <code>.2</code>, <code>.2</code> → <code>.3</code>, etc.</li>
<li>Delete oldest: <code>audit.jsonl.{backup_count}</code> removed</li>
<li>Create new: <code>audit.jsonl</code> with 0600 permissions</li>
<li>Continue <code>seq_no</code> and <code>prev_hash</code> chain from previous file</li>
<li>Emit <code>system.rotation</code> event</li>
</ol>
<p><strong>Chain Continuity</strong>:</p>
<ul>
<li>First record in new file uses <code>prev_hash</code> from tail of previous file</li>
<li>Maintains tamper-evident chain across file boundaries</li>
<li>Verification tool must process files in chronological order</li>
</ul>
<h4 id="permissions--security" class="position-relative d-flex align-items-center group">
<span>Permissions &amp; Security</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="permissions--security"
aria-haspopup="dialog"
aria-label="Share link: Permissions &amp; Security">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p><strong>File Permissions</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl"><span class="c1"># Audit log files</span>
</span></span><span class="line"><span class="cl">-rw------- <span class="m">1</span> geode geode <span class="m">104857600</span> Jan <span class="m">24</span> 10:30 audit.jsonl
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># Directory permissions</span>
</span></span><span class="line"><span class="cl">drwx------ <span class="m">2</span> geode geode <span class="m">4096</span> Jan <span class="m">24</span> 10:30 /var/log/geode/
</span></span></code></pre></div><p><strong>SELinux Context</strong> (if enabled):</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">chcon -t geode_log_t /var/log/geode/audit.jsonl
</span></span></code></pre></div><p><strong>AppArmor Profile</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-plaintext" data-lang="plaintext"><span class="line"><span class="cl">/var/log/geode/audit.jsonl rw,
</span></span><span class="line"><span class="cl">/var/log/geode/audit.jsonl.* r,
</span></span></code></pre></div>
<h3 id="verification" class="position-relative d-flex align-items-center group">
<span>Verification</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="verification"
aria-haspopup="dialog"
aria-label="Share link: Verification">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h3>
<h4 id="audit-log-verification" class="position-relative d-flex align-items-center group">
<span>Audit Log Verification</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="audit-log-verification"
aria-haspopup="dialog"
aria-label="Share link: Audit Log Verification">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p>Verify tamper-evident chain and signatures:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl"><span class="c1"># Verify single file</span>
</span></span><span class="line"><span class="cl">geode audit verify <span class="se">\
</span></span></span><span class="line"><span class="cl"><span class="se"></span> --file /var/log/geode/audit.jsonl <span class="se">\
</span></span></span><span class="line"><span class="cl"><span class="se"></span> --algo sha256 <span class="se">\
</span></span></span><span class="line"><span class="cl"><span class="se"></span> --pubkey <span class="nv">$GEODE_AUDIT_PUB</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># Verify rotated files (chronological order)</span>
</span></span><span class="line"><span class="cl"><span class="k">for</span> file in <span class="k">$(</span>ls -tr /var/log/geode/audit.jsonl*<span class="k">)</span><span class="p">;</span> <span class="k">do</span>
</span></span><span class="line"><span class="cl"> geode audit verify <span class="se">\
</span></span></span><span class="line"><span class="cl"><span class="se"></span> --file <span class="nv">$file</span> <span class="se">\
</span></span></span><span class="line"><span class="cl"><span class="se"></span> --algo sha256 <span class="se">\
</span></span></span><span class="line"><span class="cl"><span class="se"></span> --pubkey <span class="nv">$GEODE_AUDIT_PUB</span>
</span></span><span class="line"><span class="cl"><span class="k">done</span>
</span></span></code></pre></div><p><strong>Verification Outputs</strong>:</p>
<p>✅ <strong>Valid Chain</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-fallback" data-lang="fallback"><span class="line"><span class="cl">OK chain records=1000 digests=10 algo=sha256
</span></span></code></pre></div><p>❌ <strong>Tampered Chain</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-fallback" data-lang="fallback"><span class="line"><span class="cl">TAMPER chain at_seq=523 reason=PREV_HASH_MISMATCH
</span></span><span class="line"><span class="cl"> expected=a3c7f1d2e5b4a8c9f0d1e2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3
</span></span><span class="line"><span class="cl"> got=b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5
</span></span></code></pre></div><p>❌ <strong>Invalid Signature</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-fallback" data-lang="fallback"><span class="line"><span class="cl">TAMPER digest at_seq=600 reason=DIGEST_MISMATCH
</span></span><span class="line"><span class="cl"> expected=d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9
</span></span><span class="line"><span class="cl"> got=e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0
</span></span></code></pre></div><p>⚠️ <strong>Schema Error</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-fallback" data-lang="fallback"><span class="line"><span class="cl">SCHEMA_ERROR at_seq=789 field=timestamp detail="missing required field"
</span></span><span class="line"><span class="cl">WARN ignored trailing partial record
</span></span></code></pre></div>
<h4 id="forensic-analysis" class="position-relative d-flex align-items-center group">
<span>Forensic Analysis</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="forensic-analysis"
