I've made a little progress on what I optimistically think will be an acceptable solution. If any know of a better way, I am teachable. I get user and service information as related to any delegate request by routing the following to a separate appender.
org.pac4j.saml.credentials.SAML2Credentials -- INFO org.apereo.cas.web.flow.DelegatedClientAuthenticationAction -- DEBUG ---- I do have an addtional related question: Is it possible that client/x-ff IP is routed to MDC or some mechanism such that I could append it to the log format for this particular appender/logifie? Thanks, Andrew Marker On Tuesday, October 22, 2019 at 1:06:15 PM UTC-5, Andrew Marker wrote: > > Hi all, > > I currently have what I assume is a relatively vanilla logging config with > some minor tweaks to prevent filling the drive on the servers. We are > beginning in earnest work to leverage Delegate Auth with CAS 5.3.12.1 and > one of the items I'd like to do if possible would have one or the other of > these two outcomes. > > In addition to the current logging: > > 1. Add a log appender for all delegate auth events. > > 2. Target just a specific delegate auth provider, and log just those > events to an appender. > > I'm working with a specific IDP that would like to see the traffic happens > for their users in our system. We have an existing trust relationship where > I could share the audit log without concern, but there is a lot of > irrelevant to in that. > > Thanks in advance for the suggestions. > > Andrew Marker > -- - Website: https://apereo.github.io/cas - Gitter Chatroom: https://gitter.im/apereo/cas - List Guidelines: https://goo.gl/1VRrw7 - Contributions: https://goo.gl/mh7qDG --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/9d57aa4f-5dd6-47c6-bc6e-2259d4f7b7c1%40apereo.org.
