3.1 access-audit

The most common event in the system. Fires at AccessCheck completion, from the SACL audit walk, and from a token's audit_policy forcing an audit that no ACE asked for.

Event type string: access-audit.

KeyTypeMeaning
subjectmapSubject record (§2.1).
object_contextbin or nilCaller-supplied opaque identifier for the object. nil if AccessCheck was not given one.
requested_accessuintThe mask the caller requested, after generic mapping.
granted_accessuintThe mask actually granted.
successboolTrue when every requested bit is in granted_access.
triggermapWhy this event fired. Below.
processmapProcess record (§2.2).

Every field is always present.

3.1.1 The trigger record #

KeyTypeMeaning
kindstringsacl or policy.
acebin or nilFor kind = sacl, the matched ACE's bytes. For kind = policy, nil.

kind = sacl means an audit ACE in the object's SACL — or in a central access policy's SACL — matched this access, and ace carries the exact ACE so a consumer can identify which rule fired.

kind = policy means nothing in any SACL asked for this. The audit fired because the calling token's audit_policy carries OBJECT_ACCESS_SUCCESS or OBJECT_ACCESS_FAILURE, which forces an audit on every access that token makes.

The distinction matters when reading volume. A flood of kind = policy events is a property of the token, and is fixed by changing the token's policy. A flood of kind = sacl events is a property of the object, and is fixed by changing its SACL.

3.1.2 One access can produce several events #

The event is per matching audit ACE, not per access. An access that matches three audit ACEs produces three events, each with a different ace in its trigger and otherwise identical.

3.1.3 Example #

A successful read where a SACL audit ACE matched:

{
  "event_type": "access-audit",
  "event_time": <timestamp>,
  "subject": { ... },
  "object_context": <bin>,
  "requested_access": 0x00120089,
  "granted_access":   0x00120089,
  "success": true,
  "trigger": { "kind": "sacl", "ace": <bin> },
  "process": { ... }
}

0x00120089 is GENERIC_READ after mapping to file-specific bits. Generic bits never survive into an event; the mask is always specific.

Edit this page