aria-haspopup="dialog"
aria-label="Share link: Forensic Analysis">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p><strong>Extract events by actor</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">jq <span class="s1">'select(.actor == "[email protected]")'</span> /var/log/geode/audit.jsonl
</span></span></code></pre></div><p><strong>Count events by type</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">jq -r <span class="s1">'.event_type'</span> /var/log/geode/audit.jsonl <span class="p">|</span> sort <span class="p">|</span> uniq -c <span class="p">|</span> sort -rn
</span></span></code></pre></div><p><strong>Find failed authentications</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">jq <span class="s1">'select(.event_type == "auth.login" and .result == "failure")'</span> <span class="se">\
</span></span></span><span class="line"><span class="cl"><span class="se"></span> /var/log/geode/audit.jsonl
</span></span></code></pre></div><p><strong>Verify chain segment</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl"><span class="c1"># Extract seq 100-200 and verify hash chain</span>
</span></span><span class="line"><span class="cl">jq <span class="s1">'select(.seq_no >= 100 and .seq_no <= 200)'</span> audit.jsonl > segment.jsonl
</span></span><span class="line"><span class="cl">geode audit verify --file segment.jsonl --algo sha256
</span></span></code></pre></div>
<h3 id="integration" class="position-relative d-flex align-items-center group">
<span>Integration</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="integration"
aria-haspopup="dialog"
aria-label="Share link: Integration">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h3>
<h4 id="syslog-integration-rfc-5424" class="position-relative d-flex align-items-center group">
<span>Syslog Integration (RFC 5424)</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="syslog-integration-rfc-5424"
aria-haspopup="dialog"
aria-label="Share link: Syslog Integration (RFC 5424)">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p><strong>CEF Format</strong> (Common Event Format):</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-fallback" data-lang="fallback"><span class="line"><span class="cl"><134>1 2026-01-24T10:30:15.123Z prod-db-01 geode 1234 auth.login -
</span></span><span class="line"><span class="cl">CEF:0|DEVNW|GEODE|0.2.18|auth.login|User Login|5|
</span></span><span class="line"><span class="cl">act=authenticate [email protected] outcome=success
</span></span><span class="line"><span class="cl">rt=Jan 24 2026 10:30:15 src=192.168.1.100
</span></span></code></pre></div><p><strong>Field Mapping</strong>:</p>
<ul>
<li><code><134></code>: Priority (local4.info)</li>
<li><code>1</code>: RFC 5424 version</li>
<li><code>prod-db-01</code>: Hostname</li>
<li><code>geode</code>: Application name</li>
<li><code>1234</code>: Process ID</li>
<li><code>auth.login</code>: Message ID</li>
<li>CEF fields: actor, action, outcome, timestamp, source IP</li>
</ul>
<p><strong>Testing Syslog</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl"><span class="c1"># Test UDP syslog</span>
</span></span><span class="line"><span class="cl">nc -u -l <span class="m">514</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># In another terminal</span>
</span></span><span class="line"><span class="cl"><span class="nb">echo</span> <span class="s2">"RETURN 1"</span> <span class="p">|</span> geode query --user alice --password <span class="nb">test</span> -
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># Check nc output for CEF messages</span>
</span></span></code></pre></div>
<h4 id="siem-integration" class="position-relative d-flex align-items-center group">
<span>SIEM Integration</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="siem-integration"
aria-haspopup="dialog"
aria-label="Share link: SIEM Integration">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p><strong>Splunk</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-fallback" data-lang="fallback"><span class="line"><span class="cl">sourcetype = geode:audit
</span></span><span class="line"><span class="cl">| stats count by event_type, result
</span></span><span class="line"><span class="cl">| where result="failure"
</span></span></code></pre></div><p><strong>Elasticsearch</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-json" data-lang="json"><span class="line"><span class="cl"><span class="err">GET</span> <span class="err">/geode-audit-*/_search</span>
</span></span><span class="line"><span class="cl"><span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"query"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"bool"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"must"</span><span class="p">:</span> <span class="p">[</span>
</span></span><span class="line"><span class="cl"> <span class="p">{</span><span class="nt">"term"</span><span class="p">:</span> <span class="p">{</span><span class="nt">"event_type"</span><span class="p">:</span> <span class="s2">"auth.login"</span><span class="p">}},</span>
</span></span><span class="line"><span class="cl"> <span class="p">{</span><span class="nt">"term"</span><span class="p">:</span> <span class="p">{</span><span class="nt">"result"</span><span class="p">:</span> <span class="s2">"failure"</span><span class="p">}}</span>
</span></span><span class="line"><span class="cl"> <span class="p">]</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span></code></pre></div><p><strong>Grafana Loki</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-fallback" data-lang="fallback"><span class="line"><span class="cl">{job="geode-audit"} |= "auth.login" |= "failure" | json
</span></span></code></pre></div>
<h3 id="compliance" class="position-relative d-flex align-items-center group">
<span>Compliance</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="compliance"
aria-haspopup="dialog"
aria-label="Share link: Compliance">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h3>
<h4 id="sox-sarbanes-oxley" class="position-relative d-flex align-items-center group">
<span>SOX (Sarbanes-Oxley)</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="sox-sarbanes-oxley"
aria-haspopup="dialog"
aria-label="Share link: SOX (Sarbanes-Oxley)">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p><strong>Requirements</strong>:</p>
<ul>
<li>✅ Tamper-evident audit trail (hash chain + signatures)</li>
<li>✅ Immutable log storage (append-only, 0600 permissions)</li>
<li>✅ Access tracking (all database operations logged)</li>
<li>✅ Retention policy (configurable backup_count)</li>
<li>✅ Periodic review (verification tools provided)</li>
</ul>
<p><strong>Configuration</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-json" data-lang="json"><span class="line"><span class="cl"><span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"sinks"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"file"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"backup_count"</span><span class="p">:</span> <span class="mi">90</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"max_bytes"</span><span class="p">:</span> <span class="mi">104857600</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span></code></pre></div>
<h4 id="pci-dss-payment-card-industry" class="position-relative d-flex align-items-center group">
<span>PCI-DSS (Payment Card Industry)</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="pci-dss-payment-card-industry"
aria-haspopup="dialog"
aria-label="Share link: PCI-DSS (Payment Card Industry)">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p><strong>Requirements</strong>:</p>
<ul>
<li>✅ Log all access to cardholder data (db.query events)</li>
<li>✅ Secure log storage (encryption at rest with TDE)</li>
<li>✅ Daily log review (automated verification)</li>
<li>✅ Retain logs for 1 year (90+ rotated files)</li>
<li>✅ Credit card redaction (Luhn algorithm detection)</li>
</ul>
<p><strong>Configuration</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-json" data-lang="json"><span class="line"><span class="cl"><span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"filters"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"pci_mode"</span><span class="p">:</span> <span class="kc">true</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"deny_key_patterns"</span><span class="p">:</span> <span class="p">[</span><span class="s2">"card"</span><span class="p">,</span> <span class="s2">"cvv"</span><span class="p">,</span> <span class="s2">"pan"</span><span class="p">]</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span></code></pre></div>
<h4 id="hipaa-health-insurance-portability" class="position-relative d-flex align-items-center group">
<span>HIPAA (Health Insurance Portability)</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="hipaa-health-insurance-portability"
aria-haspopup="dialog"
aria-label="Share link: HIPAA (Health Insurance Portability)">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p><strong>Requirements</strong>:</p>
<ul>
<li>✅ Audit controls (comprehensive event logging)</li>
<li>✅ Access tracking (actor, resource, action)</li>
<li>✅ Integrity controls (hash chain, signatures)</li>
<li>✅ PHI redaction (PII mode enabled)</li>
<li>✅ 6-year retention (adjust backup_count accordingly)</li>
</ul>
<p><strong>Configuration</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-json" data-lang="json"><span class="line"><span class="cl"><span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"filters"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"pii_mode"</span><span class="p">:</span> <span class="s2">"redact"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"deny_key_patterns"</span><span class="p">:</span> <span class="p">[</span><span class="s2">"ssn"</span><span class="p">,</span> <span class="s2">"dob"</span><span class="p">,</span> <span class="s2">"mrn"</span><span class="p">,</span> <span class="s2">"diagnosis"</span><span class="p">]</span>
</span></span><span class="line"><span class="cl"> <span class="p">},</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"sinks"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"file"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"backup_count"</span><span class="p">:</span> <span class="mi">2190</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span></code></pre></div>
<h4 id="gdpr-general-data-protection-regulation" class="position-relative d-flex align-items-center group">
<span>GDPR (General Data Protection Regulation)</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="gdpr-general-data-protection-regulation"
aria-haspopup="dialog"
aria-label="Share link: GDPR (General Data Protection Regulation)">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p><strong>Requirements</strong>:</p>
<ul>
<li>✅ Data minimization (default-deny filtering)</li>
<li>✅ Right to erasure (redaction tools)</li>
<li>✅ Breach notification (alerting on access_denied)</li>
<li>✅ Pseudonymization (PII masking)</li>
<li>✅ Audit trail (all processing logged)</li>
</ul>
<p><strong>Configuration</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-json" data-lang="json"><span class="line"><span class="cl"><span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"filters"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"default_deny"</span><span class="p">:</span> <span class="kc">true</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"pii_mode"</span><span class="p">:</span> <span class="s2">"mask"</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"allow_fields"</span><span class="p">:</span> <span class="p">[</span><span class="s2">"trace_id"</span><span class="p">,</span> <span class="s2">"action"</span><span class="p">,</span> <span class="s2">"outcome"</span><span class="p">]</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span></code></pre></div>
<h3 id="performance" class="position-relative d-flex align-items-center group">
<span>Performance</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="performance"
aria-haspopup="dialog"
aria-label="Share link: Performance">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h3>
<h4 id="benchmarks" class="position-relative d-flex align-items-center group">
<span>Benchmarks</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="benchmarks"
aria-haspopup="dialog"
aria-label="Share link: Benchmarks">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p><strong>Append Latency</strong>:</p>
<ul>
<li><strong>Non-blocking</strong>: <500μs (queue insertion)</li>
<li><strong>With fsync</strong>: <5ms (durable write)</li>
<li><strong>Hash computation</strong>: <100μs (SHA-256)</li>
<li><strong>Signature generation</strong>: <1ms (Ed25519, every 100 events)</li>
</ul>
<p><strong>Throughput</strong>:</p>
<ul>
<li><strong>Single-threaded</strong>: 10,000 events/sec</li>
<li><strong>Multi-threaded</strong>: 50,000 events/sec</li>
<li><strong>With syslog</strong>: 8,000 events/sec (network overhead)</li>
</ul>
<p><strong>Memory Usage</strong>:</p>
<ul>
<li><strong>Base</strong>: 10 MB (buffer queues)</li>
<li><strong>Per event</strong>: 1 KB (average)</li>
<li><strong>Max RSS</strong>: 512 MB (limits enforced)</li>
</ul>
<h4 id="optimization" class="position-relative d-flex align-items-center group">
<span>Optimization</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="optimization"
aria-haspopup="dialog"
aria-label="Share link: Optimization">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p><strong>Tuning for High Volumes</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-json" data-lang="json"><span class="line"><span class="cl"><span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"buffer_size"</span><span class="p">:</span> <span class="mi">10000</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"batch_flush_interval_ms"</span><span class="p">:</span> <span class="mi">100</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"sinks"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"file"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"buffer_size_bytes"</span><span class="p">:</span> <span class="mi">1048576</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span></code></pre></div><p><strong>Async Syslog</strong> (non-blocking network I/O):</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-json" data-lang="json"><span class="line"><span class="cl"><span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"sinks"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"syslog"</span><span class="p">:</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"async"</span><span class="p">:</span> <span class="kc">true</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"queue_size"</span><span class="p">:</span> <span class="mi">10000</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="nt">"timeout_ms"</span><span class="p">:</span> <span class="mi">5000</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"> <span class="p">}</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span></code></pre></div>
<h3 id="troubleshooting" class="position-relative d-flex align-items-center group">
<span>Troubleshooting</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="troubleshooting"
aria-haspopup="dialog"
aria-label="Share link: Troubleshooting">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h3>
<h4 id="common-issues" class="position-relative d-flex align-items-center group">
<span>Common Issues</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="common-issues"
aria-haspopup="dialog"
aria-label="Share link: Common Issues">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p><strong>Issue</strong>: Audit log not created</p>
<p><strong>Solution</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl"><span class="c1"># Check directory permissions</span>
</span></span><span class="line"><span class="cl">ls -ld /var/log/geode/
</span></span><span class="line"><span class="cl"><span class="c1"># Should be drwx------ geode geode</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># Create directory if missing</span>
</span></span><span class="line"><span class="cl">sudo mkdir -p /var/log/geode
</span></span><span class="line"><span class="cl">sudo chown geode:geode /var/log/geode
</span></span><span class="line"><span class="cl">sudo chmod <span class="m">700</span> /var/log/geode
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># Verify configuration</span>
</span></span><span class="line"><span class="cl">cat config/logging.json <span class="p">|</span> jq <span class="s1">'.sinks.file'</span>
</span></span></code></pre></div><hr>
<p><strong>Issue</strong>: Verification fails with SCHEMA_ERROR</p>
<p><strong>Solution</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl"><span class="c1"># Check for truncated JSON lines</span>
</span></span><span class="line"><span class="cl">tail -n <span class="m">1</span> audit.jsonl
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># Remove partial line if present</span>
</span></span><span class="line"><span class="cl">head -n -1 audit.jsonl > audit_fixed.jsonl
</span></span><span class="line"><span class="cl">mv audit_fixed.jsonl audit.jsonl
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># Re-run verification</span>
</span></span><span class="line"><span class="cl">geode audit verify --file audit.jsonl
</span></span></code></pre></div><hr>
<p><strong>Issue</strong>: Syslog messages not reaching server</p>
<p><strong>Solution</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl"><span class="c1"># Test network connectivity</span>
</span></span><span class="line"><span class="cl">nc -zv syslog.example.com <span class="m">514</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># Check firewall rules</span>
</span></span><span class="line"><span class="cl">sudo iptables -L <span class="p">|</span> grep <span class="m">514</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># Enable debug logging</span>
</span></span><span class="line"><span class="cl"><span class="nv">GEODE_LOG_LEVEL</span><span class="o">=</span>debug geode serve
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># Verify CEF format</span>
</span></span><span class="line"><span class="cl">tcpdump -i any port <span class="m">514</span> -A
</span></span></code></pre></div><hr>
<p><strong>Issue</strong>: High memory usage</p>
<p><strong>Solution</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl"><span class="c1"># Monitor memory</span>
</span></span><span class="line"><span class="cl">top -p <span class="k">$(</span>pgrep geode<span class="k">)</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># Reduce buffer size</span>
</span></span><span class="line"><span class="cl">jq <span class="s1">'.buffer_size = 1000'</span> config/logging.json > config/logging_new.json
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># Enable aggressive rotation</span>
</span></span><span class="line"><span class="cl">jq <span class="s1">'.sinks.file.max_bytes = 10485760'</span> config/logging.json > config/logging_new.json
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># Restart with new config</span>
</span></span><span class="line"><span class="cl">sudo systemctl restart geode
</span></span></code></pre></div>
<h3 id="best-practices" class="position-relative d-flex align-items-center group">
<span>Best Practices</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="best-practices"
aria-haspopup="dialog"
aria-label="Share link: Best Practices">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h3>
<h4 id="deployment-checklist" class="position-relative d-flex align-items-center group">
<span>Deployment Checklist</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="deployment-checklist"
aria-haspopup="dialog"
aria-label="Share link: Deployment Checklist">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p>Production deployment recommendations:</p>
<ul>
<li><input disabled="" type="checkbox"> Generate unique Ed25519 key pair (not test keys!)</li>
<li><input disabled="" type="checkbox"> Store private key in secure vault (HashiCorp Vault, AWS Secrets Manager)</li>
<li><input disabled="" type="checkbox"> Set <code>GEODE_AUDIT_PUB</code> and <code>GEODE_AUDIT_SEC</code> environment variables</li>
<li><input disabled="" type="checkbox"> Configure log rotation (90-2190 files for compliance)</li>
<li><input disabled="" type="checkbox"> Set up remote syslog server (redundant, geographically distributed)</li>
<li><input disabled="" type="checkbox"> Enable TDE for audit log encryption at rest</li>
<li><input disabled="" type="checkbox"> Configure automated verification (daily cron job)</li>
<li><input disabled="" type="checkbox"> Set up alerting for verification failures</li>
<li><input disabled="" type="checkbox"> Document key rotation procedures</li>
<li><input disabled="" type="checkbox"> Test disaster recovery (restore from backups)</li>
</ul>
<h4 id="security-hardening" class="position-relative d-flex align-items-center group">
<span>Security Hardening</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="security-hardening"
aria-haspopup="dialog"
aria-label="Share link: Security Hardening">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><p><strong>Restrict Access</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl"><span class="c1"># Only geode user can read audit logs</span>
</span></span><span class="line"><span class="cl">chmod <span class="m">600</span> /var/log/geode/audit.jsonl*
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># Only root can rotate</span>
</span></span><span class="line"><span class="cl">chmod <span class="m">700</span> /usr/local/bin/rotate_audit_logs.sh
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># SELinux mandatory access control</span>
</span></span><span class="line"><span class="cl">semanage fcontext -a -t geode_log_t <span class="s1">'/var/log/geode(/.*)?'</span>
</span></span><span class="line"><span class="cl">restorecon -Rv /var/log/geode
</span></span></code></pre></div><p><strong>Network Security</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl"><span class="c1"># Use TLS for syslog (port 6514)</span>
</span></span><span class="line"><span class="cl"><span class="o">{</span>
</span></span><span class="line"><span class="cl"> <span class="s2">"sinks"</span>: <span class="o">{</span>
</span></span><span class="line"><span class="cl"> <span class="s2">"syslog"</span>: <span class="o">{</span>
</span></span><span class="line"><span class="cl"> <span class="s2">"protocol"</span>: <span class="s2">"tls"</span>,
</span></span><span class="line"><span class="cl"> <span class="s2">"port"</span>: 6514,
</span></span><span class="line"><span class="cl"> <span class="s2">"tls"</span>: <span class="o">{</span>
</span></span><span class="line"><span class="cl"> <span class="s2">"ca_cert"</span>: <span class="s2">"/etc/geode/syslog-ca.pem"</span>,
</span></span><span class="line"><span class="cl"> <span class="s2">"verify"</span>: <span class="nb">true</span>
</span></span><span class="line"><span class="cl"> <span class="o">}</span>
</span></span><span class="line"><span class="cl"> <span class="o">}</span>
</span></span><span class="line"><span class="cl"> <span class="o">}</span>
</span></span><span class="line"><span class="cl"><span class="o">}</span>
</span></span></code></pre></div><p><strong>Monitoring</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl"><span class="c1"># Alert on verification failures</span>
</span></span><span class="line"><span class="cl"><span class="m">0</span> <span class="m">2</span> * * * /usr/local/bin/verify_audit_logs.sh <span class="o">||</span> mail -s <span class="s2">"Audit verification failed"</span> [email protected]
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1"># Monitor for tampering attempts</span>
</span></span><span class="line"><span class="cl">journalctl -u geode -f <span class="p">|</span> grep TAMPER <span class="p">|</span> mail -s <span class="s2">"ALERT: Audit tampering detected"</span> [email protected]
</span></span></code></pre></div>
<h3 id="code-examples" class="position-relative d-flex align-items-center group">
<span>Code Examples</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="code-examples"
aria-haspopup="dialog"
aria-label="Share link: Code Examples">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h3>
<h4 id="basic-usage" class="position-relative d-flex align-items-center group">
<span>Basic Usage</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="basic-usage"
aria-haspopup="dialog"
aria-label="Share link: Basic Usage">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><div class="highlight"><pre tabindex="0" class="chroma"><code class="language-zig" data-lang="zig"><span class="line"><span class="cl"><span class="kr">const</span><span class="w"> </span><span class="n">std</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="nb">@import</span><span class="p">(</span><span class="s">"std"</span><span class="p">);</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="kr">const</span><span class="w"> </span><span class="n">audit</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="nb">@import</span><span class="p">(</span><span class="s">"audit/logger.zig"</span><span class="p">);</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="kr">const</span><span class="w"> </span><span class="n">config</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="nb">@import</span><span class="p">(</span><span class="s">"audit/config.zig"</span><span class="p">);</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="kr">const</span><span class="w"> </span><span class="n">events</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="nb">@import</span><span class="p">(</span><span class="s">"audit/events.zig"</span><span class="p">);</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="kr">const</span><span class="w"> </span><span class="n">time</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="nb">@import</span><span class="p">(</span><span class="s">"audit/time.zig"</span><span class="p">);</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="kr">pub</span><span class="w"> </span><span class="k">fn</span><span class="w"> </span><span class="n">main</span><span class="p">()</span><span class="w"> </span><span class="o">!</span><span class="kt">void</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="kr">var</span><span class="w"> </span><span class="n">gpa</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="n">std</span><span class="p">.</span><span class="n">heap</span><span class="p">.</span><span class="n">GeneralPurposeAllocator</span><span class="p">(.{}){};</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="k">defer</span><span class="w"> </span><span class="n">_</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="n">gpa</span><span class="p">.</span><span class="n">deinit</span><span class="p">();</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="kr">const</span><span class="w"> </span><span class="n">allocator</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="n">gpa</span><span class="p">.</span><span class="n">allocator</span><span class="p">();</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="c1">// Load configuration
</span></span></span><span class="line"><span class="cl"><span class="c1"></span><span class="w"> </span><span class="kr">const</span><span class="w"> </span><span class="n">audit_config</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="k">try</span><span class="w"> </span><span class="n">config</span><span class="p">.</span><span class="n">loadConfig</span><span class="p">(</span><span class="n">allocator</span><span class="p">,</span><span class="w"> </span><span class="s">"config/logging.json"</span><span class="p">);</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="k">defer</span><span class="w"> </span><span class="n">audit_config</span><span class="p">.</span><span class="n">deinit</span><span class="p">();</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="c1">// Initialize logger
</span></span></span><span class="line"><span class="cl"><span class="c1"></span><span class="w"> </span><span class="kr">var</span><span class="w"> </span><span class="n">sys_clock</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="n">time</span><span class="p">.</span><span class="n">SystemClock</span><span class="p">{};</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="kr">var</span><span class="w"> </span><span class="n">sys_id_gen</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="n">time</span><span class="p">.</span><span class="n">SystemIdGen</span><span class="p">.</span><span class="n">init</span><span class="p">();</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="kr">const</span><span class="w"> </span><span class="n">logger</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="k">try</span><span class="w"> </span><span class="n">audit</span><span class="p">.</span><span class="n">AuditLogger</span><span class="p">.</span><span class="n">init</span><span class="p">(</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="n">allocator</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="n">audit_config</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="n">sys_clock</span><span class="p">.</span><span class="n">clock</span><span class="p">(),</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="n">sys_id_gen</span><span class="p">.</span><span class="n">idGen</span><span class="p">(),</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="p">);</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="k">defer</span><span class="w"> </span><span class="n">logger</span><span class="p">.</span><span class="n">deinit</span><span class="p">();</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="c1">// Emit authentication event
</span></span></span><span class="line"><span class="cl"><span class="c1"></span><span class="w"> </span><span class="kr">const</span><span class="w"> </span><span class="n">auth_event</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="n">events</span><span class="p">.</span><span class="n">AuditEvent</span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="p">.</span><span class="n">category</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s">"auth"</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="p">.</span><span class="n">action</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s">"login"</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="p">.</span><span class="n">outcome</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="p">.</span><span class="n">success</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="p">.</span><span class="n">ts_unix_ms</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="mi">0</span><span class="p">,</span><span class="w"> </span><span class="c1">// Auto-filled
</span></span></span><span class="line"><span class="cl"><span class="c1"></span><span class="w"> </span><span class="p">.</span><span class="n">severity</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="p">.</span><span class="n">INFO</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="p">.</span><span class="n">actor_id</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s">"[email protected]"</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="p">.</span><span class="n">subject_id</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="kc">null</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="p">.</span><span class="n">request_id</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s">"req-12345"</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="p">.</span><span class="n">session_id</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s">"ses-abcdef"</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="p">.</span><span class="n">source_ip</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s">"192.168.1.100"</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="p">.</span><span class="n">trace_id</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="kc">null</span><span class="p">,</span><span class="w"> </span><span class="c1">// Auto-generated
</span></span></span><span class="line"><span class="cl"><span class="c1"></span><span class="w"> </span><span class="p">.</span><span class="n">span_id</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="kc">null</span><span class="p">,</span><span class="w"> </span><span class="c1">// Auto-generated
</span></span></span><span class="line"><span class="cl"><span class="c1"></span><span class="w"> </span><span class="p">.</span><span class="n">metadata</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="kc">null</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="p">};</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="k">try</span><span class="w"> </span><span class="n">logger</span><span class="p">.</span><span class="n">audit</span><span class="p">(</span><span class="o">&</span><span class="n">auth_event</span><span class="p">);</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="p">}</span><span class="w">
</span></span></span></code></pre></div>
<h4 id="custom-event-types" class="position-relative d-flex align-items-center group">
<span>Custom Event Types</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="custom-event-types"
aria-haspopup="dialog"
aria-label="Share link: Custom Event Types">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><div class="highlight"><pre tabindex="0" class="chroma"><code class="language-zig" data-lang="zig"><span class="line"><span class="cl"><span class="c1">// Create custom database event
</span></span></span><span class="line"><span class="cl"><span class="c1"></span><span class="kr">const</span><span class="w"> </span><span class="n">db_event</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="n">events</span><span class="p">.</span><span class="n">AuditEvent</span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="p">.</span><span class="n">category</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s">"db"</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="p">.</span><span class="n">action</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s">"execute"</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="p">.</span><span class="n">outcome</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="p">.</span><span class="n">success</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="p">.</span><span class="n">severity</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="p">.</span><span class="n">INFO</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="p">.</span><span class="n">actor_id</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s">"[email protected]"</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="p">.</span><span class="n">resource</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s">"graph:main"</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="p">.</span><span class="n">metadata</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="p">.{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="p">.</span><span class="n">db_operation</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s">"MATCH"</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="p">.</span><span class="n">db_rowCount</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="mi">42</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="p">.</span><span class="n">duration_ms</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="mi">15</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"> </span><span class="p">},</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="p">};</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w"></span><span class="k">try</span><span class="w"> </span><span class="n">logger</span><span class="p">.</span><span class="n">audit</span><span class="p">(</span><span class="o">&</span><span class="n">db_event</span><span class="p">);</span><span class="w">
</span></span></span></code></pre></div>
<h3 id="references" class="position-relative d-flex align-items-center group">
<span>References</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="references"
aria-haspopup="dialog"
aria-label="Share link: References">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h3>
<h4 id="standards" class="position-relative d-flex align-items-center group">
<span>Standards</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="standards"
aria-haspopup="dialog"
aria-label="Share link: Standards">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><ul>
<li>
<p><strong>RFC 5424</strong>: The Syslog Protocol</p>
<ul>
<li><a
href="https://datatracker.ietf.org/doc/html/rfc5424"
aria-label="https://datatracker.ietf.org/doc/html/rfc5424 – opens in new window"
target="_blank" rel="noopener noreferrer"
>https://datatracker.ietf.org/doc/html/rfc5424
<span aria-hidden="true" class="external-icon">↗</span>
</a>
</li>
</ul>
</li>
<li>
<p><strong>Common Event Format (CEF)</strong></p>
<ul>
<li>ArcSight CEF specification for SIEM integration</li>
</ul>
</li>
<li>
<p><strong>W3C Trace Context</strong></p>
<ul>
<li><a
href="https://www.w3.org/TR/trace-context/"
aria-label="https://www.w3.org/TR/trace-context/ – opens in new window"
target="_blank" rel="noopener noreferrer"
>https://www.w3.org/TR/trace-context/
<span aria-hidden="true" class="external-icon">↗</span>
</a>
</li>
</ul>
</li>
<li>
<p><strong>Ed25519 Digital Signatures</strong></p>
<ul>
<li><a
href="https://ed25519.cr.yp.to/"
aria-label="https://ed25519.cr.yp.to/ – opens in new window"
target="_blank" rel="noopener noreferrer"
>https://ed25519.cr.yp.to/
<span aria-hidden="true" class="external-icon">↗</span>
</a>
</li>
</ul>
</li>
</ul>
<h4 id="compliance-resources" class="position-relative d-flex align-items-center group">
<span>Compliance Resources</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="compliance-resources"
aria-haspopup="dialog"
aria-label="Share link: Compliance Resources">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><ul>
<li><strong>SOX Compliance</strong>: IT audit controls</li>
<li><strong>PCI-DSS</strong>: Requirement 10 (logging and monitoring)</li>
<li><strong>HIPAA</strong>: 164.312(b) audit controls</li>
<li><strong>GDPR</strong>: Article 30 (records of processing)</li>
</ul>
<h4 id="code-location" class="position-relative d-flex align-items-center group">
<span>Code Location</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="code-location"
aria-haspopup="dialog"
aria-label="Share link: Code Location">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h4><ul>
<li><strong>Implementation</strong>: <code>src/audit/logger.zig</code></li>
<li><strong>Configuration</strong>: <code>src/audit/config.zig</code></li>
<li><strong>Tests</strong>: <code>tests/test_audit_logging.zig</code></li>
<li><strong>Documentation</strong>: <code>docs/AUDIT_LOGGING.md</code></li>
</ul>
<h3 id="next-steps" class="position-relative d-flex align-items-center group">
<span>Next Steps</span>
<button type="button"
class="h-share btn btn-link p-0 text-decoration-none link-secondary opacity-50 hover-opacity-100 transition-all ms-1"
data-share-target="next-steps"
aria-haspopup="dialog"
aria-label="Share link: Next Steps">
<i class="fa-sharp-duotone fa-solid fa-share-nodes" aria-hidden="true" style="font-size: 0.8em;"></i>
<span class="visually-hidden">Share link</span>
</button>
</h3><p><strong>For Operators</strong>:</p>
<ul>
<li><a
href="/docs/ops/observability/"
>Monitoring & Observability</a>
- Complete monitoring setup</li>
<li><a
href="/docs/ops/telemetry-advanced/"
>Telemetry Advanced</a>
- Custom metrics and dashboards</li>
<li><a
href="/docs/ops/docker-deployment/"
>Docker Deployment</a>
- Container audit log integration</li>
</ul>
<p><strong>For Security Teams</strong>:</p>
<ul>
<li><a
href="/docs/security/overview/"
>Security Overview</a>
- Complete security architecture</li>
<li><a
href="/docs/security/field-level-encryption/"
>Field-Level Encryption</a>
- Additional data protection</li>
<li><a
href="/docs/security/session-management/"
>Session Management</a>
- Session audit integration</li>
</ul>
<p><strong>For Developers</strong>:</p>
<ul>
<li><a
href="/docs/client-libraries/go-client/"
>Client Libraries</a>
- Client-side audit event generation</li>
<li><a
href="/docs/guides/testing-strategies/"
>Testing Strategies</a>
- Audit log testing approaches</li>
</ul>
<hr>
<p><strong>Document Version</strong>: 1.0
<strong>Last Updated</strong>: January 24, 2026
<strong>Status</strong>: Production Ready
<strong>Compliance</strong>: SOX, PCI-DSS, HIPAA, GDPR ready</p>
Audit Logging and Compliance
Comprehensive audit logging system in Geode with tamper-evident hash chains, RFC 5424 syslog integration, and enterprise compliance for SOX, PCI-DSS, and HIPAA requirements.